CVE-2021-29627
Severity CVSS v4.0:
Pending analysis
Type:
CWE-415
Double Free
Publication date:
07/04/2021
Last modified:
27/05/2022
Description
In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* | 12.0 (including) | 12.2 (excluding) |
| cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:12.2:p2:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.0:beta4:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:13.0:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



