Unrated severityNVD Advisory· Published Mar 9, 2026· Updated Mar 9, 2026
ipfw denial of service
CVE-2025-14769
Description
In some cases, the tcp-setmss handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer dereference.
Maliciously crafted packets sent from a remote host may result in a Denial of Service (DoS) if the tcp-setmss directive is used and a subsequent rule would allow the traffic to pass.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- security.freebsd.org/advisories/FreeBSD-SA-25:11.ipfw.ascmitrevendor-advisory
News mentions
0No linked articles in our index yet.