Off-by-one in FreeBSD - CVE-2026-101302
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an off-by-one error in the receive-side kernel TLS record-type search when processing a specially crafted TLS 1.3 record. A remote attacker can send a specially crafted TLS 1.3 record to cause a denial of service.
Exploitation requires an application to enable receive-side software KTLS.