Remote Denial of Service Vulnerability in FreeBSD NVMe/TCP Target
CVE-2026-4652
7.5HIGH
What is CVE-2026-4652?
A vulnerability exists in FreeBSD's NVMe/TCP target implementation where an attacker can trigger a kernel panic by sending a malformed or outdated CNTLID in a CONNECT command. This can lead to a remote Denial of Service condition, allowing unauthenticated clients with network access to incapacitate the target system. Administrators are advised to apply security updates to mitigate this risk and protect their systems from potential exploitation.
Affected Version(s)
FreeBSD 15.0-RELEASE
