CVE-2021-29631: High severity freebsd kernel vulnerability
In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors. A malicious guest may cause the device model to operate on uninitialized I/O vectors leading to memory corruption, crashing of the bhyve process, and possibly arbitrary code execution in the bhyve process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this FreeBSD vulnerability?
The vulnerability ID for this FreeBSD vulnerability is CVE-2021-29631.
What is the severity of CVE-2021-29631?
The severity of CVE-2021-29631 is high with a CVSS score of 7.8.
Which versions of FreeBSD are affected by CVE-2021-29631?
FreeBSD 13.0-STABLE, 12.2-STABLE, 11.4-STABLE, 13.0-RELEASE, 12.2-RELEASE, and 11.4-RELEASE are affected by CVE-2021-29631.
What is the description of CVE-2021-29631?
CVE-2021-29631 is a vulnerability in FreeBSD's bhyve virtualization feature that allows a malicious guest to cause a denial-of-service condition.
How can I fix CVE-2021-29631?
Apply the necessary patches provided by FreeBSD to fix CVE-2021-29631.