Back

HIGH

ipfw denial of service

Published Mar 9, 2026

Description

In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer dereference.

Maliciously crafted packets sent from a remote host may result in a Denial of Service (DoS) if the `tcp-setmss` directive is used and a subsequent rule would allow the traffic to pass.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner freebsd
Published Mar 9, 2026
Updated Mar 9, 2026
Reserved Dec 16, 2025
CISA Vulnrichment
Updated Mar 9, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner freebsd
Published Mar 9, 2026
Updated Mar 9, 2026
Exploited since n/a
EUVD-2025-208405