HarborGuard / CVE
Back to search
HIGHCVE-2026-7164Published Modified CNA freebsd

CVE-2026-7164: pf can overflow the stack parsing crafted SCTP packets

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
p12
Affected Products
1

Fix available

p12p13p3p7
Affected packages
  • FreeBSD / FreeBSD
    < p7 (from 15.0-RELEASE) · < p3 (from 14.4-RELEASE) · < p12 (from 14.3-RELEASE) · < p13 (from 13.5-RELEASE)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H