Back to Database
Status published
Unknown
CVE-2024-39281
Unbounded allocation in ctl(4) CAM Target Layer
Vulnerability Description
The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-39281
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Synacktiv
- The FreeBSD Foundation
- The Alpha-Omega Project
More from FreeBSD
View All →CVE-2025-24934
SO_REUSEPORT_LB breaks connect(2) for UDP sockets
Unknown
0
CVE-2025-15576
Jail chroot escape via fd exchange with a different jail
Unknown
0
CVE-2025-15547
Jail escape by a privileged user via nullfs
Unknown
0
CVE-2025-14769
ipfw denial of service
Unknown
0
CVE-2025-14558
Remote code execution via ND6 Router Advertisements
Unknown
0
Affected Vendor
FreeBSD
View all reports →Affected Software
FreeBSD
Vulnerable Versions:
14.1-RELEASE, 13.4-RELEASE, 13.3-RELEASE
Timeline
Official Publish:
November 12th, 2024
Last Modified:
January 10th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available