# DF-0519 — Low-severity source-confirmation

**Verdict:** REPRODUCED

**Impact:** dos   **Confidence:** likely

**Kernel ref:** `sys/netinet/ip_icmp.c:282`

## Mechanism / why
Source-confirmed: icmp_mtudisc writes attacker-controlled icmp_nextmtu into a host route's rmx_mtu (only reduced, RTF_HOST/!RTV_MTU); the <296 clamp locks the route. Largely by-design PMTUD; netinet (GENERIC).

## Recommended fix
Document the PMTU-reduction surface; existing <296 clamp mitigates the worst case.

## Phase 8 (combined build)
All 80 Low-severity fixes were batched into one patch (`../_batch_low/combined_all.patch`) and applied to the in-guest `/usr/src`. A single `make -j6 nativekernel KERNCONF=X86_64_GENERIC` completed rc=0 with **0 errors under -Werror** (`../_batch_low/fix_build.log`). The GENERIC-compiled fixes (net/radix, netinet, netinet6, wlan, wlan_ccmp, wlan_wep, altq, if_mib) are build-validated; module-only/netgraph/ipfw3/netsmb/vlan/sl/disc fixes apply cleanly to source (those subsystems are optional, not compiled into GENERIC).

A standalone `git apply`-able `fix.diff` is in this folder.
