CVE-2025-14769

In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer dereference. Maliciously crafted packets sent from a remote host may result in a Denial of Service (DoS) if the `tcp-setmss` directive is used and a subsequent rule would allow the traffic to pass.
Configurations

No configuration.

History

09 Mar 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

09 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 12:16

Updated : 2026-03-09 14:16


NVD link : CVE-2025-14769

Mitre link : CVE-2025-14769

CVE.ORG link : CVE-2025-14769


JSON object : View

Products Affected

No product.

CWE
CWE-476

NULL Pointer Dereference