PT-2021-3570 · Freebsd · Freebsd

M00Nbsd

·

Published

2021-05-26

·

Updated

2022-05-16

·

CVE-2021-29628

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD versions 12.2-STABLE before r369857 FreeBSD versions 12.2-RELEASE before p7 FreeBSD versions 13.0-STABLE before n245764-876ffe28796c FreeBSD versions 13.0-RELEASE before p1
Description The issue is related to weaknesses in the authorization mechanism of the FreeBSD operating system kernel. It may allow a remote attacker to disable SMAP protection during a system call, potentially affecting the integrity of protected information. This weakness could be combined with other kernel bugs to craft an exploit.
Recommendations For FreeBSD versions 12.2-STABLE before r369857, update to a version after r369857 to resolve the issue. For FreeBSD versions 12.2-RELEASE before p7, update to a version after p7 to resolve the issue. For FreeBSD versions 13.0-STABLE before n245764-876ffe28796c, update to a version after n245764-876ffe28796c to resolve the issue. For FreeBSD versions 13.0-RELEASE before p1, update to a version after p1 to resolve the issue.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03671
CVE-2021-29628
FREEBSD-SA-21_11

Affected Products

Freebsd