The pftestrule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.
Integer signedness error in the fwioctl (FWIOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crombuf->len in an FWGCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.
On 6/10/26 15:19, bumsrakete wrote: Affected versions
Vulnerable (verified or by inspection): - FreeBSD 13.0, 13.1, 13.2, 13.3, 13.4 - FreeBSD 14.0, 14.1, 14.2 - FreeBSD 15.0-RELEASE (verified on 15.0-RELEASE-p5/amd64) This would also impact MidnightBSD 4.0+
Lucas