CVE-2021-29629: Input Validation
In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10, missing message validation in libradius(3) could allow malicious clients or servers to trigger denial of service in vulnerable servers or clients respectively.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-29629?
CVE-2021-29629 is a vulnerability in FreeBSD that allows malicious clients or servers to trigger denial of service.
Which versions of FreeBSD are affected by CVE-2021-29629?
FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10 are affected by CVE-2021-29629.
What is the severity of CVE-2021-29629?
The severity of CVE-2021-29629 is high with a CVSS score of 7.5 (out of 10).
How can I fix CVE-2021-29629?
To fix CVE-2021-29629, users should update their FreeBSD installations to the patched versions provided by FreeBSD.
Where can I find more information about CVE-2021-29629?
More information about CVE-2021-29629 can be found in the FreeBSD Security Advisory FreeBSD-SA-21:12.libradius.asc and the NetApp advisory ntap-20210713-0003.