The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT213535 | vendor advisory |
https://support.apple.com/en-us/HT213532 | vendor advisory |
https://support.apple.com/en-us/HT213530 | vendor advisory |
http://seclists.org/fulldisclosure/2022/Dec/20 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2022/Dec/23 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2022/Dec/26 | third party advisory mailing list |