ZeroHour

CVE-2026-7164

CVSS 3.1
7.5 high
EPSS
<1%p36
Published
()
Modified
Description

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset.

Vendors
freebsd
Products
freebsd
Weakness
CWE-674, CWE-791
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.