In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour including a kernel panic.
Conclusion & alert: CVE-2020-7463 is rated Low Risk (33.4/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.40%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.40% | +0.35% |
| 2 | 2025-04-28 | 0.08% | 0.05% | -0.03% |
| 3 | 2025-03-17 | — | 0.08% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 4.9 | 2.0 | MEDIUM |
|
3.9 | 6.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:-:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p1:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p10:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p11:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p12:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p2:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p3:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p4:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p5:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p6:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p7:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p8:*:*:*:*:*:* |
| freebsd | freebsd | 11.3 | cpe:2.3:o:freebsd:freebsd:11.3:p9:*:*:*:*:*:* |
| freebsd | freebsd | 11.4 | cpe:2.3:o:freebsd:freebsd:11.4:-:*:*:*:*:*:* |
| freebsd | freebsd | 11.4 | cpe:2.3:o:freebsd:freebsd:11.4:p1:*:*:*:*:*:* |
| freebsd | freebsd | 11.4 | cpe:2.3:o:freebsd:freebsd:11.4:p2:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:-:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:p1:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:p2:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:p3:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:p4:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:p5:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:p6:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:p7:*:*:*:*:*:* |
| freebsd | freebsd | 12.1 | cpe:2.3:o:freebsd:freebsd:12.1:p8:*:*:*:*:*:* |
| freebsd | freebsd | 12.2 | cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:* |
| apple | icloud | < 12.3 | cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* |
| apple | itunes | < 12.11.3 | cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:* |
| apple | safari | < 14.1 | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
| apple | ipados | < 14.5 | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* |
| apple | iphone_os | < 14.5 | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
| apple | macos | >= 11.0, < 11.3 | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
| apple | tvos | < 14.5 | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
| apple | watchos | < 7.4 | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2021/Apr/49 | Mailing List Third Party Advisory |
| http://seclists.org/fulldisclosure/2021/Apr/50 | Mailing List Third Party Advisory |
| http://seclists.org/fulldisclosure/2021/Apr/57 | Mailing List Third Party Advisory |
| http://seclists.org/fulldisclosure/2021/Apr/58 | Mailing List Third Party Advisory |
| http://seclists.org/fulldisclosure/2021/Apr/59 | Mailing List Third Party Advisory |
| https://security.FreeBSD.org/advisories/FreeBSD-SA-20:25.sctp.asc | Vendor Advisory |
| https://support.apple.com/kb/HT212317 | Third Party Advisory |
| https://support.apple.com/kb/HT212318 | Third Party Advisory |
| https://support.apple.com/kb/HT212319 | Third Party Advisory |
| https://support.apple.com/kb/HT212321 | Third Party Advisory |
| https://support.apple.com/kb/HT212323 | Third Party Advisory |
| https://support.apple.com/kb/HT212324 | Third Party Advisory |
| https://support.apple.com/kb/HT212325 | Third Party Advisory |