From nobody Sun Aug 11 02:18:15 2024 X-Original-To: dev-commits-doc-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4WhLsg333rz5SCCq for ; Sun, 11 Aug 2024 02:18:15 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R11" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4WhLsg2VfZz4brL; Sun, 11 Aug 2024 02:18:15 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1723342695; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=dWB0yL/AN3eFpX8Q1ORoADjrcWhIAZHLz717xc6flqc=; b=UjU7IVmRYu+o0/BuxobqSHgQutoW00gekyl4X4nz80MpT5CVXJcjHtcGahYKOlt79VGqAg BQG8jCZv6AdfBp/kToMlcK397ENlIE6UqYd855OMNqdPijwTol3KJXqVGRQ7iJVd70J+/5 06jf7UgyeL6YCP0eGNvxQ1UmrfhQXGAzvwdfP+ZbWWfErg3ZJeiKYbY823ZqFpJnGH1xsq 2ActoVx6yUJ/IyB7tpowl8hTkwN7gObZ4di0Nat3HewlIlAi6hjDyzW0qguGfBEbskDyPi MdY2soSOlZJOjObykGWcXzIApwk5Lv2kT05Gj4rL/GdBmEAK4VnUyGxcvmKB+A== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1723342695; a=rsa-sha256; cv=none; b=FWgwfCv6ZqZOxxtsaGXbKyk+XevRh8Th91FjM/9arRuX+hEh1mjv3fIbzEk8eBfkigvJx4 Jl/5LoJAupuMiaUr/91Zl5sNCjZ75PddxRfNyJ4h3oonnQVMYLOTfO9epY4x91kRffMnuV B265NcrlNsKg7UMEB0mhPV+ukWQ79+3b78WR510g3mWF30igUUN7DRZBx7bhh+ZzfhHvnl WarJp6OCAGfxSG4ViGjnn2m18TLzy9LWb1yOq6O8oM6xMuQ3lu/nLT2VBIoxuYrc75hkjr y0rmIjg+7lLGS/S1fIPxZctIOahNYhRYh8lQjJerMQlLrkl9/Oddab+Xn5hibA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1723342695; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=dWB0yL/AN3eFpX8Q1ORoADjrcWhIAZHLz717xc6flqc=; b=EId9cJqb8bkzO+19iTERhMCAOTB3p7GFBp1kSQY5X5a8SyNSGu6QVb9GEyYzCbFG6cwxlx GxtztCj7Zhv5hgm2HPb9+FukIXOV2pdHHJkrrD/hQFQARiD+JsIg8GxEE8bhru3OGobcGk wuyUryjDjiTp/knCzlpiiWGV30l4gtfScwp4PC3i0pePZ6mw6DRDIwOwBrrEoOXZuBrPcf tCklEz7NnJaJwEurEUk9HNK1V3zc4CDkuqsAWF+XW+ytodZSXWP/7P/iCPIRcjd2c2Y4Zj ZBBWteqWw1KE4T9fSmmxAHLd1ely/KEhr1p2xRAgYLMl1rP2MSaqjW+mHSkQDQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4WhLsg21fKzQ8B; Sun, 11 Aug 2024 02:18:15 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 47B2IFWK019144; Sun, 11 Aug 2024 02:18:15 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 47B2IFQO019141; Sun, 11 Aug 2024 02:18:15 GMT (envelope-from git) Date: Sun, 11 Aug 2024 02:18:15 GMT Message-Id: <202408110218.47B2IFQO019141@gitrepo.freebsd.org> To: doc-committers@FreeBSD.org, dev-commits-doc-all@FreeBSD.org From: Philip Paeps Subject: git: 2c8a6d2bef - main - Add advisories affecting 13.3R, 14.0R, and 14.1R List-Id: Commit messages for all branches of the doc repository List-Archive: https://lists.freebsd.org/archives/dev-commits-doc-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-doc-all@freebsd.org Sender: owner-dev-commits-doc-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: philip X-Git-Repository: doc X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 2c8a6d2bef9e1967ac244cbe51b7e4060a3d246c Auto-Submitted: auto-generated The branch main has been updated by philip: URL: https://cgit.FreeBSD.org/doc/commit/?id=2c8a6d2bef9e1967ac244cbe51b7e4060a3d246c commit 2c8a6d2bef9e1967ac244cbe51b7e4060a3d246c Author: Philip Paeps AuthorDate: 2024-08-11 02:17:39 +0000 Commit: Philip Paeps CommitDate: 2024-08-11 02:17:39 +0000 Add advisories affecting 13.3R, 14.0R, and 14.1R FreeBSD-SA-24:04.openssh FreeBSD-SA-24:05.pf FreeBSD-SA-24:06.ktrace FreeBSD-SA-24:07.nfsclient FreeBSD-SA-24:08.openssh Also include FreeBSD-SA-24:04.openssh in the 13.2R release notes since the security team patched that release, despite it going out of support one day before. --- website/content/en/releases/13.2R/errata.adoc | 1 + website/content/en/releases/13.3R/errata.adoc | 8 +++++--- website/content/en/releases/14.0R/errata.adoc | 5 +++++ website/content/en/releases/14.1R/errata.adoc | 8 +++++--- 4 files changed, 16 insertions(+), 6 deletions(-) diff --git a/website/content/en/releases/13.2R/errata.adoc b/website/content/en/releases/13.2R/errata.adoc index d4ac3eb2e6..4185555de0 100644 --- a/website/content/en/releases/13.2R/errata.adoc +++ b/website/content/en/releases/13.2R/errata.adoc @@ -63,6 +63,7 @@ For a list of all FreeBSD CERT security advisories, see https://www.FreeBSD.org/ |link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:01.bhyveload.asc[FreeBSD-SA-24:01.bhyveload] |14 February 2024 |bhyveload(8) host file access |link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:02.tty.asc[FreeBSD-SA-24:02.tty] |14 February 2024 |jail(2) information leak |link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:03.unbound.asc[FreeBSD-SA-24:03.unbound] |28 March 2024 |Multiple vulnerabilities in unbound +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:04.openssh.asc[FreeBSD-SA-24:04.openssh] |1 July 2024 |OpenSSH pre-authentication remote code execution |=== [[errata]] diff --git a/website/content/en/releases/13.3R/errata.adoc b/website/content/en/releases/13.3R/errata.adoc index eeeee74d6a..23a942a8c9 100644 --- a/website/content/en/releases/13.3R/errata.adoc +++ b/website/content/en/releases/13.3R/errata.adoc @@ -44,9 +44,11 @@ For a list of all FreeBSD CERT security advisories, see https://www.FreeBSD.org/ [width="100%",cols="40%,30%,30%",options="header",] |=== |Advisory |Date |Topic - -|No advisories.|| - +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:04.openssh.asc[FreeBSD-SA-24:04.openssh] |1 July 2024 |OpenSSH pre-authentication remote code execution +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:05.pf.asc[FreeBSD-SA-24:05.pf] |7 August 2024 |pf incorrectly matches different ICMPv6 states in the state table +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:06.ktrace.asc[FreeBSD-SA-24:06.ktrace] |7 August 2024 |ktrace(2) fails to detach when executing a setuid binary +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:07.nfsclient.asc[FreeBSD-SA-24:07.nfsclient] |7 August 2024 |NFS client accepts file names containing path separators +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:08.openssh.asc[FreeBSD-SA-24:08.openssh] |7 August 2024 |OpenSSH pre-authentication async signal safety issue |=== [[errata]] diff --git a/website/content/en/releases/14.0R/errata.adoc b/website/content/en/releases/14.0R/errata.adoc index 7b64a0446e..1a4966312d 100644 --- a/website/content/en/releases/14.0R/errata.adoc +++ b/website/content/en/releases/14.0R/errata.adoc @@ -51,6 +51,11 @@ For a list of all FreeBSD CERT security advisories, see https://www.FreeBSD.org/ |link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:01.bhyveload.asc[FreeBSD-SA-24:01.bhyveload] |14 February 2024 |bhyveload(8) host file access |link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:02.tty.asc[FreeBSD-SA-24:02.tty] |14 February 2024 |jail(2) information leak |link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:03.unbound.asc[FreeBSD-SA-24:03.unbound] |28 March 2024 |Multiple vulnerabilities in unbound +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:04.openssh.asc[FreeBSD-SA-24:04.openssh] |1 July 2024 |OpenSSH pre-authentication remote code execution +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:05.pf.asc[FreeBSD-SA-24:05.pf] |7 August 2024 |pf incorrectly matches different ICMPv6 states in the state table +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:06.ktrace.asc[FreeBSD-SA-24:06.ktrace] |7 August 2024 |ktrace(2) fails to detach when executing a setuid binary +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:07.nfsclient.asc[FreeBSD-SA-24:07.nfsclient] |7 August 2024 |NFS client accepts file names containing path separators +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:08.openssh.asc[FreeBSD-SA-24:08.openssh] |7 August 2024 |OpenSSH pre-authentication async signal safety issue |=== [[errata]] diff --git a/website/content/en/releases/14.1R/errata.adoc b/website/content/en/releases/14.1R/errata.adoc index 63b1b44b42..844e05c2c2 100644 --- a/website/content/en/releases/14.1R/errata.adoc +++ b/website/content/en/releases/14.1R/errata.adoc @@ -44,9 +44,11 @@ For a list of all FreeBSD CERT security advisories, see https://www.FreeBSD.org/ [width="100%",cols="40%,30%,30%",options="header",] |=== |Advisory |Date |Topic - -|No advisories.|| - +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:04.openssh.asc[FreeBSD-SA-24:04.openssh] |1 July 2024 |OpenSSH pre-authentication remote code execution +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:05.pf.asc[FreeBSD-SA-24:05.pf] |7 August 2024 |pf incorrectly matches different ICMPv6 states in the state table +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:06.ktrace.asc[FreeBSD-SA-24:06.ktrace] |7 August 2024 |ktrace(2) fails to detach when executing a setuid binary +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:07.nfsclient.asc[FreeBSD-SA-24:07.nfsclient] |7 August 2024 |NFS client accepts file names containing path separators +|link:https://www.FreeBSD.org/security/advisories/FreeBSD-SA-24:08.openssh.asc[FreeBSD-SA-24:08.openssh] |7 August 2024 |OpenSSH pre-authentication async signal safety issue |=== [[errata]]