Remote root vulnerability in the IPv6 autoconfiguration handler in FreeBSD.
A vulnerability (CVE-2025-14558) has been discovered in the rtsold background process and the rtsol utility used in FreeBSD, which allows remote code execution with root privileges by sending a specially crafted packet with an IPv6 router advertisement. RA messages (Router Advertisement), which exploit this vulnerability, are not routed and should be discarded by routers. To carry out the attack, the attacker must have the ability to send a specially crafted packet from a system, […]
