Get a Quote   (408) 943-4100               TrueNAS Discord      VendOp_Icon_15x15px   Commercial Support

Versions Affected : All versions prior to TrueNAS 12.0-U6


Description

Certain VirtIO-based device models failed to handle errors when fetching I/O descriptors.

Such errors could be triggered by a malicious guest. As a result, the device model code could be tricked into operating on uninitialized I/O vectors, leading to memory corruption.


Workaround

No workaround is available. Virtual machines are unaffected unless they use one or more of the following device models: + virtio-console + virtio-rnd + virtio-scsi (available starting in FreeBSD 12.0)


Mitigation

  • Upgrade to TrueNAS 12.0-U6 or later.

Commit


Further information