git: dcda931e28 - main - Add EN-26:18, EN-26:19, and SA-26:50 through SA-26:55.
Gordon Tetlow <[email protected]> Wed, 29 Jul 2026 22:00:35 +0000
| Newsgroups | gmane.os.freebsd.devel.cvs.doc |
|---|---|
| Message-ID | <[email protected]> |
The branch main has been updated by gordon: URL: https://cgit.FreeBSD.org/doc/commit/?id=dcda931e282af1e8a5ad7724b1e620f481b7e969 commit dcda931e282af1e8a5ad7724b1e620f481b7e969 Author: Gordon Tetlow <[email protected]> AuthorDate: 2026-07-29 21:30:13 +0000 Commit: Gordon Tetlow <[email protected]> CommitDate: 2026-07-29 21:30:13 +0000 Add EN-26:18, EN-26:19, and SA-26:50 through SA-26:55. Approved by: so --- website/data/security/advisories.toml | 24 + website/data/security/errata.toml | 8 + .../advisories/FreeBSD-EN-26:18.tzdata.asc | 167 ++++ .../security/advisories/FreeBSD-EN-26:19.zfs.asc | 141 +++ .../advisories/FreeBSD-SA-26:50.kqueue.asc | 142 +++ .../advisories/FreeBSD-SA-26:51.ktimer.asc | 145 ++++ .../security/advisories/FreeBSD-SA-26:52.if_wg.asc | 164 ++++ .../advisories/FreeBSD-SA-26:53.ktrace.asc | 146 ++++ .../advisories/FreeBSD-SA-26:54.sysvsem.asc | 154 ++++ .../security/advisories/FreeBSD-SA-26:55.elf.asc | 155 ++++ .../security/patches/EN-26:18/tzdata-2026c.patch | 960 +++++++++++++++++++++ .../patches/EN-26:18/tzdata-2026c.patch.asc | 17 + website/static/security/patches/EN-26:19/zfs.patch | 380 ++++++++ .../static/security/patches/EN-26:19/zfs.patch.asc | 17 + .../static/security/patches/SA-26:50/kqueue.patch | 141 +++ .../security/patches/SA-26:50/kqueue.patch.asc | 17 + .../static/security/patches/SA-26:51/ktimer.patch | 16 + .../security/patches/SA-26:51/ktimer.patch.asc | 17 + .../security/patches/SA-26:52/if_wg-14.patch | 223 +++++ .../security/patches/SA-26:52/if_wg-14.patch.asc | 17 + .../security/patches/SA-26:52/if_wg-15.patch | 222 +++++ .../security/patches/SA-26:52/if_wg-15.patch.asc | 17 + .../static/security/patches/SA-26:53/ktrace.patch | 10 + .../security/patches/SA-26:53/ktrace.patch.asc | 17 + .../static/security/patches/SA-26:54/sysvsem.patch | 76 ++ .../security/patches/SA-26:54/sysvsem.patch.asc | 17 + .../static/security/patches/SA-26:55/elf-14.patch | 60 ++ .../security/patches/SA-26:55/elf-14.patch.asc | 17 + .../static/security/patches/SA-26:55/elf-15.patch | 60 ++ .../security/patches/SA-26:55/elf-15.patch.asc | 17 + 30 files changed, 3564 insertions(+) diff --git a/website/data/security/advisories.toml b/website/data/security/advisories.toml index 3dee86a4c6..7c3d11c7c1 100644 --- a/website/data/security/advisories.toml +++ b/website/data/security/advisories.toml @@ -1,6 +1,30 @@ # Sort advisories by year, month and day # $FreeBSD$ +[[advisories]] +name = "FreeBSD-SA-26:55.elf" +date = "2026-07-29" + +[[advisories]] +name = "FreeBSD-SA-26:54.sysvsem" +date = "2026-07-29" + +[[advisories]] +name = "FreeBSD-SA-26:53.ktrace" +date = "2026-07-29" + +[[advisories]] +name = "FreeBSD-SA-26:52.if_wg" +date = "2026-07-29" + +[[advisories]] +name = "FreeBSD-SA-26:51.ktimer" +date = "2026-07-29" + +[[advisories]] +name = "FreeBSD-SA-26:50.kqueue" +date = "2026-07-29" + [[advisories]] name = "FreeBSD-SA-26:49.iconv" date = "2026-06-30" diff --git a/website/data/security/errata.toml b/website/data/security/errata.toml index e6cb101d6d..92aafdccb4 100644 --- a/website/data/security/errata.toml +++ b/website/data/security/errata.toml @@ -1,6 +1,14 @@ # Sort errata notices by year, month and day # $FreeBSD$ +[[notices]] +name = "FreeBSD-EN-26:19.zfs" +date = "2026-07-29" + +[[notices]] +name = "FreeBSD-EN-26:18.tzdata" +date = "2026-07-29" + [[notices]] name = "FreeBSD-EN-26:17.rpcsec_tls" date = "2026-06-30" diff --git a/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc b/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc new file mode 100644 index 0000000000..97be7e2a66 --- /dev/null +++ b/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc @@ -0,0 +1,167 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +============================================================================= +FreeBSD-EN-26:18.tzdata Errata Notice + The FreeBSD Project + +Topic: Timezone database information update + +Category: contrib +Module: zoneinfo +Announced: 2026-07-29 +Affects: All supported versions of FreeBSD. +Corrected: 2026-07-11 09:48:44 UTC (stable/15, 15.1-STABLE) + 2026-07-29 17:50:24 UTC (releng/15.1, 15.1-RELEASE-p2) + 2026-07-29 17:50:00 UTC (releng/15.0, 15.0-RELEASE-p12) + 2026-07-11 09:52:47 UTC (stable/14, 14.4-STABLE) + 2026-07-29 17:49:33 UTC (releng/14.4, 14.4-RELEASE-p8) + +For general information regarding FreeBSD Errata Notices and Security +Advisories, including descriptions of the fields above, security branches, +and the following sections, please visit <URL:https://security.FreeBSD.org/>. + +I. Background + +The IANA Time Zone Database (often called tz or zoneinfo) contains code and +data that represent the history of local time for many representative +locations around the globe. It is updated periodically to reflect changes +made by political bodies to time zone boundaries, UTC offsets, and +daylight-saving rules. + +FreeBSD releases install the IANA Time Zone Database in /usr/share/zoneinfo. +The tzsetup(8) utility allows the user to specify the default local time +zone. Based on the selected time zone, tzsetup(8) copies one of the files +from /usr/share/zoneinfo to /etc/localtime. A time zone may also be selected +for an individual process by setting its TZ environment variable to a desired +time zone name. + +II. Problem Description + +Several changes to future and past timestamps have been recorded in the IANA +Time Zone Database after previous FreeBSD releases were released. This +affects many users in different parts of the world. Because of these +changes, the data in the zoneinfo files need to be updated. If the local +timezone on the running system is affected, tzsetup(8) needs to be run to +update /etc/localtime. + +III. Impact + +An incorrect time will be displayed on a system configured to use one of the +affected time zones if the /usr/share/zoneinfo and /etc/localtime files are +not updated, and all applications on the system that rely on the system time, +such as cron(8) and syslog(8), will be affected. + +IV. Workaround + +The system administrator can install an updated version of the IANA Time Zone +Database from the misc/zoneinfo port and run tzsetup(8). + +Applications that store and display times in Coordinated Universal Time (UTC) +are not affected. + +V. Solution + +Upgrade your system to a supported FreeBSD stable or release / security +branch (releng) dated after the correction date. + +Please note that some third party software, for instance PHP, Ruby, Java, +Perl and Python, may be using different zoneinfo data sources, in such cases +this software must be updated separately. Software packages that are +installed via binary packages can be upgraded by executing 'pkg upgrade'. + +Following the instructions in this Errata Notice will only update the IANA +Time Zone Database installed in /usr/share/zoneinfo. + +Perform one of the following: + +1) To update your system installed from base system packages: + +Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or +arm64 platforms, which were installed using base system packages, can be +updated via the pkg(8) utility: + +# pkg upgrade -r FreeBSD-base + +2) To update your system installed from binary distribution sets: + +Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms +which were not installed using base system packages can be updated via the +freebsd-update(8) utility: + +# freebsd-update fetch +# freebsd-update install + +3) To update your system via a source code patch: + +The following patches have been verified to apply to the applicable +FreeBSD release branches. + +a) Download the relevant patch from the location below, and verify the +detached PGP signature using your PGP utility. + +# fetch https://security.FreeBSD.org/patches/EN-26:18/tzdata-2026c.patch +# fetch https://security.FreeBSD.org/patches/EN-26:18/tzdata-2026c.patch.asc +# gpg --verify tzdata-2026c.patch.asc + +b) Apply the patch. Execute the following commands as root: + +# cd /usr/src +# patch -E -p0 < /path/to/patch + +c) Recompile the operating system using buildworld and installworld as +described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>. + +Restart all the affected applications and daemons, or reboot the system. + +VI. Correction details + +This issue is corrected as of the corresponding Git commit hash in the +following stable and release branches: + +Branch/path Hash Revision +- ------------------------------------------------------------------------- +stable/15/ 6470095eaa17 stable/15-n284437 +releng/15.1/ 3be83b93661d releng/15.1-n283583 +releng/15.0/ 8dd31fbcc50f releng/15.0-n281087 +stable/14/ 819af80de8e8 stable/14-n274491 +releng/14.4/ 7a227adc1ac6 releng/14.4-n273748 +- ------------------------------------------------------------------------- + +Run the following command to see which files were modified by a +particular commit: + +# git show --stat <commit hash> + +Or visit the following URL, replacing NNNNNN with the hash: + +<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> + +To determine the commit count in a working tree (for comparison against +nNNNNNN in the table above), run: + +# git rev-list --count --first-parent HEAD + +VII. References + +<URL:https://github.com/eggert/tz/blob/2026c/NEWS> + +The latest revision of this advisory is available at +<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-26:18.tzdata.asc> +-----BEGIN PGP SIGNATURE----- + +iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbjsbFIAAAAAABAAO +bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvWjEP/3AD86hhb4UDbCjoPCWg +X/lkCToUk9WXaEQqORQIFOxsUu2e4CHDWlFkUvAezEV4zzoLjh/KmUzxXpgjj4Ij +VF1pKgRBPMFQwtdrC9o106yoLAXJFGLlb1EG3jXUOHpOgMTtqCnYejp2NI0uXdDS +BL19NOZUq8uyW1bbQF1XRQHo9nvUA0fhNbRHLmvXvAQFHsWDbz1h/PvwiSNNZlHs +vOe9rqSqfOleTsj20V27kRC1/8C/0Ws29hVFWH1Zqb1x63f0nErfYAs/g9tJMdIl +n4zuxQyJueX+GJaolBHEKvNkGBf/nSRtJNSJydD5MWbzBHs+mt3oiKfqbfUCUiR/ +leyvYhYTczfiORT+GSuBzMEn2fnrP+i/7VyqmETgnEymkyDu6UyxWJIA/d57ajGv +M0GF62DYWtzjVHDvCChTPAAs4XNN26E/h8eATCNMNoLn39sQQFBjTo+36e4j7RnN +bQZc7wAwPONOyxjs8GPC7ix8Ytja5VbwIqpUw7P8NpG4RIE3mIOIHAkympT0U7rn +2xaU102yF3FlS3mUVO9KQyP0RrMhrY06av+MdkZqBcRLbX5CYw+AFcx4A2gU53vH +a5FPKgyJxcL9/TjrjfvXvRfPJ8xb2E2apqtL/Ih1Dx22XDqv0hQj8Rhrqj2ViY+w +BAQi1nCtevTlSbKBKMaCx/R0 +=5Yms +-----END PGP SIGNATURE----- diff --git a/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc b/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc new file mode 100644 index 0000000000..545c8c9af3 --- /dev/null +++ b/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc @@ -0,0 +1,141 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +============================================================================= +FreeBSD-EN-26:19.zfs Errata Notice + The FreeBSD Project + +Topic: Race conditions in zvol device management + +Category: contrib +Module: openzfs +Announced: 2026-07-29 +Affects: FreeBSD 15.1 and 15.0 +Corrected: 2026-07-27 17:33:34 UTC (stable/15, 15.1-STABLE) + 2026-07-29 17:50:28 UTC (releng/15.1, 15.1-RELEASE-p2) + 2026-07-29 17:50:04 UTC (releng/15.0, 15.0-RELEASE-p12) + +For general information regarding FreeBSD Errata Notices and Security +Advisories, including descriptions of the fields above, security branches, +and the following sections, please visit <URL:https://security.FreeBSD.org/>. + +I. Background + +ZFS is an advanced and scalable file system originally developed by Sun +Microsystems for its Solaris operating system. ZFS was integrated as part of +FreeBSD starting with FreeBSD 7.0. + +ZFS volumes (zvols) are ZFS datasets that appear as block devices. The +kernel creates and removes device nodes as zvols are created, destroyed, or +have their properties changed. + +II. Problem Description + +Several race conditions existed in interactions between the zvol device +management code and FreeBSD's GEOM subsystem. + +III. Impact + +Operations on zvols such as renaming, changing properties, or destroying a +zvol while it is being opened can cause a kernel panic. + +IV. Workaround + +No workaround is available. + +V. Solution + +Upgrade your system to a supported FreeBSD stable or release / security +branch (releng) dated after the correction date, and reboot the system. + +Perform one of the following: + +1) To update your system installed from base system packages: + +Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or +arm64 platforms, which were installed using base system packages, can be +updated via the pkg(8) utility: + +# pkg upgrade -r FreeBSD-base +# shutdown -r now + +2) To update your system installed from binary distribution sets: + +Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms +which were not installed using base system packages can be updated via the +freebsd-update(8) utility: + +# freebsd-update fetch +# freebsd-update install +# shutdown -r now + +3) To update your system via a source code patch: + +The following patches have been verified to apply to the applicable +FreeBSD release branches. + +a) Download the relevant patch from the location below, and verify the +detached PGP signature using your PGP utility. + +# fetch https://security.FreeBSD.org/patches/EN-26:19/zfs.patch +# fetch https://security.FreeBSD.org/patches/EN-26:19/zfs.patch.asc +# gpg --verify zfs.patch.asc + +b) Apply the patch. Execute the following commands as root: + +# cd /usr/src +# patch -E -p0 < /path/to/patch + +c) Recompile your kernel as described in +<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the +system. + +VI. Correction details + +This issue is corrected as of the corresponding Git commit hash in the +following stable and release branches: + +Branch/path Hash Revision +- ------------------------------------------------------------------------- +stable/15/ 698e0c419895 stable/15-n284603 +releng/15.1/ 596030c13dce releng/15.1-n283587 +releng/15.0/ 4316500c27c6 releng/15.0-n281091 +- ------------------------------------------------------------------------- + +Run the following command to see which files were modified by a +particular commit: + +# git show --stat <commit hash> + +Or visit the following URL, replacing NNNNNN with the hash: + +<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> + +To determine the commit count in a working tree (for comparison against +nNNNNNN in the table above), run: + +# git rev-list --count --first-parent HEAD + +VII. References + +<URL:https://github.com/openzfs/zfs/pull/18191> + +The latest revision of this advisory is available at +<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-26:19.zfs.asc> +-----BEGIN PGP SIGNATURE----- + +iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkIbFIAAAAAABAAO +bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvQBYP/1NHmJWw6qysoaKt/ixx +rKgRIK9hTj0+/JWPIn0M9HOD4bQevTPq0ZsX4rFhd7Ky+mzLh3UWCd1iCYpk+upr +5awrfKgA+E/UXG0Wax/9zutUYNnPrI8bwayMRAQ1JCodSsYu54NBtQFAwvkEogJw +yPQUE3bc/6kAaY+5hqGzfoZ2Vl0/Uhp0RTTWdKlSSMEv1RvdQz2gCF9akyJzN7IA +KFM24jGkMoFV6TojJCuVXgtpqF9MaofqDZu27HY0HVIEEeL/rFzel7UsPNyQ5OTX +I0tt97VjhPHEpbYbhDUfObFEnxgv8qsw3RWnb0RFttULJ+xcPoN1ASjn1N7g1pK/ +/SnOie9MJA2o9BVdPugRnj2nRmJ8IwOv235/rZwN9ChBeQXQTVxk0vgi49lzGLGB +yVb4Pc1d5gDGr+S+KBmCq51N1OxSHanQwfrvTmIUjwWalBUqxLWe9rr1Lb7PnoIn +b8M7NYR4XuX7uzeFKx0VHHFNjYhS9zwDLEVtsfBfcElApgURq/JOytJOXtJuznpw +qNwiz0hgn9Hnx8WHlWKybQ3tWwX4UTvr+fTfsGzwbJksuVZuvn7y+gnpPTSlA+Rp +g04H6N7Lcj+x15TQ452JcdzObfrshJXdXPbWLUxLSCmh4SP+3xpsEDlqsJUtX+WS +/5y3DQbqNNnvHz1ofJfEsP6k +=j9Br +-----END PGP SIGNATURE----- diff --git a/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc b/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc new file mode 100644 index 0000000000..885faf681c --- /dev/null +++ b/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc @@ -0,0 +1,142 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +============================================================================= +FreeBSD-SA-26:50.kqueue Security Advisory + The FreeBSD Project + +Topic: Use-after-free in kqueue copy-on-fork + +Category: core +Module: kqueue +Announced: 2026-07-29 +Credits: Hazley Samsudin of GovTech CSG +Affects: FreeBSD 15.1 +Corrected: 2026-07-29 17:48:38 UTC (stable/15, 15.1-STABLE) + 2026-07-29 17:50:29 UTC (releng/15.1, 15.1-RELEASE-p2) +CVE Name: CVE-2026-58083 + +For general information regarding FreeBSD Security Advisories, including +descriptions of the fields above, security branches, and the following +sections, please visit <URL:https://security.FreeBSD.org/>. + +I. Background + +The kqueue(2) event notification facility supports a copy-on-fork mode +(KQUEUE_CPONFORK) in which registered event filters (knotes) are duplicated +into the child process during fork(2). + +II. Problem Description + +While the kernel was copying knotes during fork, a knote with a timer-based +filter could fire and be enqueued on the kqueue's active list before the copy +was complete. The copy routine did not account for this and could enqueue +the new knote a second time, corrupting the active list. In addition, the +copy routine did not hold the appropriate locks while reading knote state, +allowing further races. + +III. Impact + +An unprivileged local user can trigger a use-after-free in the kernel, +potentially leading to privilege escalation. + +IV. Workaround + +No workaround is available. + +V. Solution + +Upgrade your vulnerable system to a supported FreeBSD stable or +release / security branch (releng) dated after the correction date, +and reboot the system. + +Perform one of the following: + +1) To update your vulnerable system installed from base system packages: + +Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or +arm64 platforms, which were installed using base system packages, can be +updated via the pkg(8) utility: + +# pkg upgrade -r FreeBSD-base +# shutdown -r +10min "Rebooting for a security update" + +2) To update your vulnerable system installed from binary distribution sets: + +Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms +which were not installed using base system packages can be updated via the +freebsd-update(8) utility: + +# freebsd-update fetch +# freebsd-update install +# shutdown -r +10min "Rebooting for a security update" + +3) To update your vulnerable system via a source code patch: + +The following patches have been verified to apply to the applicable +FreeBSD release branches. + +a) Download the relevant patch from the location below, and verify the +detached PGP signature using your PGP utility. + +# fetch https://security.FreeBSD.org/patches/SA-26:50/kqueue.patch +# fetch https://security.FreeBSD.org/patches/SA-26:50/kqueue.patch.asc +# gpg --verify kqueue.patch.asc + +b) Apply the patch. Execute the following commands as root: + +# cd /usr/src +# patch -E -p0 < /path/to/patch + +c) Recompile your kernel as described in +<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the +system. + +VI. Correction details + +This issue is corrected as of the corresponding Git commit hash in the +following stable and release branches: + +Branch/path Hash Revision +- ------------------------------------------------------------------------- +stable/15/ cb7cb40ae47b stable/15-n284642 +releng/15.1/ 5a4222a1b225 releng/15.1-n283588 +- ------------------------------------------------------------------------- + +Run the following command to see which files were modified by a +particular commit: + +# git show --stat <commit hash> + +Or visit the following URL, replacing NNNNNN with the hash: + +<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> + +To determine the commit count in a working tree (for comparison against +nNNNNNN in the table above), run: + +# git rev-list --count --first-parent HEAD + +VII. References + +<URL:https://www.cve.org/CVERecord?id=CVE-2026-58083> + +The latest revision of this advisory is available at +<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:50.kqueue.asc> +-----BEGIN PGP SIGNATURE----- + +iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkQbFIAAAAAABAAO +bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv0LsP/jNvCmjgjFj/yoF6f2VC +bHKymftfRZXrMj7xhO95IISFEwth5KwmrwS9e6nNwHBygRiH9AvAbrMREAhju8LK +jtPkh0kAyMuAVIIDCcpMtFrMHoCS2FyuHLifA0LWhD8ouxPleJ/AkrjBDo9QRx3U +REdng9J3nvq5N8rzon9yTqosv0qoPQD7y/QJPduzhFA6aPVK6MCHEmOtCjyUMUTS +8Lze1WFzlqMt1tRl+iVsLsZa9uameOb4D/GQMkT3OagYQQ8rDLtw0r3hyzmWEw9x +ckx3DgKNQygLY5nOvw7iHUbFdl3ovSAIjDbxRY0TV+UNVfcGhROL7GLkfg4YMVIf +o5+61XFUaavzYH03xgAVaSKhdNAEv/ybatA/F4HDGeqNVY1V9lqUMX9E+z/n7rfs +Y4theutEgwhO0ZJ3kB4WtkREEIovKOWDlPX+wbwxc2KUiEg6opkm0Ehjqt0p26+t +ReWevNgO2qXIFr7ch0JiHJpmI8/yoKwS4VJTizaT5FgYO0fLlOBhJX/YXSGqeOPG +V+Lb3MnLCGTSkRF4RckDq2ITWbRdQn0IEwYi2v1D6w5NYBd3weJdUioJUuUnXur/ +XweEflFDkNvcA4tOhn8ivMgKkT0xE4FEhBTa7ARlbsaE3/CTiu6Q4688lnKhxIzi +IXAWlS8Xup6fxlIakdBALCr0 +=BGt9 +-----END PGP SIGNATURE----- diff --git a/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc b/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc new file mode 100644 index 0000000000..60113db4c4 --- /dev/null +++ b/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc @@ -0,0 +1,145 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +============================================================================= +FreeBSD-SA-26:51.ktimer Security Advisory + The FreeBSD Project + +Topic: Kernel stack disclosure via timer_settime(2) + +Category: core +Module: ktimer +Announced: 2026-07-29 +Credits: Hazley Samsudin of GovTech CSG +Affects: FreeBSD 15.1 and 15.0 +Corrected: 2026-07-27 19:15:01 UTC (stable/15, 15.1-STABLE) + 2026-07-29 17:50:30 UTC (releng/15.1, 15.1-RELEASE-p2) + 2026-07-29 17:50:05 UTC (releng/15.0, 15.0-RELEASE-p12) +CVE Name: CVE-2026-58084 + +For general information regarding FreeBSD Security Advisories, including +descriptions of the fields above, security branches, and the following +sections, please visit <URL:https://security.FreeBSD.org/>. + +I. Background + +POSIX interval timers, managed by timer_create(2) and timer_settime(2), allow +a process to schedule periodic or one-shot notifications based on a specified +clock source. When timer_settime(2) is called with a non-NULL old_value +argument, the kernel returns the timer's previous setting. + +II. Problem Description + +To retrieve the previous timer value, the kernel calls realtimer_gettime(), +which obtains the current time for the timer's clock. For a timer using +CLOCK_TAI this can fail when no TAI offset has been configured, but the error +return was not checked, so the uninitialized output buffer was copied to +userspace. + +III. Impact + +An unprivileged local user can obtain uninitialized kernel stack memory by +creating a POSIX timer with CLOCK_TAI and calling timer_settime(2), +potentially disclosing sensitive kernel data. + +IV. Workaround + +No workaround is available. + +V. Solution + +Upgrade your vulnerable system to a supported FreeBSD stable or +release / security branch (releng) dated after the correction date, +and reboot the system. + +Perform one of the following: + +1) To update your vulnerable system installed from base system packages: + +Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or +arm64 platforms, which were installed using base system packages, can be +updated via the pkg(8) utility: + +# pkg upgrade -r FreeBSD-base +# shutdown -r +10min "Rebooting for a security update" + +2) To update your vulnerable system installed from binary distribution sets: + +Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms +which were not installed using base system packages can be updated via the +freebsd-update(8) utility: + +# freebsd-update fetch +# freebsd-update install +# shutdown -r +10min "Rebooting for a security update" + +3) To update your vulnerable system via a source code patch: + +The following patches have been verified to apply to the applicable +FreeBSD release branches. + +a) Download the relevant patch from the location below, and verify the +detached PGP signature using your PGP utility. + +# fetch https://security.FreeBSD.org/patches/SA-26:51/ktimer.patch +# fetch https://security.FreeBSD.org/patches/SA-26:51/ktimer.patch.asc +# gpg --verify ktimer.patch.asc + +b) Apply the patch. Execute the following commands as root: + +# cd /usr/src +# patch -E -p0 < /path/to/patch + +c) Recompile your kernel as described in +<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the +system. + +VI. Correction details + +This issue is corrected as of the corresponding Git commit hash in the +following stable and release branches: + +Branch/path Hash Revision +- ------------------------------------------------------------------------- +stable/15/ a4b5ff57ef85 stable/15-n284618 +releng/15.1/ e1c9b0b13a29 releng/15.1-n283589 +releng/15.0/ 3254ef000750 releng/15.0-n281092 +- ------------------------------------------------------------------------- + +Run the following command to see which files were modified by a +particular commit: + +# git show --stat <commit hash> + +Or visit the following URL, replacing NNNNNN with the hash: + +<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> + +To determine the commit count in a working tree (for comparison against +nNNNNNN in the table above), run: + +# git rev-list --count --first-parent HEAD + +VII. References + +<URL:https://www.cve.org/CVERecord?id=CVE-2026-58084> + +The latest revision of this advisory is available at +<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:51.ktimer.asc> +-----BEGIN PGP SIGNATURE----- + +iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkcbFIAAAAAABAAO +bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv4p8P/3J3oX0usjnb08Xq+wBh +u5GYBpPUUeTrJQkPqqmZon5UVRYoXobemhZ3k/sB1xX+VqxLZBbN9SO+7p5PYCAu +cOfeirWH+sLj6vCK24ZHJ02mA3KASsHCKoaKxtxj77eKE+3dl3TT8ss9dzC7HgRy +RqLDELyQnkOgeoXwm7jTxC1OhqP7rjZQiFdiOffy75C4wxWxJEqqpQazVBeqPefo +gNnFdH5/6F8uJVrKysw+TJtGrVzoQnxVhJ3pho3YXJyPFBviA4FcTg3HJNjp0DrO +Eg0/8W1R8s2ohyiBjFgoaTZGZyNaQ82F19eYp1XP/ZzeS0biZvYQZ6bTXjM4Pf92 +NOGKM65/ZZguHZMce3Yqf/czUkn9yG0aK+eeD5oQnC3HutQdfrQw+vzL9w51DJ0f +VyCTH1Gj/x4BcyuBSCLiiWjaL5VVKpPLx3BhNgkQv5KAKiJayLd+kqp42lqPAGwr +cBNdhL1awbmQtGkicl2suoongpVS6Doth92LjeB3pLT5DKZy5g4T0a/bvSdb+ghi +HS8wjhvJFMl9PiXJC7h03XdTS1EUD8nbwvq4g1ho0qeS7xVpcWcb/DWkhcVts2eI +rXe0TQwWdiQvKP7dUWpp8zdpNgpRDp1mGLiH9ojx/xChnMH1Rsu2pStlhY6F1ZjS +Q7CDj///8ewA1AcGomzzTei0 +=A9FX +-----END PGP SIGNATURE----- diff --git a/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc b/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc new file mode 100644 index 0000000000..0b1d60109d --- /dev/null +++ b/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc @@ -0,0 +1,164 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +============================================================================= +FreeBSD-SA-26:52.if_wg Security Advisory + The FreeBSD Project + +Topic: Missing MAC validation in wg(4) packet decryption + +Category: core +Module: if_wg +Announced: 2026-07-29 +Credits: Reo Shiseki +Affects: All supported versions of FreeBSD. +Corrected: 2026-07-29 17:48:41 UTC (stable/15, 15.1-STABLE) + 2026-07-29 17:50:34 UTC (releng/15.1, 15.1-RELEASE-p2) + 2026-07-29 17:50:08 UTC (releng/15.0, 15.0-RELEASE-p12) + 2026-07-29 17:49:02 UTC (stable/14, 14.4-STABLE) + 2026-07-29 17:49:36 UTC (releng/14.4, 14.4-RELEASE-p8) +CVE Name: CVE-2026-58085 + +For general information regarding FreeBSD Security Advisories, including +descriptions of the fields above, security branches, and the following +sections, please visit <URL:https://security.FreeBSD.org/>. + +I. Background + +wg(4) is a kernel driver implementing the WireGuard VPN protocol. WireGuard +uses ChaCha20-Poly1305, an authenticated encryption scheme, to protect tunnel +traffic. The Poly1305 message authentication code (MAC) embedded in each +data packet allows the receiver to verify that the packet has not been +tampered with while in transit. + +The OpenCrypto framework (OCF) provides a generic interface to the kernel's +implementation of various cryptographic transforms. Consumers submit a +request via crypto_dispatch(), and OCF routes the request to a specific +implementation of the requested transform. + +II. Problem Description + +After dispatching a decrypt operation to OCF and receiving the result, the +wg(4) driver failed to check whether the MAC verification step succeeded. +The driver thus silently accepted packets with an invalid Poly1305 +authentication tag. + +III. Impact + +A remote attacker who can send UDP packets to a WireGuard endpoint, and who +can guess the bounds of the receiver's replay window, can inject forged or +modified transport data packets into the tunnel. + +A remote attacker who can intercept WireGuard packets bound for a FreeBSD +host can modify the ciphertext and authenticated data without detection by +the receiver. + +IV. Workaround + +No workaround is available. Systems that do not use wg(4) are not affected. + +V. Solution + +Upgrade your vulnerable system to a supported FreeBSD stable or +release / security branch (releng) dated after the correction date, +and reboot the system. + +Perform one of the following: + +1) To update your vulnerable system installed from base system packages: + +Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or +arm64 platforms, which were installed using base system packages, can be +updated via the pkg(8) utility: + +# pkg upgrade -r FreeBSD-base +# shutdown -r +10min "Rebooting for a security update" + +2) To update your vulnerable system installed from binary distribution sets: + +Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms +which were not installed using base system packages can be updated via the +freebsd-update(8) utility: + +# freebsd-update fetch +# freebsd-update install +# shutdown -r +10min "Rebooting for a security update" + +3) To update your vulnerable system via a source code patch: + +The following patches have been verified to apply to the applicable +FreeBSD release branches. + +a) Download the relevant patch from the location below, and verify the +detached PGP signature using your PGP utility. + +[FreeBSD 15.x] +# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-15.patch +# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-15.patch.asc +# gpg --verify if_wg-15.patch.asc + +[FreeBSD 14.x] +# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-14.patch +# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-14.patch.asc +# gpg --verify if_wg-14.patch.asc + +b) Apply the patch. Execute the following commands as root: + +# cd /usr/src +# patch -E -p0 < /path/to/patch + +c) Recompile your kernel as described in +<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the +system. + +VI. Correction details + +This issue is corrected as of the corresponding Git commit hash in the +following stable and release branches: + +Branch/path Hash Revision +- ------------------------------------------------------------------------- +stable/15/ 4c40cb62935f stable/15-n284645 +releng/15.1/ b0254d23f508 releng/15.1-n283592 +releng/15.0/ 13be8d6d86f3 releng/15.0-n281095 +stable/14/ 825c6f45b147 stable/14-n274644 +releng/14.4/ b20841b47153 releng/14.4-n273751 +- ------------------------------------------------------------------------- + +Run the following command to see which files were modified by a +particular commit: + +# git show --stat <commit hash> + +Or visit the following URL, replacing NNNNNN with the hash: + +<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> + +To determine the commit count in a working tree (for comparison against +nNNNNNN in the table above), run: + +# git rev-list --count --first-parent HEAD + +VII. References + +<URL:https://www.cve.org/CVERecord?id=CVE-2026-58085> + +The latest revision of this advisory is available at +<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:52.if_wg.asc> +-----BEGIN PGP SIGNATURE----- + +iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkkbFIAAAAAABAAO +bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvYT4P/1sjyQxTye1SElCc9UT5 +DRVf9QXItIvjnWcsLAyNPd4EPLzhkiCUcnrYHirsSQoz3CiU1/DUev8WjWYJULoP +1zx8U/6xxz3x9aTFb9MEKRBt5jQ62PUGXCLf8SsYiFDFoKuIAYljl5q2J1QkfINc +hwCaYZbqYLunCztREtyfI4NKx5PzqS9paAlY0h85u09hvXOGgz0NeZsaztSjNpTl +i0VUbpP3KAtZyRRYgt1EpHxPkUEpvE9k2KU8cz7B5WZG3x7iwJQAk0kEq66MBx2L +dxyPpTPOM0xkkgdffZ3rGFC0tCBF1uqij0Z07ltiOmJDRJBN2imHhHv1QH/8CtwA +UpK3ukTq5ZRkh7dRy87v/ClirQCgMAHTy4L/sTI9imEp7m/6Hzv6Kse4UIhUo+wI +sisC+Hmeb/tw716QNrZeF6CT7D3V82F3VYEBNc7+e6OACEYilmKyyKp6+3sczbv0 +6IBgUjW8wQAWif2tbifQEUnxwpGhvVIAurZKnmKKN3y5OsHjaj48Lc36woVpxXPX +jvuQflUEPPXsR6du4jPVceMAA+tN5fHnGmjWba5E1RtjSqIU6Q74L2hpfTA58Y2q +yi/vSnOWk84jqXrUuL5JSGsSEQYGshOxHcWyeHndXxGMOjFmgmaoFDtVPvBQwuCo +0FQ8Cxd/bOL+VieyaGH14wtk +=xml5 +-----END PGP SIGNATURE----- diff --git a/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc b/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc new file mode 100644 index 0000000000..945ab4c1bc --- /dev/null +++ b/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc @@ -0,0 +1,146 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +============================================================================= +FreeBSD-SA-26:53.ktrace Security Advisory + The FreeBSD Project + +Topic: ktrace(2) privilege incorrectly validated in jails + +Category: core +Module: ktrace +Announced: 2026-07-29 +Credits: Alexander Leidinger +Affects: FreeBSD 15.1 and 15.0 +Corrected: 2026-07-29 17:48:42 UTC (stable/15, 15.1-STABLE) + 2026-07-29 17:50:35 UTC (releng/15.1, 15.1-RELEASE-p2) + 2026-07-29 17:50:09 UTC (releng/15.0, 15.0-RELEASE-p12) +CVE Name: CVE-2026-58086 + +For general information regarding FreeBSD Security Advisories, including +descriptions of the fields above, security branches, and the following +sections, please visit <URL:https://security.FreeBSD.org/>. + +I. Background + +The ktrace(2) facility allows tracing of kernel operations performed by a +process. When ktrace(2) tracing is configured on a target process by a user +that has the PRIV_KTRACE privilege (typically just the root user), the +process is flagged such that an unprivileged user cannot modify the tracing +flags, even if that user would otherwise be able to invoke ktrace(2) on the +process. + +II. Problem Description + +As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was +always denied to a jailed root user. Tracing configured by a jailed root +user was therefore not flagged as privileged. + +III. Impact + +An unprivileged user in a jail that has permission to debug the target +process can modify the jailed root user's ktrace(2) flags, or disable tracing +outright. A jailed root user therefore cannot reliably trace unprivileged +processes. + +IV. Workaround + +No workaround is available. + +V. Solution + +Upgrade your vulnerable system to a supported FreeBSD stable or +release / security branch (releng) dated after the correction date, +and reboot the system. + +Perform one of the following: + +1) To update your vulnerable system installed from base system packages: + +Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or +arm64 platforms, which were installed using base system packages, can be +updated via the pkg(8) utility: + +# pkg upgrade -r FreeBSD-base +# shutdown -r +10min "Rebooting for a security update" + +2) To update your vulnerable system installed from binary distribution sets: + +Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms +which were not installed using base system packages can be updated via the +freebsd-update(8) utility: + +# freebsd-update fetch +# freebsd-update install +# shutdown -r +10min "Rebooting for a security update" + +3) To update your vulnerable system via a source code patch: + +The following patches have been verified to apply to the applicable +FreeBSD release branches. + +a) Download the relevant patch from the location below, and verify the +detached PGP signature using your PGP utility. + +# fetch https://security.FreeBSD.org/patches/SA-26:53/ktrace.patch +# fetch https://security.FreeBSD.org/patches/SA-26:53/ktrace.patch.asc +# gpg --verify ktrace.patch.asc + +b) Apply the patch. Execute the following commands as root: + +# cd /usr/src +# patch -E -p0 < /path/to/patch *** 2813 LINES SKIPPED ***