Ars Technica wrote a report on the debacle[1], and I've since stopped using pfsense. I was already on the fence following their move away from open-source with "pfSense Plus"[2].
[1] https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...
[2] https://www.phoronix.com/scan.php?page=news_item&px=Netgate-...