Executive brief
A vulnerability in the FreeBSD operating system's union file system allows a local user to crash the system. By executing specific commands related to mounting file systems, an attacker can force the computer to reload or reboot. This results in a denial of service, interrupting operations and potentially causing unsaved data to be lost.
Technical details
A denial of service vulnerability exists in the union file system (unionfs) of FreeBSD 2.2 and earlier. The flaw is triggered when a local user executes a specific sequence of 'mount_union' commands, which leads to a kernel-level failure and subsequent system reload. This is a local attack requiring shell access to the target system. The vulnerability stems from improper handling of union mounts, a feature that allows multiple directories to appear as one. A patch was historically provided in FreeBSD security advisory SA-96:10.
Affected products
- FreeBSD FreeBSD 2.2 and earlier
Timeline
- 1996-05-17: advisory: Initial publication of the vulnerability details.