High severity7.5NVD Advisory· Published May 15, 2019· Updated Jun 17, 2026
CVE-2019-5598
CVE-2019-5598
Description
In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in pf does not check if the outer ICMP or ICMP6 packet has the same destination IP as the source IP of the inner protocol packet allowing a maliciously crafted ICMP/ICMP6 packet could bypass the packet filter rules and be passed to a host that would otherwise be unavailable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:o:freebsd:freebsd:11.2:-:*:*:*:*:*:*+ 11 more
- cpe:2.3:o:freebsd:freebsd:11.2:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:11.2:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:11.2:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:11.2:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:11.2:p5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:11.2:p6:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:11.2:p7:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:11.2:p9:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:11.2:rc3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.0:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.0:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.0:p3:*:*:*:*:*:*
- FreeBSD/FreeBSDdescription
Patches
Vulnerability mechanics
References
7- security.freebsd.org/advisories/FreeBSD-SA-19:06.pf.ascnvdPatchVendor Advisory
- packetstormsecurity.com/files/152934/FreeBSD-Security-Advisory-FreeBSD-SA-19-06.pf.htmlnvdThird Party AdvisoryVDB Entry
- www.synacktiv.com/posts/systems/icmp-reachable.htmlnvdThird Party Advisory
- seclists.org/fulldisclosure/2025/Apr/1nvd
- www.securityfocus.com/bid/108395nvd
- security.netapp.com/advisory/ntap-20190611-0001/nvd
- www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlnvd
News mentions
0No linked articles in our index yet.