CVE-2026-7164: Freebsd
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset.
Affected products
- Freebsd Freebsd: version 13.5 only; version 14.3 only; version 14.4 only; version 15.0 only
Published 2026-04-30. Last modified 2026-06-17.