FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- Remote DoS via receive-side kernel TLS

Affected packages
15.1 <= FreeBSD-kernel < 15.1_4
15.0 <= FreeBSD-kernel < 15.0_14
14.5 <= FreeBSD-kernel < 14.5_1
14.4 <= FreeBSD-kernel < 14.4_10

Details

VuXML ID 36c2abd8-bcce-11f1-906f-bc241121aa0a
Discovery 2026-09-29
Entry 2026-09-30

Problem Description:

TLS 1.3 embeds the actual record type as the last non-zero byte of the decrypted payload, optionally followed by zero padding. The code which searches for the inner record type had an off-by-one bug which could be triggered by an invalid frame, leading to an underflow followed by an unconditional NULL pointer dereference, causing a kernel panic.

Impact:

A remote TLS 1.3 peer can send a specially crafted record to trigger a kernel panic, resulting in a Denial of Service (DoS).

References

CVE Name CVE-2026-101302
FreeBSD Advisory SA-26:67.ktls