#VU124683 Improper resource shutdown or release in FreeBSD - CVE-2026-4247
Published: March 30, 2026
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper memory management in the TCP stack when handling unexpected TCP segments that meet challenge ACK criteria. A remote attacker can send a specially crafted sequence of TCP packets to exceed the rate limit for challenge ACKs and trigger an mbuf leak, leading to resource exhaustion.
Off-path attackers may also exploit this issue by spoofing packets with guessed connection parameters, though this is more difficult.