In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour including a kernel panic.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | apple-itunes-upgrade-latest | Apr 27, 2021 | Mar 26, 2021 | |
| Apple Osx Webrtc | apple-osx-upgrade-latest | Aug 23, 2021 | Mar 26, 2021 | |
| Apple Safari | apple-safari-upgrade-14_1apple-safari-windows-uninstall | Apr 27, 2021 | Mar 26, 2021 | |
| Freebsd | freebsd-upgrade-base-12_1-release-p9freebsd-upgrade-base-11_4-release-p3freebsd-upgrade-base-11_3-release-p13 | Sep 3, 2020 | Sep 2, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub