PT-2025-51803 · Freebsd · Freebsd

Published

2025-12-16

·

Updated

2026-03-09

·

CVE-2025-14769

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ipfw versions (affected versions not specified)
Description The tcp-setmss handler may free packet data and generate an error without stopping rule processing. A subsequent rule could then allow traffic to pass after the packet data is removed, leading to a NULL pointer dereference. Maliciously crafted packets from a remote host could cause a Denial of Service (DoS) if the tcp-setmss directive is used and a following rule permits the traffic. The vulnerable component is the tcp-setmss directive.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-14769
FREEBSD-SA-25_11

Affected Products

Freebsd