CVE-2023-3107

A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
freebsdCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
freebsdfreebsd
12.4
freebsdfreebsd
12.4:p1
freebsdfreebsd
12.4:p2
freebsdfreebsd
12.4:p3
freebsdfreebsd
12.4:rc2-p1
freebsdfreebsd
12.4:rc2-p2
freebsdfreebsd
13.1
freebsdfreebsd
13.1:b1-p1
freebsdfreebsd
13.1:b2-p2
freebsdfreebsd
13.1:p1
freebsdfreebsd
13.1:p2
freebsdfreebsd
13.1:p3
freebsdfreebsd
13.1:p4
freebsdfreebsd
13.1:p5
freebsdfreebsd
13.1:p6
freebsdfreebsd
13.1:p7
freebsdfreebsd
13.1:p8
freebsdfreebsd
13.1:rc1-p1
freebsdfreebsd
13.2
freebsdfreebsd
13.2:p1
netappclustered_data_ontap
9.0
𝑥
= Vulnerable software versions