7.8

CVE-2021-29627

In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version >= 12.0 < 12.2
Freebsd ≫ Freebsd Version 12.2 Update -
Freebsd ≫ Freebsd Version 12.2 Update p1
Freebsd ≫ Freebsd Version 12.2 Update p2
Freebsd ≫ Freebsd Version 13.0 Update beta1
Freebsd ≫ Freebsd Version 13.0 Update beta2
Freebsd ≫ Freebsd Version 13.0 Update beta3
Freebsd ≫ Freebsd Version 13.0 Update beta4
Freebsd ≫ Freebsd Version 13.0 Update rc1
Freebsd ≫ Freebsd Version 13.0 Update rc2
Freebsd ≫ Freebsd Version 13.0 Update rc3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.501
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-415 Double Free

The product calls free() twice on the same memory address.

CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://security.FreeBSD.org/advisories/FreeBSD-SA-21:09.accept_filter.asc
Vendor Advisory
https://security.netapp.com/advisory/ntap-20210423-0007/
Third Party Advisory