7.8

CVE-2021-29631

In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors. A malicious guest may cause the device model to operate on uninitialized I/O vectors leading to memory corruption, crashing of the bhyve process, and possibly arbitrary code execution in the bhyve process.

Data is provided by the National Vulnerability Database (NVD)
FreebsdFreebsd Version11.4 Update-
FreebsdFreebsd Version11.4 Updatep1
FreebsdFreebsd Version11.4 Updatep10
FreebsdFreebsd Version11.4 Updatep11
FreebsdFreebsd Version11.4 Updatep12
FreebsdFreebsd Version11.4 Updatep13
FreebsdFreebsd Version11.4 Updatep2
FreebsdFreebsd Version11.4 Updatep3
FreebsdFreebsd Version11.4 Updatep4
FreebsdFreebsd Version11.4 Updatep5
FreebsdFreebsd Version11.4 Updatep6
FreebsdFreebsd Version11.4 Updatep7
FreebsdFreebsd Version11.4 Updatep8
FreebsdFreebsd Version11.4 Updatep9
FreebsdFreebsd Version12.2 Update-
FreebsdFreebsd Version12.2 Updatep1
FreebsdFreebsd Version12.2 Updatep10
FreebsdFreebsd Version12.2 Updatep2
FreebsdFreebsd Version12.2 Updatep3
FreebsdFreebsd Version12.2 Updatep4
FreebsdFreebsd Version12.2 Updatep5
FreebsdFreebsd Version12.2 Updatep6
FreebsdFreebsd Version12.2 Updatep7
FreebsdFreebsd Version12.2 Updatep8
FreebsdFreebsd Version12.2 Updatep9
FreebsdFreebsd Version13.0 Update-
FreebsdFreebsd Version13.0 Updatep1
FreebsdFreebsd Version13.0 Updatep2
FreebsdFreebsd Version13.0 Updatep3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.117
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.