git: cc1c6248cc - main - 14.5/relnotes: initial informaton added (60 entries, SA and EN)

Vladlen Popolitov <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.doc
Message-ID <[email protected]>
The branch main has been updated by vladlen:

URL: https://cgit.FreeBSD.org/doc/commit/?id=cc1c6248cc2e1347d1685ead3e74b3592fdd7634

commit cc1c6248cc2e1347d1685ead3e74b3592fdd7634
Author:     Vladlen Popolitov <[email protected]>
AuthorDate: 2026-08-18 18:39:14 +0000
Commit:     Vladlen Popolitov <[email protected]>
CommitDate: 2026-08-18 18:39:14 +0000

    14.5/relnotes: initial informaton added (60 entries, SA and EN)
    
    Approved by: re (implicit)
    Differential Revision: https://reviews.freebsd.org/D58920
---
 website/content/en/releases/14.5R/relnotes.adoc | 413 +++++++++++++++++++++++-
 1 file changed, 407 insertions(+), 6 deletions(-)

diff --git a/website/content/en/releases/14.5R/relnotes.adoc b/website/content/en/releases/14.5R/relnotes.adoc
index ccd9ffac2b..ca7814b937 100644
--- a/website/content/en/releases/14.5R/relnotes.adoc
+++ b/website/content/en/releases/14.5R/relnotes.adoc
@@ -86,9 +86,189 @@ This section lists the various Security Advisories and Errata Notices since {rel
 | Date
 | Topic
 
-|No advisories.
-|
-|
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:05.route.asc[FreeBSD-SA-26:05.route]
+| 24 February 2026
+| Local DoS and possible privilege escalation via routing sockets
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:06.tcp.asc[FreeBSD-SA-26:06.tcp]
+| 26 March 2026
+| TCP: remotely exploitable DoS vector (mbuf leak)
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:08.rpcsec_gss.asc[FreeBSD-SA-26:08.rpcsec_gss]
+| 26 March 2026
+| Remote code execution via RPCSEC_GSS packet validation
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:09.pf.asc[FreeBSD-SA-26:09.pf]
+| 25 March 2026
+| pf silently ignores certain rules
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:10.tty.asc[FreeBSD-SA-26:10.tty]
+| 21 April 2026
+| Kernel use-after-free bug in the TIOCNOTTY handler
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:11.amd64.asc[FreeBSD-SA-26:11.amd64]
+| 21 April 2026
+| Missing large page handling in pmap_pkru_update_range()
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc[FreeBSD-SA-26:12.dhclient]
+| 29 April 2026
+| Remote code execution via malicious DHCP options 
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:13.exec.asc[FreeBSD-SA-26:13.exec]
+| 29 April 2026
+| Local privilege escalation via execve()
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:14.pf.asc[FreeBSD-SA-26:14.pf]
+| 29 April 2026
+| pf can overflow the stack parsing crafted SCTP packets
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:15.dhclient.asc[FreeBSD-SA-26:15.dhclient]
+| 29 April 2026
+| Remotely triggerable out-of-bounds heap write in dhclient
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:16.libnv.asc[FreeBSD-SA-26:16.libnv]
+| 29 April 2026
+| Stack overflow via select() file descriptor set overflow
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:17.libnv.asc[FreeBSD-SA-26:17.libnv]
+| 29 April 2026
+| Heap overflow in libnv
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:18.setcred.asc[FreeBSD-SA-26:18.setcred]
+| 20 May 2026
+| Stack buffer overflow via man:setcred[2]
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:19.file.asc[FreeBSD-SA-26:19.file]
+| 20 May 2026
+| Kernel use-after-free via file descriptor syscalls
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:20.fusefs.asc[FreeBSD-SA-26:20.fusefs]
+| 20 May 2026
+| Heap overflow in FUSE_LISTXATTR
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:21.ptrace.asc[FreeBSD-SA-26:21.ptrace]
+| 20 May 2026
+| Missing validation in ptrace(PT_SC_REMOTE)
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:22.libcasper.asc[FreeBSD-SA-26:22.libcasper]
+| 20 May 2026
+| man:select[2] file descriptor set overflow causes stack overflow
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:23.bsdinstall.asc[FreeBSD-SA-26:23.bsdinstall]
+| 20 May 2026
+| Remote code execution via installer Wi-Fi access point scans
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:24.cap_net.asc[FreeBSD-SA-26:24.cap_net]
+| 20 May 2026
+| Incorrect libcap_net limitation list manipulation
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:25.thr.asc[FreeBSD-SA-26:25.thr]
+| 9 June 2026
+| Missing permission check in man:thr_kill2[2]
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:26.ktls.asc[FreeBSD-SA-26:26.ktls]
+| 9 June 2026
+| Arbitrary file overwrite via the KTLS receive path
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:27.sound.asc[FreeBSD-SA-26:27.sound]
+| 9 June 2026
+| Multiple vulnerabilities in the man:sound[4] mmap path
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:28.capsicum.asc[FreeBSD-SA-26:28.capsicum]
+| 9 June 2026
+| man:sigqueue[2] missing capability mode restriction
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:29.ip6_multicast.asc[FreeBSD-SA-26:29.ip6_multicast]
+| 9 June 2026
+| Use-after-free bug in the IPV6_MSFILTER socket option handler
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:30.linux.asc[FreeBSD-SA-26:30.linux]
+| 9 June 2026
+| Flaw in Linuxulator execution of setugid binaries
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:31.arm64.asc[FreeBSD-SA-26:31.arm64]
+| 9 June 2026
+| Arm CPU errata may bypass page table permission changes
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:32.elf.asc[FreeBSD-SA-26:32.elf]
+| 9 June 2026
+| ASLR bypass for setuid executables via man:procctl[2]
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:33.unbound.asc[FreeBSD-SA-26:33.unbound]
+| 9 June 2026
+| Multiple vulnerabilities in unbound
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:34.vt.asc[FreeBSD-SA-26:34.vt]
+| 9 June 2026
+| Integer overflow in man:vt[4] CONS_HISTORY ioctl
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:35.openssl.asc[FreeBSD-SA-26:35.openssl]
+| 9 June 2026
+| Multiple vulnerabilities in OpenSSL
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:36.ldns.asc[FreeBSD-SA-26:36.ldns]
+| 9 June 2026
+| Insufficient response validation in the ldns stub resolver
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:37.vm.asc[FreeBSD-SA-26:37.vm]
+| 30 June 2026
+| Use-after-free in device pager page list
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:39.execve.asc[FreeBSD-SA-26:39.execve]
+| 30 June 2026
+| Local privilege escalation via man:execve[2] TOCTOU race
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:40.zfs.asc[FreeBSD-SA-26:40.zfs]
+| 30 June 2026
+| Multiple vulnerabilities in OpenZFS
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:41.libalias.asc[FreeBSD-SA-26:41.libalias]
+| 30 June 2026
+| Buffer overflow in libalias RTSP handler
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:42.unlinkat.asc[FreeBSD-SA-26:42.unlinkat]
+| 30 June 2026
+| man:unlinkat[2] ignores AT_RESOLVE_BENEATH flag
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:43.tcp.asc[FreeBSD-SA-26:43.tcp]
+| 30 June 2026
+| Use-after-free in TCP RACK stack option handler
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:44.posixshm.asc[FreeBSD-SA-26:44.posixshm]
+| 30 June 2026
+| Multiple vulnerabilities in POSIX largepage objects
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:45.audit.asc[FreeBSD-SA-26:45.audit]
+| 30 June 2026
+| Incorrect audit records for man:ptrace[2] syscall requests
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:46.ktls.asc[FreeBSD-SA-26:46.ktls]
+| 30 June 2026
+| Remote DOS via uninitialized memory access in KTLS receive
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:47.linux.asc[FreeBSD-SA-26:47.linux]
+| 30 June 2026
+| Kernel stack disclosure in Linux compatibility layer
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:48.compat32.asc[FreeBSD-SA-26:48.compat32]
+| 30 June 2026
+| Kernel stack disclosure in 32-bit compatibility support
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:49.iconv.asc[FreeBSD-SA-26:49.iconv]
+| 30 June 2026
+| Multiple vulnerabilities in man:iconv[3]
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:52.if_wg.asc[FreeBSD-SA-26:52.if_wg]
+| 29 July 2026
+| Missing MAC validation in man:wg[4] packet decryption
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:54.sysvsem.asc[FreeBSD-SA-26:54.sysvsem]
+| 29 July 2026
+| Heap out-of-bounds access in man:semctl[2]
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-26:55.elf.asc[FreeBSD-SA-26:55.elf]
+| 29 July 2026
+| Race condition in ELF core dump segment counting
 
 |===
 
@@ -102,10 +282,41 @@ This section lists the various Security Advisories and Errata Notices since {rel
 | Date
 | Topic
 
-|No notices.
-|
-|
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:05.vm.asc[FreeBSD-EN-26:05.vm]
+| 21 April 2026
+| The page fault handler fails to zero memory
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:06.timerfd.asc[FreeBSD-EN-26:06.timerfd]
+| 21 April 2026
+| Periodic man:timerfd[2] timers may produce incorrect results
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:09.tzdata.asc[FreeBSD-EN-26:09.tzdata]
+| 29 April 2026
+| Timezone database information update
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:10.amd64.asc[FreeBSD-EN-26:10.amd64]
+| 29 April 2026
+| TLB invalidation bug on AMD systems with INVLPGB
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:11.dhclient.asc[FreeBSD-EN-26:11.dhclient]
+| 1 May 2026
+| man:dhclient[8] lease validation is too strict
 
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:13.freebsd-update.asc[FreeBSD-EN-26:13.freebsd-update]
+| 20 May 2026
+| freebsd-update attempts to merge a generated file
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:15.openssl.asc[FreeBSD-EN-26:15.openssl]
+| 9 June 2026
+| Update OpenSSL to 3.0.20 and 3.5.6
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:16.arm64.asc[FreeBSD-EN-26:16.arm64]
+| 30 June 2026
+| 32-bit man:setcontext[2] and man:swapcontext[2] fail on arm64
+
+| link:https://www.FreeBSD.org/security/advisories/FreeBSD-EN-26:18.tzdata.asc[FreeBSD-EN-26:18.tzdata]
+| 29 July 2026
+| Timezone database information update
 
 |===
 
@@ -117,18 +328,124 @@ This section covers changes and additions to userland applications, contributed
 [[userland-config]]
 === Userland Configuration Changes
 
+Local-unbound-setup now properly configures DNS resolution on IPv6-only systems by disabling unsupported protocols in the server configuration and using 127.0.0.1, ::1, or both in resolv.conf based on kernel support.
+gitref:973d1f2b12ab[repository=src].
+
+The /etc/protocols file has been updated with the latest IANA assignments, including documentation of unassigned and deprecated protocols.
+gitref:9f9f0d3d9e1c[repository=src].
+
+The man:lpd[8] daemon now correctly uses the port number specified in /etc/printcap instead of ignoring it, restoring a feature broken since the addition of IPv6 support in 2000.
+gitref:85852fe5e4a9[repository=src].
+
 [[userland-programs]]
 === Userland Application Changes
 
+The rc.firewall script now supports reading IP addresses or subnets from on-disk files for the firewall_allowservices and firewall_trusted list variables. Elements that look like absolute paths are read line by line, skipping comments and blank lines, and the first word on each line is treated as an address or subnet.
+gitref:10075baae2c1[repository=src].
+
+The default history size in /bin/sh has been increased from 100 to 128, complying with the POSIX.1-2024 minimum requirement.
+gitref:9bc3d8e002b9[repository=src].
+
+LTO-10 and LTO-10P density codes and cartridge specifications have been added to mt(1) and libmt, enabling detection and reporting of the new tape formats.
+gitref:5f55c59cbab5[repository=src].
+{{< sponsored "Spectra Logic" >}}
+
+The default behavior of man:pwd[1] has changed from -P to -L, aligning with POSIX semantics.
+gitref:ae75d4bdc12b[repository=src].
+
+The ipfw(8) binary now includes a fallback mechanism to support the new kernel interface introduced in FreeBSD 15.0. When running with a 15.0+ kernel, ipfw(8) automatically invokes a bundled ipfw15 binary to load firewall rules, ensuring compatibility during upgrade procedures.
+gitref:704ec5e68c44[repository=src].
+
+The man:daemon[8] utility now supports the -m option to specify the output file mode, allowing non-root log collectors to access log files.
+gitref:cc35db95eb9e[repository=src].
+
 [[userland-contrib]]
 === Contributed Software
 
+The default linker for clang on FreeBSD is now ld.lld (LLD) instead of following the generic ld search path.
+gitref:f81c82a9db12[repository=src].
+
+Expat has been updated to version 2.8.1.
+gitref:84f7ee30767b[repository=src].
+
+man:file[1] has been updated to 5.47.
+gitref:d58218761eeb[repository=src].
+
+ldns has been updated to version 1.9.2.
+gitref:222648172b80[repository=src].
+
+libarchive has been updated to version 3.8.7. This update includes bugfixes for vulnerabilities, memory leaks, and crashes in multiple archive format readers.
+gitref:2dddbb67c6a1[repository=src].
+
+libpcap has been updated to 1.10.6.
+gitref:09db15067248[repository=src].
+{{< sponsored "The FreeBSD Foundation" >}}
+
+LLVM and related components have been updated to version 21.1.8.
+gitref:502fd5427dc8[repository=src].
+
+man:mandoc[1] has been updated to 2025-09-26.
+gitref:f763f12ed5eb[repository=src].
+
+man:ncurses[3] has been updated to 6.6.
+gitref:8de7c76ee02f[repository=src].
+
+The openresolv utility has been updated to version 3.17.4, which brings numerous improvements to the resolvconf implementation, including updated man pages and configuration file documentation, as well as new compatibility scripts for avahi-daemon, mDNSResponder, and systemd-resolved.
+gitref:266022bf0b60[repository=src].
+
+openresolv now trims leading dots from domain names in resolvconf, which affects DNS resolution behavior for users with such configurations.
+gitref:aad298c8f9ca[repository=src].
+
+OpenSSL has been updated to 3.0.21.
+gitref:ca66129a2c8a[repository=src].
+
+The pci_vendors database has been updated to the 2026-02-10 version.
+gitref:b28b6c6d33ac[repository=src].
+
+The root certificate bundle has been updated to match NSS 3.123.1, adding new trusted CA certificates and moving others to untrusted.
+gitref:09bb6a62d00f[repository=src].
+
+man:tcpdump[1] has been updated to 4.99.6.
+gitref:8a0d626219f1[repository=src].
+{{< sponsored "The FreeBSD Foundation" >}}
+
+tzcode has been updated to 2026c.
+gitref:3ab59366fed8[repository=src].
+
+The tzdata database has been updated to version 2026c.
+gitref:819af80de8e8[repository=src].
+
+man:unbound[8] has been updated to version 1.26.0.
+gitref:c555236ec76f[repository=src].
+
+USB vendor list updated to 2025.12.13.
+gitref:2f866e0547bd[repository=src].
+
+man:xz[1] has been updated to 5.8.3.
+gitref:e32e126c136d[repository=src].
+
 [[userland-deprecated-programs]]
 === Deprecated Applications
 
+The man:lpr[1] suite of programs has been deprecated and may be removed before FreeBSD 16.0. Better-maintained alternatives are available in the Ports Collection (print/cups, sysutils/LPRng).
+gitref:b734006cafa1[repository=src].
+
 [[userland-libraries]]
 === Runtime Libraries and API
 
+The sortlist parser in libc's resolver has been reimplemented, restoring the ability to configure address sort order in /etc/resolv.conf. Sorting of IPv4 and IPv6 addresses is now functional again, with updated documentation.
+gitref:fc00e7a18cde[repository=src].
+
+The libc resolver option parser now strictly validates option names and values, rejecting trailing garbage, negative values, and non-numeric arguments, which changes behavior for malformed resolv.conf options.
+gitref:b52d95bf1494[repository=src].
+
+C23-standard trigonometric functions using the pi multiplier (such as sinpi, cospi, and related variants) are now exposed in <math.h>. This extends the available math library APIs to align with the C23 standard.
+gitref:69b3aa35469a[repository=src].
+
+The inotify API is now available in libc, providing man:inotify_init[3], man:inotify_init1[3], and man:inotify_add_watch[3] functions for file system event monitoring.
+gitref:e61884183ed4[repository=src].
+{{< sponsored "Klara, Inc." >}}
+
 [[cloud]]
 == Cloud Support
 
@@ -142,6 +459,13 @@ This section covers changes to kernel configurations, system tuning, and system
 [[kernel-general]]
 === General Kernel Changes
 
+A new security knob disables unprivileged access to the kernel environment (kenv), including jailed root, to protect sensitive data. System administrators can configure this via the documented sysctl/tunable. Manual pages updated to reflect the new behavior.
+gitref:c839c1566147[repository=src].
+
+Adds man:inotify_init[2], man:inotify_add_watch[2], and man:inotify_rm_watch[2] system calls for source compatibility with Linux, allowing applications to monitor filesystem events in a directory hierarchy without opening each file.
+gitref:296d7f95aab8[repository=src].
+{{< sponsored "Klara, Inc." >}}
+
 [[drivers]]
 == Devices and Drivers
 
@@ -150,9 +474,28 @@ This section covers changes and additions to devices and device drivers since {r
 [[drivers-device]]
 === Device Drivers
 
+The br.lenovo.kbd keyboard layout is now installed and available in the system.
+gitref:ca42bd490891[repository=src].
+
+The US international keyboard layout with accented keys us.intl.acc.kbd is now installed by default and available in the system.
+gitref:823889aaafa3[repository=src].
+
+The man:smartpqi[4] driver has been updated with new controller support and a 32-bit I/O buffer size for passthrough ioctls, replacing the previous 16-bit limit.
+gitref:8accd4d99f81[repository=src].
+{{< sponsored "Microchip Technology Inc." >}}
+
+The man:acpi[4] driver now supports power management on Apple Mac hardware with dual GPUs by enabling the Darwin OSI by default, which uses the integrated GPU for improved battery life. This behavior can be toggled with the tunable hw.acpi.apple_darwin_osi.
+gitref:964c97aa80ec[repository=src].
+
+The man:ahci[4] driver now supports an additional Marvell 88SE9128 SATA controller variant (device ID 0x91a3), enabling proper operation on systems with this chip (e.g., Gigabyte GA-P55A-UD4 motherboards).
+gitref:487eeda542a7[repository=src].
+
 [[drivers-removals]]
 === Deprecated and Removed Drivers
 
+The man:asmc[4] driver no longer supports 32-bit Intel-based Macs. Users of 32-bit hardware are affected by this removal.
+gitref:432c95c57bb5[repository=src].
+
 [[storage]]
 == Storage
 
@@ -161,6 +504,9 @@ This section covers changes and additions to file systems and other storage subs
 [[storage-general]]
 === General Storage
 
+The man:msdosfs[4] filesystem now supports file names containing Unicode surrogate pairs, enabling full access to files with emoji and other characters beyond the Basic Multilingual Plane on FAT32 volumes.
+gitref:e71ad3f7a6b1[repository=src].
+
 [[boot]]
 == Boot Loader Changes
 
@@ -169,6 +515,43 @@ This section covers the boot loader, boot menu, and other boot-related changes.
 [[boot-loader]]
 === Boot Loader Changes
 
+The lualoader now supports be-list and be-switch commands, allowing boot environment changes from the loader command prompt.
+gitref:bddfcbd9bbc6[repository=src].
+
+Fixed a boot loader bug in man:loader.efi[8] for amd64 where late staging area movement after page table computation could cause boot failures, particularly when loading microcode or a large set of modules.
+gitref:8dca7fccfa65[repository=src].
+{{< sponsored "Netflix" >}}
+
+The boot loader's Lua scripting now supports filtering the list of boot environments via a user-defined callback in local.lua, allowing operators to hide certain BEs (e.g., those with a leading dot).
+gitref:9ef671ef0c6c[repository=src].
+
+The loader now prefers the embedded memory disk as the current device when built with MD_IMAGE_SIZE, improving boot behavior for such configurations.
+gitref:a4a3825d3e1d[repository=src].
+{{< sponsored "Chelsio Communications" >}}
+
+The boot loader's Lua core now follows symlinks when searching for bootable kernels.
+gitref:1841091eaa0b[repository=src].
+
+man:bsdinstall[8] now correctly creates a FreeBSD UEFI boot entry after installation, fixing a regression where some machines could not boot due to a missing boot entry.
+gitref:cfdd90abab51[repository=src].
+
+The ZFS rc script now runs before the tmp rc script, ensuring ZFS datasets (including a /tmp dataset) are mounted before tmp attempts to test writability and possibly mount a tmpfs. This fixes issues with read-only ZFS roots and the `tmpmfs=yes` setting.
+gitref:b39cac4b834c[repository=src].
+
+Boot loader on powerpc64le works around a SLOF bug in QEMU by adding padding, fixing booting on little-endian PowerPC systems.
+gitref:5d2b9a17b9c6[repository=src].
+{{< sponsored "Netflix" >}}
+
+Fix for handling of foreground and background color settings in the loader's graphical console environment, ensuring that the environment can set either independently and that colors are correctly applied when switching to the kernel.
+gitref:14c8e003318b[repository=src].
+
+Nvidia kernel modules are now blacklisted by the loader to prevent panics if loaded early via loader.conf. The nvidia, nvidia-modeset, and nvidia-drm modules are denied loading at boot time.
+gitref:7db1376bd151[repository=src].
+
+The boot logo positions for Beastie and fbsdbw have been corrected.
+gitref:9ac7e0362a24[repository=src].
+{{< sponsored "PANS Jarosław" >}}
+
 [[network]]
 == Networking
 
@@ -195,6 +578,24 @@ This section covers changes to manual (man:man[1]) pages and other documentation
 [[man-pages]]
 === Man Pages
 
+Manual pages for man:libusb20_open[3] and man:libusb20_be_device_foreach[3] have been added, documenting these library functions.
+gitref:3e05b2366af1[repository=src].
+
+Manual page man:mq_getfd_np[3] documents the function that retrieves the file descriptor from a message queue descriptor.
+gitref:11a0cf32a232[repository=src].
+
+The man:dwcotg[4] manual page has been added, documenting the DesignWare USB OTG controller driver and making it visible for future release notes.
+gitref:a1479a37fcf8[repository=src].
+
+The man:ports[7] reference manual's FILES section has been expanded and reorganized into three tables, documenting additional files such as make.conf, CHANGES, CONTRIBUTING.md, UPDATING, and Tools/scripts.
+gitref:5e1443211528[repository=src].
+
+Man page documentation for man:bhyve[8] has been updated to describe the full -c flag syntax including complex CPU topology specifiers.
+gitref:c92c3852a974[repository=src].
+
+The deprecated -p option has been removed from man:lpd[8] and its manual page.
+gitref:5f10e369a13a[repository=src].
+
 [[ports]]
 == Ports Collection and Package Infrastructure
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.