FreeBSD NVMe/TCP Remote Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in FreeBSD 15.0, specifically within the NVMe over Fabrics (nvmf) module. When an NVMe/TCP target is exposed, a remote client can cause a kernel panic by sending a CONNECT command for an I/O queue with an invalid or outdated CNTLID. This exploitation leads to an unauthenticated denial-of-service condition on the affected system.

Impact

Exploitation of this vulnerability causes a kernel panic, leading to a system crash.

Remediation

Users can upgrade to a supported FreeBSD stable or release/security branch dated after the correction date. For systems running FreeBSD 15.0-RELEASE on amd64 or arm64, installed via base system packages, the update can be performed using the pkg utility. For those not using base system packages, the freebsd-update utility can be used. Instructions for applying the update via a source code patch are also available.

Added: Mar 26, 2026, 7:22 AM
Updated: Mar 26, 2026, 7:22 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
4.3
remediation
7.7
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.