CVE-2026-4652 Details
Description
On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an I/O queue with a bogus or stale CNTLID. An attacker with network access to the NVMe/TCP target can trigger an unauthenticated Denial of Service condition on the affected machine.
A denial-of-service vulnerability has been identified in FreeBSD 15.0, specifically within the NVMe over Fabrics (nvmf) module. When an NVMe/TCP target is exposed, a remote client can cause a kernel panic by sending a CONNECT command for an I/O queue with an invalid or outdated CNTLID. This exploitation leads to an unauthenticated denial-of-service condition on the affected system.
Users can upgrade to a supported FreeBSD stable or release/security branch dated after the correction date. For systems running FreeBSD 15.0-RELEASE on amd64 or arm64, installed via base system packages, the update can be performed using the pkg utility. For those not using base system packages, the freebsd-update utility can be used. Instructions for applying the update via a source code patch are also available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.freebsd.org/advisories/FreeBSD-SA-26:07.nvmf.asc | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| freebsd freebsd | 15.0 - 15.0 p1 15.0 p2 15.0 p3 15.0 p4 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | New CVE Received | [email protected] |