CVE-2021-29632
Last modified
CVE-2021-29632 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures associated with the system console or other kernel memory.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures associated with the system console or other kernel memory.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 12.2 |
| Freebsd | Freebsd | 13.0 |
References
- https://security.freebsd.org/advisories/FreeBSD-SA-22:01.vt.ascMitigation, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20220217-0004/Third Party Advisory
- https://security.freebsd.org/advisories/FreeBSD-SA-22:01.vt.ascMitigation, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20220217-0004/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-29632?
How severe is CVE-2021-29632?
How do I fix CVE-2021-29632?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-29626In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r3…5.5
- CVE-2021-29627In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r3…7.8
- CVE-2021-29628In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STA…7.5
- CVE-2021-29629In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STA…7.5
- CVE-2021-29630In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STA…8.1
- CVE-2021-29631In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STA…7.8
- CVE-2021-29633Rejected reason: This candidate was in a CNA pool that was n…
- CVE-2021-29634Rejected reason: This candidate was in a CNA pool that was n…
- CVE-2021-29635Rejected reason: This candidate was in a CNA pool that was n…
- CVE-2021-29636Rejected reason: This candidate was in a CNA pool that was n…
- CVE-2021-29637Rejected reason: This candidate was in a CNA pool that was n…
- CVE-2021-29638Rejected reason: This candidate was in a CNA pool that was n…
Are you affected by CVE-2021-29632?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
