#VU124680 Input validation error in FreeBSD - CVE-2026-4748
Published: March 30, 2026
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an error in pf packet filter implementation when handling rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address ranges. A remote attacker can bypass previously configured rules and gain unauthorized access to the system bypassing packet filtering.