CVE-2023-4809CWE-167

pf incorrectly handles multiple IPv6 fragment headers

published September 6, 2023

CVSS
EPSS
1%
Percentile
50.1
In the wild
Unconfirmed
What it is

In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate payload. Instead a packet with multiple IPv6 fragment headers would unexpectedly be interpreted as a fragmented packet, rather than as whatever the real payload is.

As a result, IPv6 fragments may bypass pf firewall rules written on the assumption all fragments have been reassembled and, as a result, be forwarded or processed by the host.

The record
Technical detail
CVSS
Not scored
CVSS v4.0
Not supplied
EPSS
0.00680 · 50.1th percentile
Weakness
CWE-167 · Improper Handling of Additional Special Element
Published
2023-09-06T19:26Z
EPSS history
Timeline
  • 06 SEP 19:26Z
    pf incorrectly handles multiple IPv6 fragment headers
    cvelistv5