HomeDefault status
unknown
15.0-RELEASE (release) before p5
affected
Description
On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an I/O queue with a bogus or stale CNTLID. An attacker with network access to the NVMe/TCP target can trigger an unauthenticated Denial of Service condition on the affected machine.
Problem types
CWE-476: NULL Pointer Dereference
Product status
15.0-RELEASE (release) before p5
Credits
Nikolay Denev <ndenev@gmail.com>
References
security.freebsd.org/advisories/FreeBSD-SA-26:07.nvmf.asc