HIGH
ipfw denial of service
Published Mar 9, 2026
7.5
HIGHCVSS 3.1
EPSS 1.14%
Description
In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer dereference.
Maliciously crafted packets sent from a remote host may result in a Denial of Service (DoS) if the `tcp-setmss` directive is used and a subsequent rule would allow the traffic to pass.
Affected products
-
- Version 13.5-RELEASEStatusaffectedConstraints<p8
- Version 14.3-RELEASEStatusaffectedConstraints<p7
- Version
OR
- 13.5
- 13.5
- 13.5
- 13.5
- 13.5
- 13.5
- 13.5
- 13.5
- 14.3
- 14.3
- 14.3
- 14.3
- 14.3
- 14.3
- 14.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208405 Advisory
- https://security.freebsd.org/advisories/FreeBSD-SA-25:11.ipfw.asc vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208405 | Advisory | |
| https://security.freebsd.org/advisories/FreeBSD-SA-25:11.ipfw.asc | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner freebsd
Published Mar 9, 2026
Updated Mar 9, 2026
Reserved Dec 16, 2025
Link CVE-2025-14769
CISA Vulnrichment
Updated Mar 9, 2026
ENISA EUVD
EUVD-2025-208405 Assigner freebsd
Published Mar 9, 2026
Updated Mar 9, 2026
Exploited since n/a
Link EUVD-2025-208405