Vulnerability in FreeBSD Exploited via Malicious USB Device
A vulnerability in the USB stack (CVE-2020-7456) has been addressed in FreeBSD, which allows code execution at the kernel level or in user space when a malicious USB device is connected to the system. USB HID (Human Interface Device) descriptors can place and extract the current state, allowing the consolidation of element descriptions into multilevel groups. FreeBSD supports up to 4 such levels of extraction. If a level is not specified, it defaults to the highest one.
