Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic.
Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 30 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freebsd
Freebsd freebsd |
|
| Vendors & Products |
Freebsd
Freebsd freebsd |
Thu, 30 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset. | |
| Title | pf can overflow the stack parsing crafted SCTP packets | |
| Weaknesses | CWE-674 CWE-791 |
|
| References |
|
Status: PUBLISHED
Assigner: freebsd
Published:
Updated: 2026-04-30T13:09:07.760Z
Reserved: 2026-04-27T06:03:58.316Z
Link: CVE-2026-7164
Updated: 2026-04-30T13:09:03.574Z
Status : Received
Published: 2026-04-30T08:16:07.653
Modified: 2026-04-30T08:16:07.653
Link: CVE-2026-7164
No data.
OpenCVE Enrichment
Updated: 2026-04-30T09:30:15Z