FreeBSD ping(8) contains a stack-based buffer overflow in the pr_pack() packet-processing routine. When processing ICMP responses, pr_pack() reconstructs and copies the outer IP/ICMP headers and, for ICMP errors, a quoted packet (with its own IP/ICMP headers) into fixed-size stack buffers. The implementation fails to account for the presence of IP option headers following the IP header in either the response packet or the quoted packet, resulting in an overflow of the destination stack buffer by up to 40 bytes when IP options are present. The bug can be triggered by a remote host via crafted network traffic, leading at least to a crash of the ping process; FreeBSD notes ping runs in a capability-mode sandbox, constraining post-crash impact.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Small standalone exploit repository for CVE-2022-23093 targeting the FreeBSD ping utility. The repository contains only three files: an Apache 2.0 LICENSE, a README describing the vulnerability and exploitation concept, and a single C source file (main.c) that serves as the exploit entry point. The exploit is not part of a larger framework. The README explains that FreeBSD's ping pr_pack() function can overflow stack buffers when processing ICMP packets containing IP options, especially in quoted packets embedded in ICMP error responses. It identifies /sbin/ping as the vulnerable userspace binary and frames the bug as a stack-based overflow reachable through malformed ICMP traffic. The C code creates a raw AF_INET/SOCK_RAW socket using IPPROTO_ICMP, accepts one IPv4 target address from the command line, builds a 1024-byte ICMP echo packet, fills most of the payload with 'A' bytes, and inserts hardcoded x86-64 shellcode that executes /bin/sh. It computes the ICMP checksum, sends the packet to the target, receives one ICMP response, parses and prints basic IP/ICMP header fields, optionally prints any quoted packet data for ICMP_DEST_UNREACH or ICMP_TIME_EXCEEDED responses, then recomputes the checksum and sends the packet again. Main exploit capability: delivery of crafted ICMP traffic with an embedded payload intended to trigger the vulnerable ping packet-processing path and achieve code execution. However, the implementation is fairly primitive: it does not explicitly construct IP options or a fully realistic malformed quoted packet sequence as described in the README, so it appears more like an operational proof-of-concept scaffold than a polished exploit chain. Still, because it includes a real shell payload and raw packet delivery logic, it is best classified as OPERATIONAL rather than a pure POC. Notable observables are limited: the vulnerable local binary path /sbin/ping, the operator-provided target IPv4 address, use of ICMP over raw sockets, and the /bin/sh string embedded in shellcode. No hardcoded remote IPs, domains, C2 infrastructure, registry keys, or persistence mechanisms are present.
This repository contains a proof-of-concept exploit for CVE-2022-23093, a stack-based buffer overflow in the FreeBSD 'ping' utility. The exploit is implemented in C (main.c) and constructs a raw ICMP ECHO packet with a payload containing x86-64 shellcode. The shellcode is designed to execute /bin/sh on the target system. The exploit sends the crafted packet to a specified IP address, targeting the vulnerable /sbin/ping binary on FreeBSD. The README.md provides a detailed technical analysis of the vulnerability, including how the overflow occurs in the pr_pack() function when handling IP options in ICMP responses. The repository structure is simple, consisting of a license file, a README with vulnerability details, and the main exploit code. The exploit requires root privileges to send raw ICMP packets and is intended for use against FreeBSD systems with the vulnerable ping utility.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.