CVE-2023-40216
Dashboard / Vulnerabilities / CVE-2023-40216
CVE-2023-40216
Published: 10 Aug 2023Last Modified: 11 Feb 2026
Summary:
Details: OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.
References: https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/014_wscons.patch.sig, https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/014_wscons.patch.sig, https://github.com/openbsd/src/commit/9d3f688f46eba347e96ff0ae9506ef2061622e0c
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
