A remote attacker can crash NetBSD systems using ipfilter by triggering a null pointer dereference in kernel code, affecting edge network devices. A 4-byte TCP timestamp leak exposes kernel stack memory including addresses needed to bypass memory randomization protections in exploit chains.