New stable release: HardenedBSD-stable 10-STABLE v46.21

HardenedBSD-10-STABLE-v46.21 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Warning: this is a security update!

Highlights:

  • HBSD: fix for FreeBSD-SA-16:37.libc (CVE-2016-6559) improper boundary checking - b66bee517d74e7395ba293bc2f41cc8273f0acdf 54ef6264f7f041d711a6f2a6afeedd2f3646bdd9

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-10-STABLE-v46.21-amd64-bootonly.iso) = 75580ab43e32dd5fecf439d4880b5820d96eb96975c5977c0a9ea7cc6dcc39584b1489cb45747833db706ea806775342bcd99ad85359f666dd09323361a220ad
SHA512 (HardenedBSD-10-STABLE-v46.21-amd64-disc1.iso) = c656ac66693d68bfddd8909ea58dceff64f6b28607909615ce331359e70fcc4e3fe9427a27f410ff810d68849de907bb82d340afb5f784e43b7777b87fec036d
SHA512 (HardenedBSD-10-STABLE-v46.21-amd64-memstick.img) = fbb5f60f5a708cf8d44e3434eb4226329d7c6fbd49781755f8be355931323cf75c506a4ba8e3a82ec68643cc254b6cf434705a25b0ea52357f857c69b2ad87f8
SHA512 (HardenedBSD-10-STABLE-v46.21-amd64-mini-memstick.img) = 7b2cfe0075d1d58e21c64359b2d143389be8932c93c12242b17eb463bc0ebd9df0efd564402608ccccc9fc81912896dea859f978c88b998576954bd61604efb6
SHA512 (HardenedBSD-10-STABLE-v46.21-amd64-uefi-bootonly.iso) = dcfd6952056243a5989954bafad5396845520b011e6bd5da536b0ffbf3951c04caa5bc1bbee2e0b1cf8c4616819b859a0c51f2ae73a7538d06248b97d59511e7
SHA512 (HardenedBSD-10-STABLE-v46.21-amd64-uefi-disc1.iso) = 58a1ff92b43ed12933cbaf3436ec78cab6e1863f09eea9db15e16756975e31a1f9bccebd8d13a6af84d6931ec5f5ed9bf7c71b85c03d72a73ef7ab33dcd548ef
SHA512 (HardenedBSD-10-STABLE-v46.21-amd64-uefi-memstick.img) = 77224a1e23d460ec48e5df1c51c6876840817c79590818440e16a92eabb64119e87063763236a75f4a48781165af7e628ca403551fde03f070c16b674ce62db8
SHA512 (HardenedBSD-10-STABLE-v46.21-amd64-uefi-mini-memstick.img) = 52d2d2c46ab0797d87a3903deef608d5918a31ff2e1f9ff5c2e470cc9ea34c1388a3bcb942acb2a40b701789be511b38e6a709e187a1bb303a824c8c339b69bd

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlhIXH0ACgkQgZsRom/9
GI0ACg/+KhecsVMDb/vDD6ttn7NZJmQXia2nsoi0aw0FbqEeksK2cAlbKTr13yBU
OCyFg8zbDM/y1WEcS0Rs2StvqhRWoOU0G8L1H5sWFbQCxdYUZ1ndsbTZaaTSBlky
SQnzAdChWXVQsFXFAjEFA6i8xaHTvHIwxt0Fhw4oEO1FsaBDIY73Db8E3u4C9Cnz
tJuMyZKff6HffhHeBbzNT6eBM84J0r1yodIj7w1/Ep1PJLpEMNrn9IK55AIfxf+X
q7gSV8TKAMt3w0nnthJHN25vHQa7KcgbJYbiqoFVc54Hrm0sBZROwc17nx1+qClh
Qp+MbgK4flWMviL686OAnh7H5lwLLTX9tsMpqb4qC0C0YlvbxaNsenkv5z7cU2vi
E8vPLyiTs+k7Bes1jPpcZmVTE2v8Biu+H7HtPxWbY46GeqGZQ6VWjhIyDrbYCO3n
koDqlcfT7TDkIIqIAVJnidh9MXc5xZdFc9hZI0og507Wog0/ruCigHEjBNAmm6N9
wB04WjM1PrAh7JSGUXpmaDuUliu+m8MF4Jzk0cbk9N8gU4lqMgm3IOb6QR9oHi4i
CK098e1P6rHpdOG1wDsxy0YCDSbS7dOx26onE+2PXbaKx6t72M6sXr4ASZjQ+/e4
StlOllTbOP1KDtr8gZxctTXyjzPcMaEkHEeilzJrvysGAJ1o/H0=
=SVW7
-----END PGP SIGNATURE-----

New stable release: HardenedBSD-stable 11-STABLE v46.12

HardenedBSD-11-STABLE-v46.12 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Warning: this is a security update!

Highlights:

  • HBSD: fix for FreeBSD-SA-16:37.libc (CVE-2016-6559) improper boundary checking - b66bee517d74e7395ba293bc2f41cc8273f0acdf 54ef6264f7f041d711a6f2a6afeedd2f3646bdd9

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v46.12-amd64-bootonly.iso) = d1e8f7ab85cb80f155ffedff3bbd57847064bed3f3b2ea2f3ead2abddac041e007ff3ba6670373c2288620c00ffb11c3416c973840e5ccb08e03ae42b6fe4266
SHA512 (HardenedBSD-11-STABLE-v46.12-amd64-disc1.iso) = ba868e62c3e907e6e7c8751bddabffc4cca70f4ad7d447e88f68c1dd7c6d7974f8144110ffbdcdca704d7ea4f1e1a2de72562166ee12daa8db1c0632b5befa61
SHA512 (HardenedBSD-11-STABLE-v46.12-amd64-memstick.img) = 0a9f13ef94820deeac880f29e136f2fe904f30990800caddbedff12265cb5faa23252daa1273214c08a79211066d444d585644bbf7027384be938068f9a59886
SHA512 (HardenedBSD-11-STABLE-v46.12-amd64-mini-memstick.img) = c8e636881c0f651cc44d95f97539a7e6b0ebbbea046b66aed63ae1284ae336746c61c7961c241febd386f4f48ec57b0dac3311a9093357f4c606210c9f2a0847

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlhIfBQACgkQgZsRom/9
GI1SihAA4IQh1ptiQ4e52xcv16qoyqK5aZ5XRMFNLyudd/gRuxf7VEtjn5iHTvSH
KEBjHd2lEid0ELiGxKp5OjTLoRNNI3qe0Bzga3fBAbqKkAu2pnI5gpjM3ELt3OLd
/Eojw77mVILWeGdF9ZpYWQIPK6uDUvX/h6IOSkD7Y11ZXts5fjJBGLAhIKg2h0lS
3vyK2dYzDlCWhC6hm2tfxWeB0HeLad/FodS6wijOnlBoaXxrY2k8erIkGJjikb9h
G51hrWOTCoWPxAZ5FQreumyFckNRj9znKvzPrAVC3wjzlqJRuUZCqW0u5EY7ydXG
V5BO91cqc1eJb7gDsGQtzXWxUh3t6Lba9aHNdDpppdW5Sjt0flGWyt0pUptzHpB7
20iojO9UTJ/ba0VoqjNTzmq/Xh51BmNzlh1fvE13hKZAwAq2H3XVYccb9CRcitk9
Jh3A0incGx/qwmr/BmakYiBpvD/2+l5lBepeI4OumINbg8yPLHydk1jZUju3O+y1
cEKD9OjfCZpYbYgeFgmSq+Pzc2QFAKC8RsiMu9+5hHke9UBo0uUxxxTH43/KMF/f
77TveeYhu6XSRQ1xyNZOUPiPZGfBWZ7I33drDRoBXoMLX8ACEteawQjX/mVJbSJB
IZv5V4X8ejusH3StDtPwb7YiFEl2cP+ODIQXsjxtqaM5SA/y9i8=
=jspS
-----END PGP SIGNATURE-----

New stable release: HardenedBSD-stable 10-STABLE v46.20

HardenedBSD-10-STABLE-v46.20 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

WARNING: this is a security update!

Highlights:

  • FreeBSD-SA-16:38.bhyve - integer overflow in bhyve - 02a6052b3f42f24b9015e26ef196c33cdaf56719
  • FreeBSD-SA-16:37.libc - buffer overflow in libc - 6eec5c0ac4990b2cf298afce48e0ea2529fa645c
  • FreeBSD-SA-16:36.telnetd - insufficient error checking in telnetd - d50c6c5b00e248bc0ebd39164e5b7d56af49d701
  • ACPICA update to fix issues with recent Skylake CPU based systems
  • SVN update to 1.9.5
  • bhyve: stability and performance improvement for dbgport

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-10-STABLE-v46.20-amd64-bootonly.iso) = bc9012bd9af9b9a9e1458a5b73f509250a82b90fa0d54126b3ea13630b0f6dea8a42457c049d396b073c52a5199d477ffe892e64bf3fd129c310392cfd440197
SHA512 (HardenedBSD-10-STABLE-v46.20-amd64-disc1.iso) = bf585c79fd8cc0bf481e84a369eb76fb30b1bf1dd5c328d43b51e8b88f2033485b94b2be8025758774b95e5fbf67fe620a62ba62fec93d70ed156b41721fc99e
SHA512 (HardenedBSD-10-STABLE-v46.20-amd64-memstick.img) = 298f39484d6403403a9213c399d309706ad4c3eaa7181136180af019bea66ff2862d52d9e15c095de58207eccea1791a6fafe13e3e7e4677070fc0cb8c6399c8
SHA512 (HardenedBSD-10-STABLE-v46.20-amd64-mini-memstick.img) = 1725c96a19c9cdb9429c951d1b21eca5c1804a9c5d8cbbdd376eb783759b046f8105e2d94d5091b4d00725584d89dade2df2e6128803ee55b98e24af99f93a58
SHA512 (HardenedBSD-10-STABLE-v46.20-amd64-uefi-bootonly.iso) = 1a55a48c7ea229c7b994262619db606b40424682a480978d6a95cb1ef29bfef2c8589b89ff27af31a1d4f63a63c4cc96b63dd084b8dcb6fe61cb461677243aa5
SHA512 (HardenedBSD-10-STABLE-v46.20-amd64-uefi-disc1.iso) = 00ea40e7afe74072feeb9cddd990eb482aed3259e20a754c0f38ddb1e7d7c63da9886be4740662d48f69334fe0b4dc3fac5195a62f9ca4e4b08c3ee81f6df834
SHA512 (HardenedBSD-10-STABLE-v46.20-amd64-uefi-memstick.img) = 46ccc6a8e8684d34867c811efbc3f87c4225fdc5b789235952630052b100a508b2012a6c3b30b703952835bc772d9b99a2687283c9330a6cb8f543eba31ba59b
SHA512 (HardenedBSD-10-STABLE-v46.20-amd64-uefi-mini-memstick.img) = 00815ec0284ccdfc56a5c877555306b444af525a64b78af7a72e1c5efb2ace936345ccba787df4737628cd728aa449e4d0a802e9040811a82a576eed08d13de1

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlhHJzEACgkQgZsRom/9
GI1VbxAAveup7QZKBQSZn3fWgUcdW5C91iqD78UqdGuO07fh8GU7akbh69emf1h7
OLgXSgjxw2PGi2Lt+PxlhMgxTs9KHe20/dX14nOGQnJbRZphH2ZhsyIo1a2Ir94V
qx1d1ha1xSqYMm3xMaj27/Q6aks23lEF5DL+qwNJ6dnpgaU4/K297K+vt5ixtD6H
bxSy3kqSTg2MSx0EiITguoR0c40zocKiqs6QnqIPddgGo5nIeFgktviDH2StthjA
SkqqB7O/Hi8M1ePDOJlFWGuWjZXoc+s+6Y/JdV6FnJv905clrjiVG6wPoV7naPGJ
PVZBjjdjn9i/roF327C3kFagGc7tDLb18xHFJWr6jiOvg5vRNsAoepjwIPSRcUh9
iJPptUgcqBPrpvaBZyZaQsfh5sor7BCYmt7nfS3FU5aaGqTrKawtwqMeF3ID3Q5k
Q+aOxUz/cXQnLSURXG8RyrIfk0I1a4aQoE47lPnlWZ3HHBBYV7/h1sE8sTkuP6pO
OjpadzPF5M4+LMA5qzGKCC+Oo7sISJ55HQjdQa1x3WV1ok7Ph/BfMcj6/v08OTh+
Fauingu+ZoZbj/rQcPN6t/dS4n2JEeeD/KX2JWII4ogP2znIIrZmprOhrKAtG8OF
AHZxVq5/AjXgaBrLPBe5BhDEEA2jKn0e3ifLh+iI8Mfs+5uT8vY=
=7uYD
-----END PGP SIGNATURE-----

New stable release: HardenedBSD-stable 11-STABLE v46.11

HardenedBSD-11-STABLE-v46.11 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

WARNING: this a security update!

Highlights:

  • FreeBSD-SA-16:38.bhyve - integer overflow in bhyve - f836007bd73e9e537d2aa37f997452952dc86d84
  • FreeBSD-SA-16:37.libc - buffer overflow in libc - 8ce24fbbdcb70e8a23953f5da6f4687b334c3f84
  • FreeBSD-SA-16:36.telnetd - insufficient error checking in telnetd - b3dac027c0c7df4a5b85edb1c34742a467493508
  • SVN update to 1.9.5
  • bhyve: stability and performance improvement for dbgport
  • updated default HARDENEDBSD kernel config
  • Hyper-V updates

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v46.11-amd64-bootonly.iso) = bf0cb0253e6c3b037782d46f7d518934d707e679b876cd8d095255f7132e0c4a0010223b0372e6a14816d224a16cc803ed4fb1f1b236c474d92cb0f09d9a645d
SHA512 (HardenedBSD-11-STABLE-v46.11-amd64-disc1.iso) = b67f247bb254b123bdc82080ebf02c4acef5112a4cedc0adade853c1905838102f58abb8c2a83902beffd6f1265b58a1e26be6c22777f88fc550f3989982cbb2
SHA512 (HardenedBSD-11-STABLE-v46.11-amd64-memstick.img) = 492d0ca285db1db830501ec3078e36236a99cd20f61c6bc0973a0da88f8a9cb7f11051d18cf0a1019421aa94617782c78787fec36af207f67574541d17bc74f1
SHA512 (HardenedBSD-11-STABLE-v46.11-amd64-mini-memstick.img) = 23a494a96584f84951a02f053c4d1e4388a7e4f39535a62021ccb3c106faf4e3f78282ba8df4c8b2b61d5627de40051ecf6efb86c708ba55ed87fc56f1d8182c

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlhHXZsACgkQgZsRom/9
GI0UaxAA4i8gmc2xFdsEvfdV69eiObuH+lt7Oa9Ig8yzoHb4hNDZAAz7oPQC6Ila
/eP7+ZLNdCV/OwkkfQzfpGz/yRo0LOxxS2H6bWaIxAMgAVb7O79g0PLcAOUtBDQ/
zZPJ8KQbNtfNDAxqPkDd1h4bBRfLdeg0uYp2eORdv5ff+ElqN7J6pX+WP2oTmKiX
5GdiEUWLxyLg0fJAgZpNGsSkbU1AA9wFsJDJFcxh7zQC8cC2sor+/2a8TKy3YGLB
qRYANiDdwZmXdeIOHxV70k+gN0ra/yxZCP+3813bnOmBzZjX3DsJ2TpmSJK6EYMd
zRKvTl3Lhgz4oDF9Tr00ob4jExDapAKTgg3ZxuzYW1QG8vpd8RqJbnsRTRE3vVxD
gW6y8U5xviQdO38d8xkeaMIxz5t4EHcr0d4rQhtjnI0sz+QQajZkwOkuqFgJ7TN7
ayR541g8ksju30RfdXMuGtn/ZVFOSKN8cCxohqAw37iC18uy7wyT/naNVJFpru9Q
M1PhNbhbSS7Npawr12aZu+B29keZ3S8Y6reyk1j92UUtkcw3utHN6CLlmpweXpga
I9b0wMj2gtbXAvRsfQfra4zK0OK77+R3xm7cpNhfCbsRh0zhs3Idzu0YJy5yxT/G
q1fRbZmVxQOELfhSn9XSmKcecajCCbsB+cMfobD9eeDbVZUZdqk=
=XzZQ
-----END PGP SIGNATURE-----

New Ports Tree

We sync with FreeBSD's GitHub repos every six hours via an automated process. Our automated sync process sends us an email with the status of the sync: if it succeeded or if it failed. If the process fails, it tells us why. Having this automated sync process allows us to follow FreeBSD closely and manage the occasional merge conflict with ease.

Late in the evening on Thursday, 01 December 2016, we noticed that the sync failed for the ports tree with hundreds of merge conflicts. Even files HardenedBSD hasn't changed were in conflict with upstream FreeBSD. Around the same time, other people outside of both FreeBSD and HardenedBSD noticed something was wrong. It turns out that FreeBSD's script to convert from subversion to git had issues. FreeBSD has given a brief post-mortem on what happened. The problem affects any project downstream of FreeBSD that uses FreeBSD's ports mirror on GitHub.

On Friday, 02 December 2016, we started looking into the issue. On Saturday, 03 December 2016, we stopped the automated sync process for our ports tree. We made the decision that because the FreeBSD's ports tree's history had been rewritten, causing commit hashes to be different and merge conflicts with hundreds of files we never changed, we would recreate our ports tree from scratch. We have imported the core of our changes to the ports tree as a single atomic commit. As such, we will lose the history behind all the changes we made to the ports tree. If you followed or watched our ports tree through GitHub's interface, you'll need to follow or watch it again. We're running an experimental package build right now to make sure our ports tree is still sane.

As part of FreeBSD's post-mortem, they noted that the same thing can and likely will happen with the source (src) tree. We are investigating what we can do on our end to mitigate any short- and long-term issues stemming from FreeBSD's subversion to git conversion process for both the ports and src trees. Obviously, losing the commit history for the src tree is much more serious. We are working hard to prevent that from happening.

Introducing SafeStack

We are excited to announce SafeStack in HardenedBSD base, along with the availability of SafeStack in ports! SafeStack is part of the Code Pointer Integrity (CPI) project within clang. For those running HardenedBSD 12-CURRENT (the hardened/current/master branch) on amd64, you can enjoy the benefits of SafeStack. Simply sync your source tree and rebuild world (you'll likely want to rebuild kernel to match world, of course). SafeStack is enabled by default for amd64 only. It is not ready for other architectures (like aarch64). Additionally, SafeStack is only applicable to applications, not shared objects.

Since SafeStack is still in early stages of development, we will not be enabling SafeStack globally for ports like we do with PIE and RELRO+BIND_NOW. Instead, we will add a flag to commonly-used ports entries that will tell our ports hardening framework to use SafeStack for that port. Users always have the option to opt-in or out a port via the config.

As the lld project becomes more mature, we'll make sure to test other CPI features. We hope to incorporate more CPI features in the future.

UPDATE 28 November 2016 - More Info:
Not many people may know what SafeStack is. Below is more information.

SafeStack is an exploit mitigation technique that creates two stacks: one for data that needs to be kept safe, such as return addresses and function pointers; and an unsafe stack for everything else. SafeStack promises a low performance penalty (typically around 0.1%).

SafeStack requires both ASLR and W^X in order to be effective. With HardenedBSD satisfying both of those prerequisites, SafeStack was deemed to be an excellent candidate for default inclusion in HardenedBSD. Starting with HardenedBSD 12-CURRENT, it is enabled by default for amd64. Support for non-amd64 architectures is limited by upstream clang.

As of 28 November 2016, with clang 3.9.0, SafeStack only supports being applied to applications and not shared libraries. Multiple patches have been submitted to clang by third parties to add support for shared libraries. As such, SafeStack is still undergoing active development.

SafeStack has been made available to the HardenedBSD ports tree as well. Unlike PIE and RELRO+BIND_NOW, it is not enabled globally for the ports tree. Some ports, like ports-mgmt/pkg have SafeStack enabled by default. Only those ports that have been tested to work fine will have SafeStack enabled by default. Users are able to toggle SafeStack by using the config target. Additionally, the SafeStack option is only applicable to amd64 architectures. Attempting to enable SafeStack for a non-amd64 port build will result in a NO-OP. SafeStack will simply not be applied.

Here's some good weekend reading for you if you'd like more info about SafeStack and CFI/CPI in general:

  1. SafeStack - Clang documentation
  2. Fine-Grained Control-Flow Integrity through Binary Hardening (PDF)
  3. Control-Flow Bending: On the Effectiveness of Control-Flow Integrity (PDF
  4. Code-Pointer Integrity (PDF)

Stable release: HardenedBSD-stable 10-STABLE v46.19

HardenedBSD-10-STABLE-v46.19 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Warning: this is a security update!

Highlights:

  • Advanced ifunc resolver in rtld (ebcf883abaa4a5407d9321c90e77b62d5400239e)
  • Updated ntpd to 4.2.8p2 (ae8e146bd5a44ecee88074684cfb450384368980) [FreeBSD-SA-Candidate]
  • Possible UFS related kernel panic fix (f1841547a520610c8f48c2c0b473b55dc84e1714)

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-bootonly.iso) = 98bfe0c145d04e8476a6af8639c8a1324c96572d4fc3739708e45e2bbab210a79c0bb766171034bba946b53db32782edf5f81d78a7f1d71603d6270117590027
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-disc1.iso) = 6c1672403a04dc819b45be7846332767266c1e565db14fb5d82e26792ccec4024f0348c71242464e18c3b4011fd235dfdc686ba8e342f2edea9d1b097167ba97
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-memstick.img) = 7297be987017198e761f85f43677677826b8828fce6bc8b7c233f6ec40abf84f5d23fdfe63c0c2be42d7017a8c8417286b793fdd865df68dbe769f31433a354c
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-mini-memstick.img) = ee63073bef4d3e4e8f2b86c8649b403eafaf7341432966fa97c76ad01544bff5e4819be84befa51ce7dd3f3c8da9c8192b6a7883cf3113f2306ddba7e4182811
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-uefi-bootonly.iso) = e776686a78c765125bb3cd2adb7cefbec1e529ba4ceca31a19809ccb7d1ca9c6076fe8f404f1eed7a7d616abd1219ea7d22356f8eb30432074ca414e5d5f05d9
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-uefi-disc1.iso) = 5cba03d06f4c7d67cac958843c9a7026dfdf4b498ad658c1bf112a9dca04b45fa16d89c1be0c8fd316ac2b37a05e58498b9459cde81144a2942497edccf43852
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-uefi-memstick.img) = 117e6ebee28e9660dc5461f5b5dd7ef940ac09539dd2e2f7f8da11f821c7f4db3a9f3fa356a655ca7fff192dad4d6e39137e26cb79f6737ff31afd6106cf65f1
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-uefi-mini-memstick.img) = 258221b9771875eb49e7ac997d1d3924023976fae5f9247659d474eba69acca5cae29bc2b2ef6894494760d322287976b79e09746e718869f2cfb74ec174b3ce

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlg2IwMACgkQgZsRom/9
GI3yoA/+NIY/HrcYpsGI23u0F4OnWV9AHRIEsaRdkq6vFAfXlaX0Idlh710ZQEgw
TbTCEGWFTGNBnr004JmPp9DNvUfSdjgK3I1LGV9TZvEqzv5kybY6cmZLYjzyw7nx
sreCTKlviJePbRViAjWPbPNH8a9G8nQModDeD+AoOzYx1j/S16uilsMETQDTV+lL
ROW3C+ia2XyK/wTW3AVoC1AjoeRvDV73bOP8Qfs8RLqyqmAZu2ii15BRNkMMuACz
XwxSQ6Dg22f8U9vTSinnr9RmPfT9LyFChwiE7CokKqJG5ROL/esbWaRBSch9UmQS
nulrrbBAy2LhoUzSlG/100SsWBsn8B3ZMhpBpJgINGhU5gBLCSW4PWLvE5yo38eE
6qKWpjOq3YXUvON0wvO4sjTw/QOoIhMB2sTp8H35tv/sDBZpd0sSr4yMTCKWD9MK
Vm8WlxH8fXlDkCPG7ugdqYL45A8zkiaXYO6jHuGiNlvYznaxytY1O6zjXSB5c5FA
IJ/t1br0q3f844mELDHuMkQOg3UqWi+Vr/x0oni9bKCdcp89U4xaDCyB6Jb3jo/X
6bYnXG1FTuzijxE9nfs/kFw1tZhoSJmB6t87gkiIgvFR/u7U4m5PfhoV59sOkrj8
OSZ3kzInbxEqNfglcWfi9UVaJJwQOkkDWfE5Z4GBHFOX3yrOSqo=
=5c4N
-----END PGP SIGNATURE-----

New stable release: HardenedBSD-stable 11-STABLE v46.10

HardenedBSD-11-STABLE-v46.10 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Warning: this is a security update

Highlights:

  • Update ntpd to 4.2.8p9 (db75d5027e10e6a41b54cb66e21f2fe7480a1618) [FreeBSD-SA-Candidate]
  • Initialize reserved bytes in struct mq_attr (a0c278e1ff9e12b0d2716d96eab8499cd124918b) [FreeBSD-SA-Candidate]
  • Increase the max allowed size of the microcode update blob for x86. (01d99faedd3455353cd536056c4aeb3f97086cc0)
  • HyperV updates
  • ZFS updates
  • VM updates
  • tzdata update

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v46.10-amd64-bootonly.iso) = b044feffd705ac9aa12f5c9fb9a6c3696353dddfe5bf398968b2cadb02e086b964c2010736232d10c08087ee9ff0f86658415a3d401d1d3f8ea5424f06b33060
SHA512 (HardenedBSD-11-STABLE-v46.10-amd64-disc1.iso) = 35d96229be27bcd1c538875becbf9078b5d727657ebac0584799e1a45c791ab9f013837ab4177415477bd4cca599fa657176267407b464b46dd693a075a647a2
SHA512 (HardenedBSD-11-STABLE-v46.10-amd64-memstick.img) = 61f92489daab8c6eb5cbb6d9ee31a040f1603b55a26d3049cda9507e9c374dcfb7fb83e876cdf9f07fb93966a5565dd50b14d95357d9687541d3782c4562b88e
SHA512 (HardenedBSD-11-STABLE-v46.10-amd64-mini-memstick.img) = 0364d36957814afa094d19603c30839c7caed783254e8f1b5de4b893493641386370f678a0c9ce8321be0b5be260c5bc231db55c73f401c2469e29a83366892f

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlg2BSYACgkQgZsRom/9
GI0wnxAAwmJq7LA9WSfSUQixeHqGCXcu6XyoxZJbvluKdbZsacFZYjd4G/wYGYQx
YKZ3ShHTzJIJAbpPg0a2OfNDMtFa20YX/mhcU3/qW9gZMzKMVdO4lAMYFokAQQDL
GCvtzh4QY+XRDhbI3RXr16bYsOSFSjDci7mX1RBui+U3ER7pzcymPuOO8703Rewh
+pffiHSlFragITJo8PDZMLwFwWeq4G92g1YODmrADYzxPDuBF9+ax8Ysgq4nzqPr
mdg/JyLRpz/WE1XSsGuZB6r5yi5CV/XLJb9mBnLXRQyRvHe+zMqO3uvLr1mdcIZV
/TTleLL32FVQXf2+UXfs6w8qy4kqUZT6kLUecV1dixc6HXk4YGkrKLrahKKQWe/Q
lxUo6JhMxQbQCZJY18gDEMiH4kpSmb161BXAjmWHon2vhqCkLnOYxo1tbrEDof6i
Ndz8F9C5MsuZg9a5cnwxKW7xWE0dV7rjMxLQ1dooil1MVRY0Ap7jO3HsyuHiZskU
m+YObvCMHTFbuX/Qrag/f1t6Q1sWvaUSL0o7l2hRS2XSPnaKE1IomPK1i0oJtIKE
DE3Hg6ydL5zQOzkOoC3Gs092Y/RATfw/7SRdwtFrPt+zmFnzK581VFLfqMyvY3lT
Pg3niuMPETIbpWiVcGJGYuFSew/52FCFbHisrMX/367XPThQqww=
=AM8E
-----END PGP SIGNATURE-----

New stable version: HardenedBSD-stable 10-STABLE v46.18

HardenedBSD-10-STABLE-v46.18 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • HBSD MFC: elimiante infoleak from uipc_mqueue (r308642) 986b9324751267 [FreeBSD-SA-Candidate]
  • MSDOSFS updates
  • Hyper-V updates
  • HBSD: increase UCODE_SIZE_MAX from 32kB to 128kB (4MB) in sys/dev/cpuctl/cpuctl.c to fix microcode update on Intel 6th gen CPUs

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-10-STABLE-v46.18-amd64-bootonly.iso) = 9b6dbd1e941c180dfcf16f55b7efa878971139bd1f9a3c02bd37299d817711eec8adec078c90d078620b636435d9f654c42e2496bade02c7bb15f8efc4123ace
SHA512 (HardenedBSD-10-STABLE-v46.18-amd64-disc1.iso) = 0973251862ccc7b2908f37926e713a6f377347f7a4140384af2a2986cafa2cefec563e17a5b8677f23755e1292c28f9fe6c9d325123fac631762fe8ed5f2a2e1
SHA512 (HardenedBSD-10-STABLE-v46.18-amd64-memstick.img) = 0f14f0583ef847daa6372c53f4490e7b4607fcbfda6c58b27b9124592ef8980875e5d7d4209c4be93606de16bbcc4c0d0a0111834775b1da6d4b13574c11b448
SHA512 (HardenedBSD-10-STABLE-v46.18-amd64-mini-memstick.img) = 0ab823880253fb0b494b4f757bf8b66fa88d498259e213a95d7b2b305c0d01385a3af552e44944831a4077d807e8ecb61a8ffa13601269938df323a37c0b2760
SHA512 (HardenedBSD-10-STABLE-v46.18-amd64-uefi-bootonly.iso) = c7b513cde20c51fb84daac30e46e508498ea978e7b5f57911c2a894a037e5aa14d8a703da4a3b37e0ef146383e0ba177e65a13abcb86b002ee94f4265d99a0b4
SHA512 (HardenedBSD-10-STABLE-v46.18-amd64-uefi-disc1.iso) = 5fa03972fafa63fe5c65b4a661225e28df33c13b862c9c6a27da2c16cf71642d82c7c1d43e5e4c3dc1ddfa3f423d80ce3162629bab859ff5eb5d410bf6bfe306
SHA512 (HardenedBSD-10-STABLE-v46.18-amd64-uefi-memstick.img) = 3bb0b7b84598a818038361323216aab23b0651daed94129a287f7f1576680fb28e95af51ad1f34cf10b894013c206cd3897fcec6d60e981e13da669b8fd792b1
SHA512 (HardenedBSD-10-STABLE-v46.18-amd64-uefi-mini-memstick.img) = 1a7f6669d6518fbfe01a7edf728bfea7d050c365ef2969d63d54b8d33e41f9644932548e8e2b3095f8999ca07165b00d0953196dc731b8e5cfbbb392e6641947

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIcBAABCAAGBQJYK4FoAAoJEIGbEaJv/RiNNb0P/jRzFmwHVyGP8zHp3Q37EQR3
tgC99+AbeDsuDIgTER7zt8KeszEiMnQiSyg8+8Lb07WcHlzLjmzHyWWym97FkjVt
wTQWiO0RzeXJnP3FH7zsEyFiuphxv8F218YfUlI5aJ8kBrHschWizFq2HC+FonU5
GDLkB8t/yKZDQG9zz/Cf+lTQIfs3+KMezu0V4pcDAuuvs0WQpk7xyrDn4fYbX73P
PP5jW7T+ZrOF5gJlOyuBn9RddPk/qbyyJfTAmwv/Ru3CgoPVY2b4EGW1nIAWWs8O
SL/r3NbW3nNH7Umume0eJrSPWZbgTDm69zQGKddE9F82hsiyziwpcPYL7ZmWyY8i
tiidi1kM8WrqF1cvUTNZyfJDA1nFUuV6dSrjDl2/gBjiIN5FUc0P7W2uNGlgPEJW
T5A8r8U1BliTT8PfBDYw6VIzM8k3zm+Hj3LVq8gGbZRmqZsCClNS8ClJomJQbn8/
zjzq8zrC6/XLw4sspPMAsvEOYkXhaVzEXXGAFXMaBqm7kmNP8hcBEE3b9OR6EXze
VvoapFGPD4lnBPpntsJeiB172A+zZkVNeEmBv9klu6a+JyocSvNUcb1DLmILyj4W
R2B63k+okPoUdujXwBEJ7X4DzZwfgXZZeyBz70snNvUOSqjhMY63nLXBYXu/biPX
JXErKmjmmWW4LYFNaZFc
=lMRM
-----END PGP SIGNATURE-----

New stable version: HardenedBSD-stable 10-STABLE v46.17

HardenedBSD-10-STABLE-v46.17 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

WARNING: this is a security update

Highlights:

  • OpenSSL: Don't allow too many consecutive warning alerts. CVE-2016-8610 (3944e88fda9dc9f4f391a06b18cd7583f783e8ec) [FreeBSD-SA-16:35.openssl]
  • MFC r308197: MFV r308196: Fix OpenSSH remote Denial of Service vulnerability. CVE-2016-8858 (bb8c1d3b5e1d1ff2b26db3fcd0ca74e6418a4908) [FreeBSD-SA-16:33.openssh]
  • MFC r307132: Use copyout() instead of pointing sbuf to user-space buffer. (1e74d3419b0da1ebb8106c23763e29c3ddacfc5a)

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-10-STABLE-v46.17-amd64-bootonly.iso) = aad9e8d4c879e77aebe8f6da63654f5f3a5b8fc1dd67cf20e158d537255ca2d0ca1ec9752814a0b7466231e4e49a61be31cc8b9d00e8ceae4f5bf5991a246626
SHA512 (HardenedBSD-10-STABLE-v46.17-amd64-disc1.iso) = 4cfb825fad4c9bf2872d3da3aa8e9ec0e58ac9eb75441c9af87f062cf9a6a5353340984d59efeaf906bb184e15b574d82e908d868c45fc7fe6885a326c59972e
SHA512 (HardenedBSD-10-STABLE-v46.17-amd64-memstick.img) = e1287439ab32fe7cc8738ff35b2c6fa7faf8960b85104512a28bb5bb3c39ec07c30669e19cb8bf6223e85cce0286a33927f52c38522efde5c92c7a4c103bbc65
SHA512 (HardenedBSD-10-STABLE-v46.17-amd64-mini-memstick.img) = f14b0dbe4c2af31a02a8d919fd8ffaf0835a3ac4ff59330a51bb38ba993ea963493e48fabe9c89c564be46eacb0506d060e45356e319315c0d6f94dea28eab12
SHA512 (HardenedBSD-10-STABLE-v46.17-amd64-uefi-bootonly.iso) = 05170a1ea94e3b828ba501a76bf544d7c3082539b7ed0c555381c0c53faa878e103d2faf155fcda8d705ebefb8e0b4e08288a56e9412f1c8d15b7bd771c9a5cc
SHA512 (HardenedBSD-10-STABLE-v46.17-amd64-uefi-disc1.iso) = 36e8325dc103e12472b0a68ccae88ff632400fb9fc70f77857ee757c33342ab0f22f877801384ecc39cd77dbccf1e2cc78cf0564b0d86a3f3d225cc6fcded5c3
SHA512 (HardenedBSD-10-STABLE-v46.17-amd64-uefi-memstick.img) = 58d1abe6a6e55d88e77840a4ea804c0b789b79981f11a1c0ee4d4c0ec8ddecd3dbf6754d97f254d06bfeabdd0ffa725c6d76150ecd64604c85b23760ddbd92ef
SHA512 (HardenedBSD-10-STABLE-v46.17-amd64-uefi-mini-memstick.img) = 7cae17f04dec06c67f4307dc12114897fd87560a5dcf800b79497316ca328abbcaba2406daf9d4bb1e728f5b50741ee9217215b2bd425aa9bd32309328d8173e

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIcBAABCAAGBQJYGdoMAAoJEIGbEaJv/RiNyWIQAMVKOe8zAIrAQLiIvx2GqGMp
JluKdh5+dgRcDlDXBrnbpWthsCNx22zfIYfPKezH7qVdd+yIMAI5pr3K19IADWDb
JkJjAishvAnxmUsF0MjLuk7zWkuKmxpN7ZBRTZUrSkN6qzQqvelK68NPi+fXCJJr
62kMOmoQfmswNu9SzCAPCSN9eSsg2f4F36oYLCiHsVAybWhyDWiikJLii74cCOVx
YgSSnLU07mDhq3DKHV5l41lKHtGEL99UwoaVT0fdQrPqf/saSb0Pw7Z019cOeg7e
vq4o+uAKgbPe6w+QUAYnc6hNU5w/md1ljP5cXHGg1GkXw5sHVXnvbS871/4tyghx
v05MOeM1srHyLkv0EznA/raWfs2okZ7P59pCrNvd9FYeJquk4dk7ItSF20fStoEm
RN1g6cCrLwtfzKNWKaP66vnLjtdZt4kKTkSvXomIzJlI4mHAWIAxH430/zqOEy4O
QUWrN3I7FHA3O0HCVdEm6fcyMmlL6YN5Cb9waMyDMM/jZX/ZePnpgZd7S2o1nRpa
HxkpIllpsclYr0cEzGwucdSWOUUf2xYvnjF5P5koaUI/B98ZfDS8j1oBqvizJtGf
ArWZsGlrPmSZkJF5LiB0nJ7d2JBESB5CrAKpcEN1hfskLnyQWEfyFlpDLNJydW4u
XGtCwRGzoGcaFGir3D1g
=z6fM
-----END PGP SIGNATURE-----

Pages

Subscribe to HardenedBSD RSS