CVE-2026-7164: pf can overflow the stack parsing crafted SCTP packets
Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7164?
CVE-2026-7164 has a high severity level due to potential stack overflow and system panic.
How do I fix CVE-2026-7164?
To mitigate CVE-2026-7164, update to the latest version of OpenBSD pf that addresses the vulnerability.
What systems are affected by CVE-2026-7164?
CVE-2026-7164 affects any system running OpenBSD pf that is susceptible to crafted SCTP packets.
Can CVE-2026-7164 be exploited remotely?
Yes, CVE-2026-7164 can be exploited remotely by an attacker sending crafted SCTP packets.
What happens if CVE-2026-7164 is successfully exploited?
If exploited, CVE-2026-7164 can cause a stack overflow, leading to system panic and crash.