git: dcda931e28 - main - Add EN-26:18, EN-26:19, and SA-26:50 through SA-26:55.
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 29 Jul 2026 22:00:35 UTC
The branch main has been updated by gordon:
URL: https://cgit.FreeBSD.org/doc/commit/?id=dcda931e282af1e8a5ad7724b1e620f481b7e969
commit dcda931e282af1e8a5ad7724b1e620f481b7e969
Author: Gordon Tetlow <gordon@FreeBSD.org>
AuthorDate: 2026-07-29 21:30:13 +0000
Commit: Gordon Tetlow <gordon@FreeBSD.org>
CommitDate: 2026-07-29 21:30:13 +0000
Add EN-26:18, EN-26:19, and SA-26:50 through SA-26:55.
Approved by: so
---
website/data/security/advisories.toml | 24 +
website/data/security/errata.toml | 8 +
.../advisories/FreeBSD-EN-26:18.tzdata.asc | 167 ++++
.../security/advisories/FreeBSD-EN-26:19.zfs.asc | 141 +++
.../advisories/FreeBSD-SA-26:50.kqueue.asc | 142 +++
.../advisories/FreeBSD-SA-26:51.ktimer.asc | 145 ++++
.../security/advisories/FreeBSD-SA-26:52.if_wg.asc | 164 ++++
.../advisories/FreeBSD-SA-26:53.ktrace.asc | 146 ++++
.../advisories/FreeBSD-SA-26:54.sysvsem.asc | 154 ++++
.../security/advisories/FreeBSD-SA-26:55.elf.asc | 155 ++++
.../security/patches/EN-26:18/tzdata-2026c.patch | 960 +++++++++++++++++++++
.../patches/EN-26:18/tzdata-2026c.patch.asc | 17 +
website/static/security/patches/EN-26:19/zfs.patch | 380 ++++++++
.../static/security/patches/EN-26:19/zfs.patch.asc | 17 +
.../static/security/patches/SA-26:50/kqueue.patch | 141 +++
.../security/patches/SA-26:50/kqueue.patch.asc | 17 +
.../static/security/patches/SA-26:51/ktimer.patch | 16 +
.../security/patches/SA-26:51/ktimer.patch.asc | 17 +
.../security/patches/SA-26:52/if_wg-14.patch | 223 +++++
.../security/patches/SA-26:52/if_wg-14.patch.asc | 17 +
.../security/patches/SA-26:52/if_wg-15.patch | 222 +++++
.../security/patches/SA-26:52/if_wg-15.patch.asc | 17 +
.../static/security/patches/SA-26:53/ktrace.patch | 10 +
.../security/patches/SA-26:53/ktrace.patch.asc | 17 +
.../static/security/patches/SA-26:54/sysvsem.patch | 76 ++
.../security/patches/SA-26:54/sysvsem.patch.asc | 17 +
.../static/security/patches/SA-26:55/elf-14.patch | 60 ++
.../security/patches/SA-26:55/elf-14.patch.asc | 17 +
.../static/security/patches/SA-26:55/elf-15.patch | 60 ++
.../security/patches/SA-26:55/elf-15.patch.asc | 17 +
30 files changed, 3564 insertions(+)
diff --git a/website/data/security/advisories.toml b/website/data/security/advisories.toml
index 3dee86a4c6..7c3d11c7c1 100644
--- a/website/data/security/advisories.toml
+++ b/website/data/security/advisories.toml
@@ -1,6 +1,30 @@
# Sort advisories by year, month and day
# $FreeBSD$
+[[advisories]]
+name = "FreeBSD-SA-26:55.elf"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:54.sysvsem"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:53.ktrace"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:52.if_wg"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:51.ktimer"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:50.kqueue"
+date = "2026-07-29"
+
[[advisories]]
name = "FreeBSD-SA-26:49.iconv"
date = "2026-06-30"
diff --git a/website/data/security/errata.toml b/website/data/security/errata.toml
index e6cb101d6d..92aafdccb4 100644
--- a/website/data/security/errata.toml
+++ b/website/data/security/errata.toml
@@ -1,6 +1,14 @@
# Sort errata notices by year, month and day
# $FreeBSD$
+[[notices]]
+name = "FreeBSD-EN-26:19.zfs"
+date = "2026-07-29"
+
+[[notices]]
+name = "FreeBSD-EN-26:18.tzdata"
+date = "2026-07-29"
+
[[notices]]
name = "FreeBSD-EN-26:17.rpcsec_tls"
date = "2026-06-30"
diff --git a/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc b/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc
new file mode 100644
index 0000000000..97be7e2a66
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc
@@ -0,0 +1,167 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-EN-26:18.tzdata Errata Notice
+ The FreeBSD Project
+
+Topic: Timezone database information update
+
+Category: contrib
+Module: zoneinfo
+Announced: 2026-07-29
+Affects: All supported versions of FreeBSD.
+Corrected: 2026-07-11 09:48:44 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:24 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:00 UTC (releng/15.0, 15.0-RELEASE-p12)
+ 2026-07-11 09:52:47 UTC (stable/14, 14.4-STABLE)
+ 2026-07-29 17:49:33 UTC (releng/14.4, 14.4-RELEASE-p8)
+
+For general information regarding FreeBSD Errata Notices and Security
+Advisories, including descriptions of the fields above, security branches,
+and the following sections, please visit <URL:https://security.FreeBSD.org/>.
+
+I. Background
+
+The IANA Time Zone Database (often called tz or zoneinfo) contains code and
+data that represent the history of local time for many representative
+locations around the globe. It is updated periodically to reflect changes
+made by political bodies to time zone boundaries, UTC offsets, and
+daylight-saving rules.
+
+FreeBSD releases install the IANA Time Zone Database in /usr/share/zoneinfo.
+The tzsetup(8) utility allows the user to specify the default local time
+zone. Based on the selected time zone, tzsetup(8) copies one of the files
+from /usr/share/zoneinfo to /etc/localtime. A time zone may also be selected
+for an individual process by setting its TZ environment variable to a desired
+time zone name.
+
+II. Problem Description
+
+Several changes to future and past timestamps have been recorded in the IANA
+Time Zone Database after previous FreeBSD releases were released. This
+affects many users in different parts of the world. Because of these
+changes, the data in the zoneinfo files need to be updated. If the local
+timezone on the running system is affected, tzsetup(8) needs to be run to
+update /etc/localtime.
+
+III. Impact
+
+An incorrect time will be displayed on a system configured to use one of the
+affected time zones if the /usr/share/zoneinfo and /etc/localtime files are
+not updated, and all applications on the system that rely on the system time,
+such as cron(8) and syslog(8), will be affected.
+
+IV. Workaround
+
+The system administrator can install an updated version of the IANA Time Zone
+Database from the misc/zoneinfo port and run tzsetup(8).
+
+Applications that store and display times in Coordinated Universal Time (UTC)
+are not affected.
+
+V. Solution
+
+Upgrade your system to a supported FreeBSD stable or release / security
+branch (releng) dated after the correction date.
+
+Please note that some third party software, for instance PHP, Ruby, Java,
+Perl and Python, may be using different zoneinfo data sources, in such cases
+this software must be updated separately. Software packages that are
+installed via binary packages can be upgraded by executing 'pkg upgrade'.
+
+Following the instructions in this Errata Notice will only update the IANA
+Time Zone Database installed in /usr/share/zoneinfo.
+
+Perform one of the following:
+
+1) To update your system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+
+2) To update your system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+
+3) To update your system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/EN-26:18/tzdata-2026c.patch
+# fetch https://security.FreeBSD.org/patches/EN-26:18/tzdata-2026c.patch.asc
+# gpg --verify tzdata-2026c.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile the operating system using buildworld and installworld as
+described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>.
+
+Restart all the affected applications and daemons, or reboot the system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ 6470095eaa17 stable/15-n284437
+releng/15.1/ 3be83b93661d releng/15.1-n283583
+releng/15.0/ 8dd31fbcc50f releng/15.0-n281087
+stable/14/ 819af80de8e8 stable/14-n274491
+releng/14.4/ 7a227adc1ac6 releng/14.4-n273748
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat <commit hash>
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+<URL:https://github.com/eggert/tz/blob/2026c/NEWS>
+
+The latest revision of this advisory is available at
+<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-26:18.tzdata.asc>
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbjsbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvWjEP/3AD86hhb4UDbCjoPCWg
+X/lkCToUk9WXaEQqORQIFOxsUu2e4CHDWlFkUvAezEV4zzoLjh/KmUzxXpgjj4Ij
+VF1pKgRBPMFQwtdrC9o106yoLAXJFGLlb1EG3jXUOHpOgMTtqCnYejp2NI0uXdDS
+BL19NOZUq8uyW1bbQF1XRQHo9nvUA0fhNbRHLmvXvAQFHsWDbz1h/PvwiSNNZlHs
+vOe9rqSqfOleTsj20V27kRC1/8C/0Ws29hVFWH1Zqb1x63f0nErfYAs/g9tJMdIl
+n4zuxQyJueX+GJaolBHEKvNkGBf/nSRtJNSJydD5MWbzBHs+mt3oiKfqbfUCUiR/
+leyvYhYTczfiORT+GSuBzMEn2fnrP+i/7VyqmETgnEymkyDu6UyxWJIA/d57ajGv
+M0GF62DYWtzjVHDvCChTPAAs4XNN26E/h8eATCNMNoLn39sQQFBjTo+36e4j7RnN
+bQZc7wAwPONOyxjs8GPC7ix8Ytja5VbwIqpUw7P8NpG4RIE3mIOIHAkympT0U7rn
+2xaU102yF3FlS3mUVO9KQyP0RrMhrY06av+MdkZqBcRLbX5CYw+AFcx4A2gU53vH
+a5FPKgyJxcL9/TjrjfvXvRfPJ8xb2E2apqtL/Ih1Dx22XDqv0hQj8Rhrqj2ViY+w
+BAQi1nCtevTlSbKBKMaCx/R0
+=5Yms
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc b/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc
new file mode 100644
index 0000000000..545c8c9af3
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc
@@ -0,0 +1,141 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-EN-26:19.zfs Errata Notice
+ The FreeBSD Project
+
+Topic: Race conditions in zvol device management
+
+Category: contrib
+Module: openzfs
+Announced: 2026-07-29
+Affects: FreeBSD 15.1 and 15.0
+Corrected: 2026-07-27 17:33:34 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:28 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:04 UTC (releng/15.0, 15.0-RELEASE-p12)
+
+For general information regarding FreeBSD Errata Notices and Security
+Advisories, including descriptions of the fields above, security branches,
+and the following sections, please visit <URL:https://security.FreeBSD.org/>.
+
+I. Background
+
+ZFS is an advanced and scalable file system originally developed by Sun
+Microsystems for its Solaris operating system. ZFS was integrated as part of
+FreeBSD starting with FreeBSD 7.0.
+
+ZFS volumes (zvols) are ZFS datasets that appear as block devices. The
+kernel creates and removes device nodes as zvols are created, destroyed, or
+have their properties changed.
+
+II. Problem Description
+
+Several race conditions existed in interactions between the zvol device
+management code and FreeBSD's GEOM subsystem.
+
+III. Impact
+
+Operations on zvols such as renaming, changing properties, or destroying a
+zvol while it is being opened can cause a kernel panic.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your system to a supported FreeBSD stable or release / security
+branch (releng) dated after the correction date, and reboot the system.
+
+Perform one of the following:
+
+1) To update your system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r now
+
+2) To update your system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r now
+
+3) To update your system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/EN-26:19/zfs.patch
+# fetch https://security.FreeBSD.org/patches/EN-26:19/zfs.patch.asc
+# gpg --verify zfs.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ 698e0c419895 stable/15-n284603
+releng/15.1/ 596030c13dce releng/15.1-n283587
+releng/15.0/ 4316500c27c6 releng/15.0-n281091
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat <commit hash>
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+<URL:https://github.com/openzfs/zfs/pull/18191>
+
+The latest revision of this advisory is available at
+<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-26:19.zfs.asc>
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkIbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvQBYP/1NHmJWw6qysoaKt/ixx
+rKgRIK9hTj0+/JWPIn0M9HOD4bQevTPq0ZsX4rFhd7Ky+mzLh3UWCd1iCYpk+upr
+5awrfKgA+E/UXG0Wax/9zutUYNnPrI8bwayMRAQ1JCodSsYu54NBtQFAwvkEogJw
+yPQUE3bc/6kAaY+5hqGzfoZ2Vl0/Uhp0RTTWdKlSSMEv1RvdQz2gCF9akyJzN7IA
+KFM24jGkMoFV6TojJCuVXgtpqF9MaofqDZu27HY0HVIEEeL/rFzel7UsPNyQ5OTX
+I0tt97VjhPHEpbYbhDUfObFEnxgv8qsw3RWnb0RFttULJ+xcPoN1ASjn1N7g1pK/
+/SnOie9MJA2o9BVdPugRnj2nRmJ8IwOv235/rZwN9ChBeQXQTVxk0vgi49lzGLGB
+yVb4Pc1d5gDGr+S+KBmCq51N1OxSHanQwfrvTmIUjwWalBUqxLWe9rr1Lb7PnoIn
+b8M7NYR4XuX7uzeFKx0VHHFNjYhS9zwDLEVtsfBfcElApgURq/JOytJOXtJuznpw
+qNwiz0hgn9Hnx8WHlWKybQ3tWwX4UTvr+fTfsGzwbJksuVZuvn7y+gnpPTSlA+Rp
+g04H6N7Lcj+x15TQ452JcdzObfrshJXdXPbWLUxLSCmh4SP+3xpsEDlqsJUtX+WS
+/5y3DQbqNNnvHz1ofJfEsP6k
+=j9Br
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc b/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc
new file mode 100644
index 0000000000..885faf681c
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc
@@ -0,0 +1,142 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:50.kqueue Security Advisory
+ The FreeBSD Project
+
+Topic: Use-after-free in kqueue copy-on-fork
+
+Category: core
+Module: kqueue
+Announced: 2026-07-29
+Credits: Hazley Samsudin of GovTech CSG
+Affects: FreeBSD 15.1
+Corrected: 2026-07-29 17:48:38 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:29 UTC (releng/15.1, 15.1-RELEASE-p2)
+CVE Name: CVE-2026-58083
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit <URL:https://security.FreeBSD.org/>.
+
+I. Background
+
+The kqueue(2) event notification facility supports a copy-on-fork mode
+(KQUEUE_CPONFORK) in which registered event filters (knotes) are duplicated
+into the child process during fork(2).
+
+II. Problem Description
+
+While the kernel was copying knotes during fork, a knote with a timer-based
+filter could fire and be enqueued on the kqueue's active list before the copy
+was complete. The copy routine did not account for this and could enqueue
+the new knote a second time, corrupting the active list. In addition, the
+copy routine did not hold the appropriate locks while reading knote state,
+allowing further races.
+
+III. Impact
+
+An unprivileged local user can trigger a use-after-free in the kernel,
+potentially leading to privilege escalation.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/SA-26:50/kqueue.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:50/kqueue.patch.asc
+# gpg --verify kqueue.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ cb7cb40ae47b stable/15-n284642
+releng/15.1/ 5a4222a1b225 releng/15.1-n283588
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat <commit hash>
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+<URL:https://www.cve.org/CVERecord?id=CVE-2026-58083>
+
+The latest revision of this advisory is available at
+<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:50.kqueue.asc>
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkQbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv0LsP/jNvCmjgjFj/yoF6f2VC
+bHKymftfRZXrMj7xhO95IISFEwth5KwmrwS9e6nNwHBygRiH9AvAbrMREAhju8LK
+jtPkh0kAyMuAVIIDCcpMtFrMHoCS2FyuHLifA0LWhD8ouxPleJ/AkrjBDo9QRx3U
+REdng9J3nvq5N8rzon9yTqosv0qoPQD7y/QJPduzhFA6aPVK6MCHEmOtCjyUMUTS
+8Lze1WFzlqMt1tRl+iVsLsZa9uameOb4D/GQMkT3OagYQQ8rDLtw0r3hyzmWEw9x
+ckx3DgKNQygLY5nOvw7iHUbFdl3ovSAIjDbxRY0TV+UNVfcGhROL7GLkfg4YMVIf
+o5+61XFUaavzYH03xgAVaSKhdNAEv/ybatA/F4HDGeqNVY1V9lqUMX9E+z/n7rfs
+Y4theutEgwhO0ZJ3kB4WtkREEIovKOWDlPX+wbwxc2KUiEg6opkm0Ehjqt0p26+t
+ReWevNgO2qXIFr7ch0JiHJpmI8/yoKwS4VJTizaT5FgYO0fLlOBhJX/YXSGqeOPG
+V+Lb3MnLCGTSkRF4RckDq2ITWbRdQn0IEwYi2v1D6w5NYBd3weJdUioJUuUnXur/
+XweEflFDkNvcA4tOhn8ivMgKkT0xE4FEhBTa7ARlbsaE3/CTiu6Q4688lnKhxIzi
+IXAWlS8Xup6fxlIakdBALCr0
+=BGt9
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc b/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc
new file mode 100644
index 0000000000..60113db4c4
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc
@@ -0,0 +1,145 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:51.ktimer Security Advisory
+ The FreeBSD Project
+
+Topic: Kernel stack disclosure via timer_settime(2)
+
+Category: core
+Module: ktimer
+Announced: 2026-07-29
+Credits: Hazley Samsudin of GovTech CSG
+Affects: FreeBSD 15.1 and 15.0
+Corrected: 2026-07-27 19:15:01 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:30 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:05 UTC (releng/15.0, 15.0-RELEASE-p12)
+CVE Name: CVE-2026-58084
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit <URL:https://security.FreeBSD.org/>.
+
+I. Background
+
+POSIX interval timers, managed by timer_create(2) and timer_settime(2), allow
+a process to schedule periodic or one-shot notifications based on a specified
+clock source. When timer_settime(2) is called with a non-NULL old_value
+argument, the kernel returns the timer's previous setting.
+
+II. Problem Description
+
+To retrieve the previous timer value, the kernel calls realtimer_gettime(),
+which obtains the current time for the timer's clock. For a timer using
+CLOCK_TAI this can fail when no TAI offset has been configured, but the error
+return was not checked, so the uninitialized output buffer was copied to
+userspace.
+
+III. Impact
+
+An unprivileged local user can obtain uninitialized kernel stack memory by
+creating a POSIX timer with CLOCK_TAI and calling timer_settime(2),
+potentially disclosing sensitive kernel data.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/SA-26:51/ktimer.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:51/ktimer.patch.asc
+# gpg --verify ktimer.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ a4b5ff57ef85 stable/15-n284618
+releng/15.1/ e1c9b0b13a29 releng/15.1-n283589
+releng/15.0/ 3254ef000750 releng/15.0-n281092
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat <commit hash>
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+<URL:https://www.cve.org/CVERecord?id=CVE-2026-58084>
+
+The latest revision of this advisory is available at
+<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:51.ktimer.asc>
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkcbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv4p8P/3J3oX0usjnb08Xq+wBh
+u5GYBpPUUeTrJQkPqqmZon5UVRYoXobemhZ3k/sB1xX+VqxLZBbN9SO+7p5PYCAu
+cOfeirWH+sLj6vCK24ZHJ02mA3KASsHCKoaKxtxj77eKE+3dl3TT8ss9dzC7HgRy
+RqLDELyQnkOgeoXwm7jTxC1OhqP7rjZQiFdiOffy75C4wxWxJEqqpQazVBeqPefo
+gNnFdH5/6F8uJVrKysw+TJtGrVzoQnxVhJ3pho3YXJyPFBviA4FcTg3HJNjp0DrO
+Eg0/8W1R8s2ohyiBjFgoaTZGZyNaQ82F19eYp1XP/ZzeS0biZvYQZ6bTXjM4Pf92
+NOGKM65/ZZguHZMce3Yqf/czUkn9yG0aK+eeD5oQnC3HutQdfrQw+vzL9w51DJ0f
+VyCTH1Gj/x4BcyuBSCLiiWjaL5VVKpPLx3BhNgkQv5KAKiJayLd+kqp42lqPAGwr
+cBNdhL1awbmQtGkicl2suoongpVS6Doth92LjeB3pLT5DKZy5g4T0a/bvSdb+ghi
+HS8wjhvJFMl9PiXJC7h03XdTS1EUD8nbwvq4g1ho0qeS7xVpcWcb/DWkhcVts2eI
+rXe0TQwWdiQvKP7dUWpp8zdpNgpRDp1mGLiH9ojx/xChnMH1Rsu2pStlhY6F1ZjS
+Q7CDj///8ewA1AcGomzzTei0
+=A9FX
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc b/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc
new file mode 100644
index 0000000000..0b1d60109d
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc
@@ -0,0 +1,164 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:52.if_wg Security Advisory
+ The FreeBSD Project
+
+Topic: Missing MAC validation in wg(4) packet decryption
+
+Category: core
+Module: if_wg
+Announced: 2026-07-29
+Credits: Reo Shiseki
+Affects: All supported versions of FreeBSD.
+Corrected: 2026-07-29 17:48:41 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:34 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:08 UTC (releng/15.0, 15.0-RELEASE-p12)
+ 2026-07-29 17:49:02 UTC (stable/14, 14.4-STABLE)
+ 2026-07-29 17:49:36 UTC (releng/14.4, 14.4-RELEASE-p8)
+CVE Name: CVE-2026-58085
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit <URL:https://security.FreeBSD.org/>.
+
+I. Background
+
+wg(4) is a kernel driver implementing the WireGuard VPN protocol. WireGuard
+uses ChaCha20-Poly1305, an authenticated encryption scheme, to protect tunnel
+traffic. The Poly1305 message authentication code (MAC) embedded in each
+data packet allows the receiver to verify that the packet has not been
+tampered with while in transit.
+
+The OpenCrypto framework (OCF) provides a generic interface to the kernel's
+implementation of various cryptographic transforms. Consumers submit a
+request via crypto_dispatch(), and OCF routes the request to a specific
+implementation of the requested transform.
+
+II. Problem Description
+
+After dispatching a decrypt operation to OCF and receiving the result, the
+wg(4) driver failed to check whether the MAC verification step succeeded.
+The driver thus silently accepted packets with an invalid Poly1305
+authentication tag.
+
+III. Impact
+
+A remote attacker who can send UDP packets to a WireGuard endpoint, and who
+can guess the bounds of the receiver's replay window, can inject forged or
+modified transport data packets into the tunnel.
+
+A remote attacker who can intercept WireGuard packets bound for a FreeBSD
+host can modify the ciphertext and authenticated data without detection by
+the receiver.
+
+IV. Workaround
+
+No workaround is available. Systems that do not use wg(4) are not affected.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+[FreeBSD 15.x]
+# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-15.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-15.patch.asc
+# gpg --verify if_wg-15.patch.asc
+
+[FreeBSD 14.x]
+# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-14.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-14.patch.asc
+# gpg --verify if_wg-14.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ 4c40cb62935f stable/15-n284645
+releng/15.1/ b0254d23f508 releng/15.1-n283592
+releng/15.0/ 13be8d6d86f3 releng/15.0-n281095
+stable/14/ 825c6f45b147 stable/14-n274644
+releng/14.4/ b20841b47153 releng/14.4-n273751
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat <commit hash>
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+<URL:https://www.cve.org/CVERecord?id=CVE-2026-58085>
+
+The latest revision of this advisory is available at
+<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:52.if_wg.asc>
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkkbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvYT4P/1sjyQxTye1SElCc9UT5
+DRVf9QXItIvjnWcsLAyNPd4EPLzhkiCUcnrYHirsSQoz3CiU1/DUev8WjWYJULoP
+1zx8U/6xxz3x9aTFb9MEKRBt5jQ62PUGXCLf8SsYiFDFoKuIAYljl5q2J1QkfINc
+hwCaYZbqYLunCztREtyfI4NKx5PzqS9paAlY0h85u09hvXOGgz0NeZsaztSjNpTl
+i0VUbpP3KAtZyRRYgt1EpHxPkUEpvE9k2KU8cz7B5WZG3x7iwJQAk0kEq66MBx2L
+dxyPpTPOM0xkkgdffZ3rGFC0tCBF1uqij0Z07ltiOmJDRJBN2imHhHv1QH/8CtwA
+UpK3ukTq5ZRkh7dRy87v/ClirQCgMAHTy4L/sTI9imEp7m/6Hzv6Kse4UIhUo+wI
+sisC+Hmeb/tw716QNrZeF6CT7D3V82F3VYEBNc7+e6OACEYilmKyyKp6+3sczbv0
+6IBgUjW8wQAWif2tbifQEUnxwpGhvVIAurZKnmKKN3y5OsHjaj48Lc36woVpxXPX
+jvuQflUEPPXsR6du4jPVceMAA+tN5fHnGmjWba5E1RtjSqIU6Q74L2hpfTA58Y2q
+yi/vSnOWk84jqXrUuL5JSGsSEQYGshOxHcWyeHndXxGMOjFmgmaoFDtVPvBQwuCo
+0FQ8Cxd/bOL+VieyaGH14wtk
+=xml5
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc b/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc
new file mode 100644
index 0000000000..945ab4c1bc
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc
@@ -0,0 +1,146 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:53.ktrace Security Advisory
+ The FreeBSD Project
+
+Topic: ktrace(2) privilege incorrectly validated in jails
+
+Category: core
+Module: ktrace
+Announced: 2026-07-29
+Credits: Alexander Leidinger
+Affects: FreeBSD 15.1 and 15.0
+Corrected: 2026-07-29 17:48:42 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:35 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:09 UTC (releng/15.0, 15.0-RELEASE-p12)
+CVE Name: CVE-2026-58086
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit <URL:https://security.FreeBSD.org/>.
+
+I. Background
+
+The ktrace(2) facility allows tracing of kernel operations performed by a
+process. When ktrace(2) tracing is configured on a target process by a user
+that has the PRIV_KTRACE privilege (typically just the root user), the
+process is flagged such that an unprivileged user cannot modify the tracing
+flags, even if that user would otherwise be able to invoke ktrace(2) on the
+process.
+
+II. Problem Description
+
+As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was
+always denied to a jailed root user. Tracing configured by a jailed root
+user was therefore not flagged as privileged.
+
+III. Impact
+
+An unprivileged user in a jail that has permission to debug the target
+process can modify the jailed root user's ktrace(2) flags, or disable tracing
+outright. A jailed root user therefore cannot reliably trace unprivileged
+processes.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/SA-26:53/ktrace.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:53/ktrace.patch.asc
+# gpg --verify ktrace.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
*** 2813 LINES SKIPPED ***