pf is an Internet Protocol packet filter originally written for OpenBSD. In addition to filtering packets, it also has packet normalization capabilities. A logic bug in pf's IP fragment cache may result in a packet fragment being inserted twice, violating a kernel invariant.