cvedb.io
CVE-2026-7164
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-04-30T08:16:07.653 · Last modified 2026-06-17T11:01:57.550

Summary

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset.

Affected products

freebsd — freebsd

Does this affect you?

Add your gear to cvedb and we'll alert you only when freebsd ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.