Note jpb will be remote, but there will be people watching at the Brass Monkey ** VIDAR - Server Protection for Internet facing FreeBSD Servers, Jim Brown 2026-08-05 @ 18:45 local (22:45 UTC) - Backroom of Brass Monkey 55 Little West 12th St Vidar is a combination of programs, a PostgreSQL database, and the SEC correlator engine that reads logfiles from authentication, email (postfix), and web server (nginx), (and potentially any other logs) and takes action based on SEC rules to add e ntries to an IPFW firewall. In concept it is similar to fail2ban and has some features in common with blocklistd. SEC reads the logs in real time and based on its rules and correlations, outputs metadata that is piped to a process that inserts the events into a PostgreSQL database and further pipes the offending IP address to a script that updates a table named “BAD” in IPFW. This table is read by IPFW rules to block offending external systems from wreaking havoc on a FreeBSD host. A corresponding table named GOOD contains whitelisted IP addresses so you don’t accidentally lock yourself out. <RANT> Are you sick and tired of seeing: 2a03:b0c0:3:d0::402:d001 - - [31/Jan/2026:17:37:17 -0500] \x16\x03\x01\x05\xDE\x01 ... in your nginx logs and sick of seeing: Feb 20 16:36:03 jimby dovecot[59472]: imap-login: Disconnected: Connection closed (no auth attempts in 5 secs): user=<>, rip=206.168.34.125, lip=174.136.97.66, TLS: Connection closed, ... in your mail logs and sick of seeing: Feb 20 12:47:58 jimby sshd-session[47730]: Invalid user zzzz from 2607:f170:44:12::5d0 port 520 in your authentication logs? With Vidar, you get to put the hammer down: “If you abuse my system, I will shut you out. Permanently.” </RANT> Vidar has additional tricks - a way to dump the IPFW BAD table and a way to import it later - you can keep this database of shame up to date on all those miscreants and keep them away. You can even import the BAD table on another FreeBSD system running IPFW. Also, there’s a handy audit script that lets you compare the entries in the database with what is actually in the IPFW BAD table. Also, Vidar keeps the evidence of the event in question that resulted in blocked access. Finally, using SEC rules, you can make the block last for an hour (for a misconfigured remote system) or a day (for a script kiddie), or permanently (for a determined hacker), or any length of time you choose. There is also a feature to check live processes and alert if, for example, the vi editor is running at 2:00am in the morning. Jim Brown is a long time BSD aficionado who currently lives in Durham, NC. Nearest NYC Subway is the 14th Street/Eighth Avenue station L, A, C, E. To get to the backroom, you must enter the front door, follow the long bar on your left, and walk all the way to the back. At the rear of the BrassMonkey, you will see an alcove for the 3 bathrooms our room is off to your right. _______________________________________________ announce mailing list announce@lists.nycbug.org https://lists.nycbug.org:8443/mailman/listinfo/announce
Wednesday, August 5, 2026
fedora-scm-requests has moved to Fedora Forge (Action: please update fedpkg)
Hello everyone, The fedora-scm-requests ticket queue has moved from pagure.io to Fedora Forge. New location: https://forge.fedoraproject.org/releng/fedora-scm-requests What this means for you ----------------------- This project is only the **request tracker** for new dist-git repositories, new branches, and related SCM admin automation. Dist-git itself has not moved; packages still live on https://src.fedoraproject.org/. `fedpkg request-repo` and `fedpkg request-branch` (and related flows that open tickets on this queue) now target Forge. Please update to a current fedpkg build so new requests go to the right place. Older fedpkg versions that still point at pagure.io will not work against the new queue. How to request repos and branches --------------------------------- Continue to use fedpkg as usual: fedpkg request-repo <package-name> <bugzilla-id> fedpkg request-branch --repo <package-name> <branch> See `fedpkg request-repo --help` and `fedpkg request-branch --help` for options. We strongly encourage using fedpkg rather than filing tickets by hand. The older pagure.io queue was migrated to Forge as https://forge.fedoraproject.org/releng/fedora-scm-requests-old and will live under the releng org as an archive for historical purposes. Do not open new requests there; use https://forge.fedoraproject.org/releng/fedora-scm-requests instead. If something goes wrong ----------------------- We are tracking migration follow-ups here: https://forge.fedoraproject.org/releng/tickets/issues/13108 If you hit a bug (failed request, wrong behaviour after updating fedpkg, etc.), please file a Releng ticket on the tracker: https://forge.fedoraproject.org/releng/tickets/issues You can also reach us in #releng:fedoraproject.org on Fedora Matrix. Thank you for your patience while we completed this move, and apologies for the delay. We know several of you were waiting for this cutover. Best, Samyak Jain Fedora Release Engineering Lead -- _______________________________________________ devel-announce mailing list -- devel-announce@lists.fedoraproject.org To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
Monday, August 3, 2026
CORRECTION: fedora-scm-requests migration start date and time
It was brought to my attention that I accidentally made a mistake in my previous announcement email. My apologies.
-- _______________________________________________ devel-announce mailing list -- devel-announce@lists.fedoraproject.org To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
List of long term FTBFS packages to be retired in a week
Dear maintainers. Based on the current fail to build from source policy, the following packages should be retired from Fedora 45 approximately one week before branching, i.e. 2026-08-05. 5 weekly reminders are required, this is the last one. Policy: https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails_to_install/ The packages in rawhide were not successfully built at least since Fedora 42. This report is based on dist tags. Packages collected via: https://github.com/hroncok/fedora-report-ftbfs-retirements/blob/master/ftbfs-retirements.ipynb If you see a package that was built, please let me know. If you see a package that should be exempted from the process, please let me know and we can work together to get a FESCo approval for that. If you see a package that can be rebuilt, please do so. Package (co)maintainers ==================================================================== cvise mpolacek drumstick0 kkofler, yanqiyu golang-github-facebookincubator-go2chef @go-sig, dcavalca, salimma golang-github-jedib0t-pretty-6 @go-sig, eclipseo golang-github-kit @go-sig, alexsaezm gotun @go-sig, kushal knotes @kde-sig, orphan, than mingw-gsm valtri php-mtdowling-jmespath-php siwinski plotnetcfg jbenc rubygem-sinatra-cross_origin valtri tcl-pgtcl @db-sig, fjanus, praiskup tcl-tcludp spot tcl-tileqt spot tcl-tkpng spot tcl-tktreectrl spot The following packages require above mentioned packages: Depending on: drumstick0 (1) kmid2 (maintained by: cheeselee, kkofler) kmid2-2.4.0-34.fc44.src requires drumstick0-devel kmid2-2.4.0-34.fc44.x86_64 requires drumstick0, libdrumstick-alsa.so.0()(64bit), libdrumstick-file.so.0()(64bit) Depending on: knotes (1) kdepim (maintained by: @kde-sig, than) kdepim-7:17.12.3-20.fc45.x86_64 requires knotes Depending on: mingw-gsm (2) mingw-gstreamer1-plugins-bad-free (maintained by: elmarco, etrunko, mooninite) mingw-gstreamer1-plugins-bad-free-1.28.5-2.fc45.src requires mingw32-gsm, mingw64-gsm mingw32-gstreamer1-plugins-bad-free-1.28.5-2.fc45.noarch requires mingw32(libgsm-1.dll) mingw64-gstreamer1-plugins-bad-free-1.28.5-2.fc45.noarch requires mingw64(libgsm-1.dll) mingw-gtk4 (maintained by: elmarco) mingw-gtk4-4.22.2-3.fc45.src requires mingw32-gstreamer1-plugins-bad-free, mingw64-gstreamer1-plugins-bad-free mingw32-gtk4-4.22.2-3.fc45.noarch requires mingw32(libgstd3d12-1.0-0.dll), mingw32(libgstplay-1.0-0.dll) mingw64-gtk4-4.22.2-3.fc45.noarch requires mingw64(libgstd3d12-1.0-0.dll), mingw64(libgstplay-1.0-0.dll) Affected (co)maintainers @db-sig: tcl-pgtcl @go-sig: gotun, golang-github-jedib0t-pretty-6, golang-github-facebookincubator-go2chef, golang-github-kit @kde-sig: knotes alexsaezm: golang-github-kit cheeselee: drumstick0 dcavalca: golang-github-facebookincubator-go2chef eclipseo: golang-github-jedib0t-pretty-6 elmarco: mingw-gsm etrunko: mingw-gsm fjanus: tcl-pgtcl jbenc: plotnetcfg kkofler: drumstick0 kushal: gotun mooninite: mingw-gsm mpolacek: cvise praiskup: tcl-pgtcl salimma: golang-github-facebookincubator-go2chef siwinski: php-mtdowling-jmespath-php spot: tcl-tktreectrl, tcl-tcludp, tcl-tkpng, tcl-tileqt than: knotes valtri: rubygem-sinatra-cross_origin, mingw-gsm yanqiyu: drumstick0 -- _______________________________________________ devel-announce mailing list -- devel-announce@lists.fedoraproject.org To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
scm-requests moving to Forgejo, new fedpkg needed
-- _______________________________________________ devel-announce mailing list -- devel-announce@lists.fedoraproject.org To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
Thursday, July 30, 2026
F45 Changes TESTABLE deadline approaching - August 11, 2026
Hi all, If you are a change owner for F45, your change is required to be 'Testable'[1] by August 11, 2026 as per our release schedule[2]. Please ensure your tracker bug is updated with the latest information on the status of your change before this date and is in a testable state. If you are ahead of the game and your change is done, well done :) ! Please make sure you mark your change to ON_QA or Closed, or add a comment on the bug indicating what progress is made. F45 changes must be fully complete by August 25, 2026 before we enter Beta Freeze. If you would like to defer your change to F46[3], please let me know and I will update the tracking links accordingly. A full list of our current F45 change set can be found on the change set page[4]. Kindest regards, Aoife [1] https://docs.fedoraproject.org/en-US/program_management/changes_policy/#_change_process_milestones [2] https://fedorapeople.org/groups/schedule/f-45/f-45-key-tasks.html [3] https://fedorapeople.org/groups/schedule/f-46/f-46-key-tasks.html [4] https://fedoraproject.org/wiki/Releases/45/ChangeSet -- Aoife Moloney Fedora Operations Architect Fedora Project Matrix: @amoloney:fedora.im IRC: amoloney -- _______________________________________________ devel-announce mailing list -- devel-announce@lists.fedoraproject.org To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
Wednesday, July 29, 2026
Bouncing messages from freebsd-announce@FreeBSD.org
Hi, this is the Mlmmj program managing the <freebsd-announce@FreeBSD.org> mailing list. Some messages to you could not be delivered. If you're seeing this message it means things are back to normal, and it's merely for your information. Here is the list of the bounced messages: - 303, Message-ID: <20260729223421.2AD5715BF8@freefall.freebsd.org>
FreeBSD Security Advisory FreeBSD-SA-26:52.if_wg
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-SA-26:52.if_wg Security Advisory The FreeBSD Project Topic: Missing MAC validation in wg(4) packet decryption Category: core Module: if_wg Announced: 2026-07-29 Credits: Reo Shiseki Affects: All supported versions of FreeBSD. Corrected: 2026-07-29 17:48:41 UTC (stable/15, 15.1-STABLE) 2026-07-29 17:50:34 UTC (releng/15.1, 15.1-RELEASE-p2) 2026-07-29 17:50:08 UTC (releng/15.0, 15.0-RELEASE-p12) 2026-07-29 17:49:02 UTC (stable/14, 14.4-STABLE) 2026-07-29 17:49:36 UTC (releng/14.4, 14.4-RELEASE-p8) CVE Name: CVE-2026-58085 For general information regarding FreeBSD Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit <URL:https://security.FreeBSD.org/>. I. Background wg(4) is a kernel driver implementing the WireGuard VPN protocol. WireGuard uses ChaCha20-Poly1305, an authenticated encryption scheme, to protect tunnel traffic. The Poly1305 message authentication code (MAC) embedded in each data packet allows the receiver to verify that the packet has not been tampered with while in transit. The OpenCrypto framework (OCF) provides a generic interface to the kernel's implementation of various cryptographic transforms. Consumers submit a request via crypto_dispatch(), and OCF routes the request to a specific implementation of the requested transform. II. Problem Description After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag. III. Impact A remote attacker who can send UDP packets to a WireGuard endpoint, and who can guess the bounds of the receiver's replay window, can inject forged or modified transport data packets into the tunnel. A remote attacker who can intercept WireGuard packets bound for a FreeBSD host can modify the ciphertext and authenticated data without detection by the receiver. IV. Workaround No workaround is available. Systems that do not use wg(4) are not affected. V. Solution Upgrade your vulnerable system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date, and reboot the system. Perform one of the following: 1) To update your vulnerable system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base # shutdown -r +10min "Rebooting for a security update" 2) To update your vulnerable system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install # shutdown -r +10min "Rebooting for a security update" 3) To update your vulnerable system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. [FreeBSD 15.x] # fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-15.patch # fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-15.patch.asc # gpg --verify if_wg-15.patch.asc [FreeBSD 14.x] # fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-14.patch # fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-14.patch.asc # gpg --verify if_wg-14.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile your kernel as described in <URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ 4c40cb62935f stable/15-n284645 releng/15.1/ b0254d23f508 releng/15.1-n283592 releng/15.0/ 13be8d6d86f3 releng/15.0-n281095 stable/14/ 825c6f45b147 stable/14-n274644 releng/14.4/ b20841b47153 releng/14.4-n273751 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat <commit hash> Or visit the following URL, replacing NNNNNN with the hash: <URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References <URL:https://www.cve.org/CVERecord?id=CVE-2026-58085> The latest revision of this advisory is available at <URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:52.if_wg.asc> -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkkbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvYT4P/1sjyQxTye1SElCc9UT5 DRVf9QXItIvjnWcsLAyNPd4EPLzhkiCUcnrYHirsSQoz3CiU1/DUev8WjWYJULoP 1zx8U/6xxz3x9aTFb9MEKRBt5jQ62PUGXCLf8SsYiFDFoKuIAYljl5q2J1QkfINc hwCaYZbqYLunCztREtyfI4NKx5PzqS9paAlY0h85u09hvXOGgz0NeZsaztSjNpTl i0VUbpP3KAtZyRRYgt1EpHxPkUEpvE9k2KU8cz7B5WZG3x7iwJQAk0kEq66MBx2L dxyPpTPOM0xkkgdffZ3rGFC0tCBF1uqij0Z07ltiOmJDRJBN2imHhHv1QH/8CtwA UpK3ukTq5ZRkh7dRy87v/ClirQCgMAHTy4L/sTI9imEp7m/6Hzv6Kse4UIhUo+wI sisC+Hmeb/tw716QNrZeF6CT7D3V82F3VYEBNc7+e6OACEYilmKyyKp6+3sczbv0 6IBgUjW8wQAWif2tbifQEUnxwpGhvVIAurZKnmKKN3y5OsHjaj48Lc36woVpxXPX jvuQflUEPPXsR6du4jPVceMAA+tN5fHnGmjWba5E1RtjSqIU6Q74L2hpfTA58Y2q yi/vSnOWk84jqXrUuL5JSGsSEQYGshOxHcWyeHndXxGMOjFmgmaoFDtVPvBQwuCo 0FQ8Cxd/bOL+VieyaGH14wtk =xml5 -----END PGP SIGNATURE-----
FreeBSD Security Advisory FreeBSD-SA-26:51.ktimer
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-SA-26:51.ktimer Security Advisory The FreeBSD Project Topic: Kernel stack disclosure via timer_settime(2) Category: core Module: ktimer Announced: 2026-07-29 Credits: Hazley Samsudin of GovTech CSG Affects: FreeBSD 15.1 and 15.0 Corrected: 2026-07-27 19:15:01 UTC (stable/15, 15.1-STABLE) 2026-07-29 17:50:30 UTC (releng/15.1, 15.1-RELEASE-p2) 2026-07-29 17:50:05 UTC (releng/15.0, 15.0-RELEASE-p12) CVE Name: CVE-2026-58084 For general information regarding FreeBSD Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit <URL:https://security.FreeBSD.org/>. I. Background POSIX interval timers, managed by timer_create(2) and timer_settime(2), allow a process to schedule periodic or one-shot notifications based on a specified clock source. When timer_settime(2) is called with a non-NULL old_value argument, the kernel returns the timer's previous setting. II. Problem Description To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was not checked, so the uninitialized output buffer was copied to userspace. III. Impact An unprivileged local user can obtain uninitialized kernel stack memory by creating a POSIX timer with CLOCK_TAI and calling timer_settime(2), potentially disclosing sensitive kernel data. IV. Workaround No workaround is available. V. Solution Upgrade your vulnerable system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date, and reboot the system. Perform one of the following: 1) To update your vulnerable system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base # shutdown -r +10min "Rebooting for a security update" 2) To update your vulnerable system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install # shutdown -r +10min "Rebooting for a security update" 3) To update your vulnerable system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch https://security.FreeBSD.org/patches/SA-26:51/ktimer.patch # fetch https://security.FreeBSD.org/patches/SA-26:51/ktimer.patch.asc # gpg --verify ktimer.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile your kernel as described in <URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ a4b5ff57ef85 stable/15-n284618 releng/15.1/ e1c9b0b13a29 releng/15.1-n283589 releng/15.0/ 3254ef000750 releng/15.0-n281092 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat <commit hash> Or visit the following URL, replacing NNNNNN with the hash: <URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References <URL:https://www.cve.org/CVERecord?id=CVE-2026-58084> The latest revision of this advisory is available at <URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:51.ktimer.asc> -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkcbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv4p8P/3J3oX0usjnb08Xq+wBh u5GYBpPUUeTrJQkPqqmZon5UVRYoXobemhZ3k/sB1xX+VqxLZBbN9SO+7p5PYCAu cOfeirWH+sLj6vCK24ZHJ02mA3KASsHCKoaKxtxj77eKE+3dl3TT8ss9dzC7HgRy RqLDELyQnkOgeoXwm7jTxC1OhqP7rjZQiFdiOffy75C4wxWxJEqqpQazVBeqPefo gNnFdH5/6F8uJVrKysw+TJtGrVzoQnxVhJ3pho3YXJyPFBviA4FcTg3HJNjp0DrO Eg0/8W1R8s2ohyiBjFgoaTZGZyNaQ82F19eYp1XP/ZzeS0biZvYQZ6bTXjM4Pf92 NOGKM65/ZZguHZMce3Yqf/czUkn9yG0aK+eeD5oQnC3HutQdfrQw+vzL9w51DJ0f VyCTH1Gj/x4BcyuBSCLiiWjaL5VVKpPLx3BhNgkQv5KAKiJayLd+kqp42lqPAGwr cBNdhL1awbmQtGkicl2suoongpVS6Doth92LjeB3pLT5DKZy5g4T0a/bvSdb+ghi HS8wjhvJFMl9PiXJC7h03XdTS1EUD8nbwvq4g1ho0qeS7xVpcWcb/DWkhcVts2eI rXe0TQwWdiQvKP7dUWpp8zdpNgpRDp1mGLiH9ojx/xChnMH1Rsu2pStlhY6F1ZjS Q7CDj///8ewA1AcGomzzTei0 =A9FX -----END PGP SIGNATURE-----
FreeBSD Security Advisory FreeBSD-SA-26:50.kqueue
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-SA-26:50.kqueue Security Advisory The FreeBSD Project Topic: Use-after-free in kqueue copy-on-fork Category: core Module: kqueue Announced: 2026-07-29 Credits: Hazley Samsudin of GovTech CSG Affects: FreeBSD 15.1 Corrected: 2026-07-29 17:48:38 UTC (stable/15, 15.1-STABLE) 2026-07-29 17:50:29 UTC (releng/15.1, 15.1-RELEASE-p2) CVE Name: CVE-2026-58083 For general information regarding FreeBSD Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit <URL:https://security.FreeBSD.org/>. I. Background The kqueue(2) event notification facility supports a copy-on-fork mode (KQUEUE_CPONFORK) in which registered event filters (knotes) are duplicated into the child process during fork(2). II. Problem Description While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the copy was complete. The copy routine did not account for this and could enqueue the new knote a second time, corrupting the active list. In addition, the copy routine did not hold the appropriate locks while reading knote state, allowing further races. III. Impact An unprivileged local user can trigger a use-after-free in the kernel, potentially leading to privilege escalation. IV. Workaround No workaround is available. V. Solution Upgrade your vulnerable system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date, and reboot the system. Perform one of the following: 1) To update your vulnerable system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base # shutdown -r +10min "Rebooting for a security update" 2) To update your vulnerable system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install # shutdown -r +10min "Rebooting for a security update" 3) To update your vulnerable system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch https://security.FreeBSD.org/patches/SA-26:50/kqueue.patch # fetch https://security.FreeBSD.org/patches/SA-26:50/kqueue.patch.asc # gpg --verify kqueue.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile your kernel as described in <URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ cb7cb40ae47b stable/15-n284642 releng/15.1/ 5a4222a1b225 releng/15.1-n283588 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat <commit hash> Or visit the following URL, replacing NNNNNN with the hash: <URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References <URL:https://www.cve.org/CVERecord?id=CVE-2026-58083> The latest revision of this advisory is available at <URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:50.kqueue.asc> -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkQbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv0LsP/jNvCmjgjFj/yoF6f2VC bHKymftfRZXrMj7xhO95IISFEwth5KwmrwS9e6nNwHBygRiH9AvAbrMREAhju8LK jtPkh0kAyMuAVIIDCcpMtFrMHoCS2FyuHLifA0LWhD8ouxPleJ/AkrjBDo9QRx3U REdng9J3nvq5N8rzon9yTqosv0qoPQD7y/QJPduzhFA6aPVK6MCHEmOtCjyUMUTS 8Lze1WFzlqMt1tRl+iVsLsZa9uameOb4D/GQMkT3OagYQQ8rDLtw0r3hyzmWEw9x ckx3DgKNQygLY5nOvw7iHUbFdl3ovSAIjDbxRY0TV+UNVfcGhROL7GLkfg4YMVIf o5+61XFUaavzYH03xgAVaSKhdNAEv/ybatA/F4HDGeqNVY1V9lqUMX9E+z/n7rfs Y4theutEgwhO0ZJ3kB4WtkREEIovKOWDlPX+wbwxc2KUiEg6opkm0Ehjqt0p26+t ReWevNgO2qXIFr7ch0JiHJpmI8/yoKwS4VJTizaT5FgYO0fLlOBhJX/YXSGqeOPG V+Lb3MnLCGTSkRF4RckDq2ITWbRdQn0IEwYi2v1D6w5NYBd3weJdUioJUuUnXur/ XweEflFDkNvcA4tOhn8ivMgKkT0xE4FEhBTa7ARlbsaE3/CTiu6Q4688lnKhxIzi IXAWlS8Xup6fxlIakdBALCr0 =BGt9 -----END PGP SIGNATURE-----
FreeBSD Errata Notice FreeBSD-EN-26:19.zfs
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-EN-26:19.zfs Errata Notice The FreeBSD Project Topic: Race conditions in zvol device management Category: contrib Module: openzfs Announced: 2026-07-29 Affects: FreeBSD 15.1 and 15.0 Corrected: 2026-07-27 17:33:34 UTC (stable/15, 15.1-STABLE) 2026-07-29 17:50:28 UTC (releng/15.1, 15.1-RELEASE-p2) 2026-07-29 17:50:04 UTC (releng/15.0, 15.0-RELEASE-p12) For general information regarding FreeBSD Errata Notices and Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit <URL:https://security.FreeBSD.org/>. I. Background ZFS is an advanced and scalable file system originally developed by Sun Microsystems for its Solaris operating system. ZFS was integrated as part of FreeBSD starting with FreeBSD 7.0. ZFS volumes (zvols) are ZFS datasets that appear as block devices. The kernel creates and removes device nodes as zvols are created, destroyed, or have their properties changed. II. Problem Description Several race conditions existed in interactions between the zvol device management code and FreeBSD's GEOM subsystem. III. Impact Operations on zvols such as renaming, changing properties, or destroying a zvol while it is being opened can cause a kernel panic. IV. Workaround No workaround is available. V. Solution Upgrade your system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date, and reboot the system. Perform one of the following: 1) To update your system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base # shutdown -r now 2) To update your system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install # shutdown -r now 3) To update your system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch https://security.FreeBSD.org/patches/EN-26:19/zfs.patch # fetch https://security.FreeBSD.org/patches/EN-26:19/zfs.patch.asc # gpg --verify zfs.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile your kernel as described in <URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ 698e0c419895 stable/15-n284603 releng/15.1/ 596030c13dce releng/15.1-n283587 releng/15.0/ 4316500c27c6 releng/15.0-n281091 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat <commit hash> Or visit the following URL, replacing NNNNNN with the hash: <URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References <URL:https://github.com/openzfs/zfs/pull/18191> The latest revision of this advisory is available at <URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-26:19.zfs.asc> -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkIbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvQBYP/1NHmJWw6qysoaKt/ixx rKgRIK9hTj0+/JWPIn0M9HOD4bQevTPq0ZsX4rFhd7Ky+mzLh3UWCd1iCYpk+upr 5awrfKgA+E/UXG0Wax/9zutUYNnPrI8bwayMRAQ1JCodSsYu54NBtQFAwvkEogJw yPQUE3bc/6kAaY+5hqGzfoZ2Vl0/Uhp0RTTWdKlSSMEv1RvdQz2gCF9akyJzN7IA KFM24jGkMoFV6TojJCuVXgtpqF9MaofqDZu27HY0HVIEEeL/rFzel7UsPNyQ5OTX I0tt97VjhPHEpbYbhDUfObFEnxgv8qsw3RWnb0RFttULJ+xcPoN1ASjn1N7g1pK/ /SnOie9MJA2o9BVdPugRnj2nRmJ8IwOv235/rZwN9ChBeQXQTVxk0vgi49lzGLGB yVb4Pc1d5gDGr+S+KBmCq51N1OxSHanQwfrvTmIUjwWalBUqxLWe9rr1Lb7PnoIn b8M7NYR4XuX7uzeFKx0VHHFNjYhS9zwDLEVtsfBfcElApgURq/JOytJOXtJuznpw qNwiz0hgn9Hnx8WHlWKybQ3tWwX4UTvr+fTfsGzwbJksuVZuvn7y+gnpPTSlA+Rp g04H6N7Lcj+x15TQ452JcdzObfrshJXdXPbWLUxLSCmh4SP+3xpsEDlqsJUtX+WS /5y3DQbqNNnvHz1ofJfEsP6k =j9Br -----END PGP SIGNATURE-----
FreeBSD Errata Notice FreeBSD-EN-26:18.tzdata
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-EN-26:18.tzdata Errata Notice The FreeBSD Project Topic: Timezone database information update Category: contrib Module: zoneinfo Announced: 2026-07-29 Affects: All supported versions of FreeBSD. Corrected: 2026-07-11 09:48:44 UTC (stable/15, 15.1-STABLE) 2026-07-29 17:50:24 UTC (releng/15.1, 15.1-RELEASE-p2) 2026-07-29 17:50:00 UTC (releng/15.0, 15.0-RELEASE-p12) 2026-07-11 09:52:47 UTC (stable/14, 14.4-STABLE) 2026-07-29 17:49:33 UTC (releng/14.4, 14.4-RELEASE-p8) For general information regarding FreeBSD Errata Notices and Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit <URL:https://security.FreeBSD.org/>. I. Background The IANA Time Zone Database (often called tz or zoneinfo) contains code and data that represent the history of local time for many representative locations around the globe. It is updated periodically to reflect changes made by political bodies to time zone boundaries, UTC offsets, and daylight-saving rules. FreeBSD releases install the IANA Time Zone Database in /usr/share/zoneinfo. The tzsetup(8) utility allows the user to specify the default local time zone. Based on the selected time zone, tzsetup(8) copies one of the files from /usr/share/zoneinfo to /etc/localtime. A time zone may also be selected for an individual process by setting its TZ environment variable to a desired time zone name. II. Problem Description Several changes to future and past timestamps have been recorded in the IANA Time Zone Database after previous FreeBSD releases were released. This affects many users in different parts of the world. Because of these changes, the data in the zoneinfo files need to be updated. If the local timezone on the running system is affected, tzsetup(8) needs to be run to update /etc/localtime. III. Impact An incorrect time will be displayed on a system configured to use one of the affected time zones if the /usr/share/zoneinfo and /etc/localtime files are not updated, and all applications on the system that rely on the system time, such as cron(8) and syslog(8), will be affected. IV. Workaround The system administrator can install an updated version of the IANA Time Zone Database from the misc/zoneinfo port and run tzsetup(8). Applications that store and display times in Coordinated Universal Time (UTC) are not affected. V. Solution Upgrade your system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date. Please note that some third party software, for instance PHP, Ruby, Java, Perl and Python, may be using different zoneinfo data sources, in such cases this software must be updated separately. Software packages that are installed via binary packages can be upgraded by executing 'pkg upgrade'. Following the instructions in this Errata Notice will only update the IANA Time Zone Database installed in /usr/share/zoneinfo. Perform one of the following: 1) To update your system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base 2) To update your system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install 3) To update your system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch https://security.FreeBSD.org/patches/EN-26:18/tzdata-2026c.patch # fetch https://security.FreeBSD.org/patches/EN-26:18/tzdata-2026c.patch.asc # gpg --verify tzdata-2026c.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile the operating system using buildworld and installworld as described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>. Restart all the affected applications and daemons, or reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ 6470095eaa17 stable/15-n284437 releng/15.1/ 3be83b93661d releng/15.1-n283583 releng/15.0/ 8dd31fbcc50f releng/15.0-n281087 stable/14/ 819af80de8e8 stable/14-n274491 releng/14.4/ 7a227adc1ac6 releng/14.4-n273748 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat <commit hash> Or visit the following URL, replacing NNNNNN with the hash: <URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN> To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References <URL:https://github.com/eggert/tz/blob/2026c/NEWS> The latest revision of this advisory is available at <URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-26:18.tzdata.asc> -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbjsbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvWjEP/3AD86hhb4UDbCjoPCWg X/lkCToUk9WXaEQqORQIFOxsUu2e4CHDWlFkUvAezEV4zzoLjh/KmUzxXpgjj4Ij VF1pKgRBPMFQwtdrC9o106yoLAXJFGLlb1EG3jXUOHpOgMTtqCnYejp2NI0uXdDS BL19NOZUq8uyW1bbQF1XRQHo9nvUA0fhNbRHLmvXvAQFHsWDbz1h/PvwiSNNZlHs vOe9rqSqfOleTsj20V27kRC1/8C/0Ws29hVFWH1Zqb1x63f0nErfYAs/g9tJMdIl n4zuxQyJueX+GJaolBHEKvNkGBf/nSRtJNSJydD5MWbzBHs+mt3oiKfqbfUCUiR/ leyvYhYTczfiORT+GSuBzMEn2fnrP+i/7VyqmETgnEymkyDu6UyxWJIA/d57ajGv M0GF62DYWtzjVHDvCChTPAAs4XNN26E/h8eATCNMNoLn39sQQFBjTo+36e4j7RnN bQZc7wAwPONOyxjs8GPC7ix8Ytja5VbwIqpUw7P8NpG4RIE3mIOIHAkympT0U7rn 2xaU102yF3FlS3mUVO9KQyP0RrMhrY06av+MdkZqBcRLbX5CYw+AFcx4A2gU53vH a5FPKgyJxcL9/TjrjfvXvRfPJ8xb2E2apqtL/Ih1Dx22XDqv0hQj8Rhrqj2ViY+w BAQi1nCtevTlSbKBKMaCx/R0 =5Yms -----END PGP SIGNATURE-----