CVE-2026-7164
גבוהה 7.5
תיאור (מקור, אנגלית)
Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-27/9/2026
- CWE
- CWE-674, CWE-791
מוצרים מושפעים
freebsd: freebsd
קישורים
- https://security.freebsd.org/advisories/FreeBSD-SA-26:14.pf.asc Vendor Advisory