CVE-2023-6534: TCP spoofing vulnerability in pf(4)
Published Dec 13, 2023
·Updated
In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9, the pf(4) packet filter incorrectly validates TCP sequence numbers. This could allow a malicious actor to execute a denial-of-service attack against hosts behind the firewall.
Affected Software
23 affected components
FreeBSD FreeBSD=12.4
FreeBSD FreeBSD=12.4-p1
FreeBSD FreeBSD=12.4-p2
FreeBSD FreeBSD=12.4-p3
FreeBSD FreeBSD=12.4-p4
FreeBSD FreeBSD=12.4-p5
FreeBSD FreeBSD=12.4-p6
FreeBSD FreeBSD=12.4-p7
FreeBSD FreeBSD=12.4-p8
FreeBSD FreeBSD=12.4-rc2-p1
FreeBSD FreeBSD=12.4-rc2-p2
FreeBSD FreeBSD=13.2
FreeBSD FreeBSD=13.2-p1
FreeBSD FreeBSD=13.2-p2
FreeBSD FreeBSD=13.2-p3
FreeBSD FreeBSD=13.2-p4
FreeBSD FreeBSD=13.2-p5
FreeBSD FreeBSD=13.2-p6
FreeBSD FreeBSD=14.0
FreeBSD FreeBSD=14.0-beta5
FreeBSD FreeBSD=14.0-p1
FreeBSD FreeBSD=14.0-rc3
FreeBSD FreeBSD=14.0-rc4-p1
Event History
Dec 13, 2023
CVE Published
via MITRE·08:12 AM
Data Sourced
via MITRE·08:12 AM
Description
Data Sourced
via NVD·09:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6534?
CVE-2023-6534 has been classified as a denial-of-service vulnerability.
2
How do I fix CVE-2023-6534?
To fix CVE-2023-6534, upgrade to FreeBSD versions 12.4-RELEASE-p9, 13.2-RELEASE-p7, or 14.0-RELEASE-p2 or later.
3
Which versions of FreeBSD are affected by CVE-2023-6534?
CVE-2023-6534 affects FreeBSD versions 12.4 before p9, 13.2 before p7, and 14.0 before p2.
4
What kind of attack can CVE-2023-6534 lead to?
CVE-2023-6534 can be exploited to execute a denial-of-service attack against the affected systems.
5
When was CVE-2023-6534 disclosed?
CVE-2023-6534 was disclosed in October 2023.