Issue 293
Published August 26, 2026

FreeBSD security advisories, ROCm porting, RAIDframe improvements and more

Releases

No releases.

BSDSec

FreeBSD Security Advisory FreeBSD-SA-26:61.openssl: FreeBSD has issued a security advisory for multiple OpenSSL vulnerabilities affecting FreeBSD 14.x and 15.x, including heap buffer overflow, double free, format string injection, NULL pointer dereference, and unbounded memory allocation, with impacts ranging from DoS to potential RCE.

FreeBSD Security Advisory FreeBSD-SA-26:60.ppp: FreeBSD ppp(8) has three memory safety vulnerabilities (CVE-2026-58095, CVE-2026-58096, CVE-2026-58097) that can allow a malicious PPP peer or local user to crash ppp or execute arbitrary code as root, with patches available for all supported releases.

FreeBSD Security Advisory FreeBSD-SA-26:59.mac_do: FreeBSD 15.0 and later have a bug in the mac_do MAC policy module where certain rules can be abused to set a process’ primary group ID to 0, potentially allowing privilege escalation depending on system configuration. Systems not using mac_do or with rules that explicitly specify a target group ID are unaffected.

FreeBSD Security Advisory FreeBSD-SA-26:58.sound: A use-after-free in the sound(4) driver’s SNDCTL_DSP_SYNCSTART ioctl allows a local unprivileged user to escalate privileges on systems with multiple audio devices; patches are available for all supported FreeBSD releases.

FreeBSD Security Advisory FreeBSD-SA-26:57.unix: A use-after-free in unix SOCK_STREAM message handling allows an unprivileged local user to escalate privileges on FreeBSD 15.0 and later, with patches available for stable/15, 15.1-RELEASE-p3, and 15.0-RELEASE-p13.

FreeBSD Security Advisory FreeBSD-SA-26:56.hwpmc: The hwpmc(4) driver fails to detach performance monitoring counters during exec credential transitions, allowing an unprivileged local user to continue monitoring a process after it executes a setuid or setgid binary.

FreeBSD Errata Notice FreeBSD-EN-26:21.openssl: FreeBSD 14.4’s OpenSSL pkg-config files incorrectly report version 3.5.1 instead of the actual 3.0.x, which can cause builds to fail or select unsupported code paths.

FreeBSD Errata Notice FreeBSD-EN-26:20.microcode: Early loading of Intel CPU microcode fails for some CPUs due to an inverted bounds check in ucode_intel_match(), affecting Alder Lake, Raptor Lake, Sapphire Rapids, Emerald Rapids, and newer Intel Core Ultra processors.

OpenBSD Errata: August 22, 2026 (ifioctl nipledge kernproc ttyioctl expat): Errata patches for kernel and libexpat have been released for OpenBSD 7.8 and 7.9, with binary updates available via syspatch on amd64, arm64, and i386.

As always, it’s worth following BSDSec. RSS feed available.

News

FreeBSD Foundation Intern Sourojeet Adhikari on Bringing ROCm to FreeBSD: A FreeBSD Foundation intern describes his summer project porting AMD’s ROCm GPU computing platform to FreeBSD, including patching LLVM, adapting ROCm runtimes, and integrating with drm-kmod, with some changes already upstreamed.

Valuable News – 2026/08/24: This week covers FreeBSD 14.5-BETA3, FreeBSD Git Weekly updates, NetBSD 11 with RISC-V support, FreeBSD on IBM PowerVM, BSDun for running FreeBSD ELF binaries on Linux, a FreeBSD Foundation intern’s Raspberry Pi work, and more.

Google Summer of Code 2026 Reports: Improving RAIDframe: A GSoC 2026 report details Emmanuel Nyarko’s work on NetBSD’s RAIDframe, adding N-way RAID 1 for multi-disk mirroring, implementing RAID scrubbing for health checks, and updating reconstruction logic, with testing on 3-way and 5-way RAID 1 setups.

rpki-client 9.9 released: rpki-client 9.9 is out with a backoff retry mechanism for non-functional CAs, OpenSSL 4 support, safer config output, improved warnings, and multiple reliability fixes, and is available on OpenBSD mirrors.

FreeBSD Foundation Intern Jim Huang Chen on Raspberry Pi Support and Open Source: FreeBSD Foundation intern Jim Huang Chen describes his summer contributing Raspberry Pi support, including porting Raspberry Pi Imager to FreeBSD and adding support for the Raspberry Pi Compute Module 5’s PCIe controller and RP1 southbridge.

BSD Now 677: Butler at your service: This episode covers OpenBSD updates including WPA3 support, Game of Trees 0.127, relayd ECDSA support, httpd custom headers, LLVM on sparc64, and vmm/vmd fd-ification, plus Wine 11.14 on FreeBSD and a FreeBSD cloud build.

Did we miss anything?

This newsletter is made from your content on DiscoverBSD and BSDSec. Submit the stuff we missed so it can appear next time.

Do you have an OSS BSD-related project that you would like to showcase in BSD Weekly? Reply to sender and we can showcase you as a sponsor of an issue (for free).

Do you know anyone who would like this newsletter? Consider forwarding and tell them to subscribe.

Thanks for reading and see you next week! Stay safe!

Become a Sponsor! Become a Patron!

We won't spam you. Unsubscribe any time.