# DF-0478 - Verification Verdict

**Verdict:** REPRODUCED (source-only confirmation)

**Bug class:** ub

**Impact:** none

**Source file:** `sys/net/ipfw3/ip_fw3.c`

## Mechanism

CONFIRMED: ctx->sets & (1 << f->set). f->set is uint8_t(0-255). set>=32: 1<<set is UB. Fix: check f->set < 32.

## Fix

See `fix.diff` for the git-apply-able patch.

## Build validation

Combined kernel build with all 70 Low-severity fixes: **rc=0, -Werror**.
All fixes compile cleanly in `X86_64_GENERIC` kernel configuration.

**Guest:** DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul  2 06:02:54 UTC 2026     root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC  x86_64
