Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

8.00 - 8.5X: CVE-2021-29627 & : Is it possible with these CVEs? #5

Open
MrTweek1987 opened this issue Apr 15, 2021 · 1 comment
Open

Comments

@MrTweek1987
Copy link

MrTweek1987 commented Apr 15, 2021

CVE-2021-29627
In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly **freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.**

CVE-2021-29626
In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r369551, 11.4-STABLE before r369559, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, copy-on-write logic failed to invalidate shared memory page mappings between multiple processes allowing an unpriivleged process to maintain a mapping after it is freed, allowing the process to read private data belonging to other processes or the kernel.

@MrTweek1987 MrTweek1987 changed the title 8.00 - 8.5X: CVE-2021-29627: Is it possible with this CVE? 8.00 - 8.5X: CVE-2021-29627 & : Is it possible with these CVEs? Apr 15, 2021
@sleirsgoevy
Copy link
Owner

The first is the one reported by flatz, and the security advisory states that it is "FreeBSD >=12.2". PS4's OS is based on FreeBSD 9.
The second one is more interesting, but if it's read-only there is not much use of it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants