Stack-based buffer overflow in FreeBSD - CVE-2026-7164
Published: April 30, 2026
FreeBSD
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in pf SCTP packet parsing when processing crafted SCTP packets. A remote attacker can send a specially crafted SCTP packet to cause a denial of service.
This affects systems where pf is configured to process traffic, independent of the configured ruleset.