Double Free Vulnerability in FreeBSD Listening Socket Accept Filters

Double Free Vulnerability in FreeBSD Listening Socket Accept Filters

CVE-2021-29627 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.

Learn more about our Web Application Penetration Testing UK.