CVE-2021-29630: High severity freebsd kernel vulnerability
In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response before writing it to a fixed-sized buffer allowing a malicious attacker in a privileged network position to overwrite the stack of ggatec and potentially execute arbitrary code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-29630?
CVE-2021-29630 is a vulnerability in FreeBSD versions before 13.0-STABLE n246938-0729ba2f49c9, 12.2-STABLE r370383, 11.4-STABLE r370381, 13.0-RELEASE p4, 12.2-RELEASE p10, and 11.4-RELEASE p13 that allows a malicious actor to write a response of any size to a fixed-sized buffer.
What is the severity of CVE-2021-29630?
The severity of CVE-2021-29630 is high, with a CVSS score of 8.1.
How does CVE-2021-29630 affect FreeBSD?
CVE-2021-29630 affects FreeBSD versions 11.4 through 13.0.
How can I fix CVE-2021-29630?
To fix CVE-2021-29630, users should update their FreeBSD installations to the patched versions available.
Where can I find more information about CVE-2021-29630?
More information about CVE-2021-29630 can be found in the FreeBSD security advisory and the NetApp advisory.