CVE-2019-5597
In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last received packet instead of the first packet allowing maliciously crafted IPv6 packets to cause a crash or potentially bypass the packet filter.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 3.63% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- freebsd/freebsd
- Source
- secteam@freebsd.org
References
- http://packetstormsecurity.com/files/152933/FreeBSD-Security-Advisory-FreeBSD-SA-19-05.pf.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108395
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:05.pf.ascPatch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190611-0001/
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.synacktiv.com/ressources/Synacktiv_OpenBSD_PacketFilter_CVE-2019-5597_ipv6_frag.pdfExploit, Third Party Advisory
- http://packetstormsecurity.com/files/152933/FreeBSD-Security-Advisory-FreeBSD-SA-19-05.pf.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108395
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:05.pf.ascPatch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190611-0001/
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.synacktiv.com/ressources/Synacktiv_OpenBSD_PacketFilter_CVE-2019-5597_ipv6_frag.pdfExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.