CVE-2021-29627: Double Free
In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accfcreate callback incorrectly freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-29627?
CVE-2021-29627 is a vulnerability in FreeBSD that affects versions before n245050, r369525, p0, and p6.
How does the vulnerability in FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6 occur?
The vulnerability occurs due to listening socket accept filters implementing the accf_create callback incorrectly freeing a process supplied argument string.
What is the severity of CVE-2021-29627?
The severity of CVE-2021-29627 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2021-29627?
FreeBSD versions before n245050, r369525, p0, and p6 are affected by CVE-2021-29627.
How can I fix the vulnerability in FreeBSD?
To fix the vulnerability, you should update to version n245050 or apply the relevant patches provided by FreeBSD.