CVE-2014-7250: Bsd

Medium severity, CVSS 5.0. EPSS: 4.7% chance of exploitation in the next 30 days.

The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.

Affected products

  • Bsd Bsd: version 4.3 only
  • Freebsd Freebsd: version 5.4 only
  • Netbsd Netbsd: version 2.0 only
  • OpenBSD OpenBSD: version 3.6 only

Published 2014-12-12. Last modified 2026-06-17.