Lucene search

K
cveFreebsdCVE-2021-29627
HistoryApr 07, 2021 - 3:15 p.m.

CVE-2021-29627

2021-04-0715:15:13
CWE-415
CWE-416
freebsd
web.nvd.nist.gov
41
13
cve-2021-29627
freebsd
nvd
security
vulnerability
double free
use after free
socket
listening socket

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.

Affected configurations

Nvd
Node
freebsdfreebsdRange12.0–12.2
OR
freebsdfreebsdMatch12.2-
OR
freebsdfreebsdMatch12.2p1
OR
freebsdfreebsdMatch12.2p2
OR
freebsdfreebsdMatch13.0beta1
OR
freebsdfreebsdMatch13.0beta2
OR
freebsdfreebsdMatch13.0beta3
OR
freebsdfreebsdMatch13.0beta4
OR
freebsdfreebsdMatch13.0rc1
OR
freebsdfreebsdMatch13.0rc2
OR
freebsdfreebsdMatch13.0rc3
VendorProductVersionCPE
freebsdfreebsd*cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
freebsdfreebsd12.2cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*
freebsdfreebsd12.2cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:*
freebsdfreebsd12.2cpe:2.3:o:freebsd:freebsd:12.2:p2:*:*:*:*:*:*
freebsdfreebsd13.0cpe:2.3:o:freebsd:freebsd:13.0:beta1:*:*:*:*:*:*
freebsdfreebsd13.0cpe:2.3:o:freebsd:freebsd:13.0:beta2:*:*:*:*:*:*
freebsdfreebsd13.0cpe:2.3:o:freebsd:freebsd:13.0:beta3:*:*:*:*:*:*
freebsdfreebsd13.0cpe:2.3:o:freebsd:freebsd:13.0:beta4:*:*:*:*:*:*
freebsdfreebsd13.0cpe:2.3:o:freebsd:freebsd:13.0:rc1:*:*:*:*:*:*
freebsdfreebsd13.0cpe:2.3:o:freebsd:freebsd:13.0:rc2:*:*:*:*:*:*
Rows per page:
1-10 of 111

CNA Affected

[
  {
    "product": "FreeBSD",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "FreeBSD 12.2-RELEASE before p6"
      }
    ]
  }
]

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%