CVE-2026-4652 is a denial-of-service vulnerability impacting systems exposing an NVMe/TCP target. A remote, unauthenticated attacker can trigger a kernel panic and subsequent system crash by sending a CONNECT command with a bogus or stale CNTLID. This vulnerability carries a CVSS score of 7.5 (High) due to its network-based attack vector and low attack complexity, resulting in a complete loss of availability for the affected machine. There is currently no evidence of active exploitation, nor is public exploit code or Metasploit modules available. While community discussion is minimal and its EPSS score is very low, organizations utilizing NVMe/TCP targets should be aware of this unauthenticated denial of service risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:15.0:-:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:15.0:p1:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:15.0:p2:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:15.0:p3:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:15.0:p4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.