Stable release: HardenedBSD-stable 11-STABLE v1100056.13

HardenedBSD-11-STABLE-v1100056.13 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • MFC r343784: Avoid leaking fp references when truncating SCM_RIGHTS control messages. (70e1efc1c0f84fb9e92135883a6107e2ef19642e) [CVE-2019-5596 FreeBSD-SA-19:02.fd]
  • MFC r343780: amd64: clear callee-preserved registers on syscall exit. (7ecad8ecb0ef125b47333806ace844e7792294a8) [CVE-2019-5595 FreeBSD-SA-19:01.syscall]
  • MFC r343499: rc(8): do not stop dhclient(8) when wpa_supplicant(8) / hostapd(8) is used (15afe7b042f7cdfad46cc2eca5e59dd9297f6197)
  • MFC r343418: pf: Fix use-after-free of counters (a1b261656792fdc235e151c61ea87b06dd48103a)
  • MFC of 343449 and 343483 Update tunefs to allow '_' in label names. (627115fbab7f0ad32d8d58f2ac948255c86a33a9)
  • MFC r343249: Fix duplicate wpa_supplicant(8) / hostapd(8) startup with devd(8) (396ce8497cb2ae7eed1e297d7edf3396759eaca1)
  • MFC r343089: Limit the user-controllable amount of memory the kernel allocates via IPPROTO_SCTP level socket options. (58e6efc1eb253c25e32671305fb296c75c88e173)
  • MFC r343082: Implement shmat(2) flag SHM_REMAP. (5e5aec12f096e44b4aff26c5b9623f1eea21b72c)
  • MFC r343286: nfs: Zero the buffers exported by NFSSVC_DUMPCLIENTS and DUMPLOCKS. (676ce698dd3e14aac903708b48c9e447e46526f0)
  • MFC r343265: hwpmc: Plug memory disclosures from PMC_OP_{GETPMCINFO,GETCPUINFO}. (99c280e90dcde9a082478af18e6806adae270cf9)
  • MFC linuxulator stack memory disclosure fixes (8139f0a4ce76358213e6802baa237a6e0f4a8f8a)
  • MFC r343043: scp: disallow empty or current directory (ae0b64fb08800073bccfffa0e7ba12fa30dbf669) [CVE-2018-20685]
  • llvm updates
  • ena updates
  • ipfilter updates
  • pf updates
  • net80211 updates

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v1100056.13-amd64-bootonly.iso) = 2d3601235daf67914e522ae03e28717af8c8f380a32a57bf6ce01dd1b5c90a2e381766a89abbeda9ac3c4d46b998f0ca9846fb8c59b9370985e56fde126e4836
SHA512 (HardenedBSD-11-STABLE-v1100056.13-amd64-disc1.iso) = 90bcf218e2575331f6f83f7b83e6c058fd1c268ccecdc162be385c95e22aab849c5090c90b03fb46135893ecc75d42341dd3373574cbf2597fc09611e290034a
SHA512 (HardenedBSD-11-STABLE-v1100056.13-amd64-memstick.img) = cffa5583145e6ae2fbd9e12281aaef06fada4886095fa220c4b62464c453873839d8c59b276f0866ee038c96d1494275f0d1852ca39714914d3d5d744fad7c76
SHA512 (HardenedBSD-11-STABLE-v1100056.13-amd64-mini-memstick.img) = a4ec2037cb9d7054a644c12518867bf8f2ba04353e238d5d26e2faf64493eb2bcc65364a245e157193ffa657e7fe6a25ce109272b7a7e3064fd6d18d56f46ee3

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlxavC4ACgkQgZsRom/9
GI2S0Q//fpLION18AZR7veeEBk7hz6KdrvE4xR3I1HYYAsK6L+/IVO3UX04lyhju
Ypu2efMQWuaq0yTpqq7UEgn4lysTEFIruaoMtmto6JMxtnBOdLBwVR8Es/uE23TU
12EEVL/y0c9zb0f7cXzDso6aMZlH/sIUp3LMF6P8XIfo2T+UbqAipWGeTYSwcPTE
+xH5JjfOv4i+0OjVClVB5KH4h8zNGzOFLR6yfx4JCQ96/X5plLx2pTTstvODBSjE
RAFIh3wSISc3tTjAGiJ8P+XiD0+41elF2EutoUcpgRVvazCtnjbXl1ep09y/r0Zj
uiAlVpIoHYBBTFRyvPiefhEzTdOT87xNMdYRvCqxerrHqNwrSAzzw1jtDjzoWNPw
e6Z79gXPSTZWx/sOOETB7M58m2nUeH3cypOKszuf+SroKWor37uxreLjMHCptIHB
SaFh2M7mkKQm9nuaV3TO+oPJPYQb0muiu8ujESm93xS24PfwePmn7jzv3QJCiXFT
MMGMfhiL8DDVXnkBDftTarTX56sba+S4DlQ0SAkaraEfKxn+PzpTgqsUuL4dzXWe
RHwX7+EiP9FoirhKiRn+cRObHU8EAO0628FU38AWZNfJgA7QnCPiTkeQR3oAjiKf
tZwdQOmPlzDyKozvcIIhUQYIOrKBKlWolRSfr5a9o0DVw9fef7c=
=OzKS
-----END PGP SIGNATURE-----


Oliver Pinter (1):

  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master

Oliver Pinter + (48):

  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master
  • Merge branch 'freebsd/11-stable/master' into hardened/11-stable/master

ae (1):

  • MFC 342925: Relax requirement to packet size of CARP protocol and remove version check.

avos (20):

  • MFC r343190: net80211: drop m_pullup call from ieee80211_crypto_decap.
  • MFC r343244: devd.conf(5): add otus(4) into wifi-driver-regex
  • MFC r343249: Fix duplicate wpa_supplicant(8) / hostapd(8) startup with devd(8)
  • MFC r343213: net80211: resolve ioctl <-> detach race for ieee80211com structure
  • MFC r306323: [ath_hal] Add FCC6_FCCA regulatory domain (0x0014).
  • MFC r343341: ifconfig: drop unused macros from ifieee80211.c
  • MFC r343235: iwn(4): drop return code from iwn_*attach functions (they cannot fail)
  • MFC r343340: net80211: fix channel list construction for non-auto operating mode.
  • MFC r343342: net80211: turn channel mode check into assertion.
  • MFC r343234: run(4): add more length checks in Rx path.
  • MFC r343238: urtw(4): add length checks in Rx path.
  • MFC r343472: otus(4): fix a typo in man page (802.11 -> 802.11n)
  • MFC r343473: geom_uzip(4): move NULL pointer KASSERT check before it is dereferenced
  • MFC r343495: wlan.4: improve wording
  • MFC r343497: Unbreak devd.conf(5) regex after r343249
  • MFC r343496: pcf(4): fix parentheses in if condition
  • MFC r343499: rc(8): do not stop dhclient(8) when wpa_supplicant(8) / hostapd(8) is used
  • MFC r343502: Remove RADIUS-related files when WITHOUT_RADIUS_SUPPORT=true is set in src.conf(5)
  • MFC r343576: ndiscvt(8): abort if no IDs were found during conversion.
  • MFC r343541: Drop some unneeded includes from wireless USB drivers.

bapt (2):

  • MFC r340933:
  • MFC: 332990,337892,343546

brooks (3):

  • MFC r343162:
  • MFC r343366:
  • MFC r340242:

cy (5):

  • MFC r343073:
  • MFC r343103:
  • MFC r343486:
  • MFC r343600:
  • MFC r342815:

dab (2):

  • MFC r342770:
  • MFC r342822:

delphij (3):

  • MFC r342845,342846: Port NetBSD improvements:
  • MFC r342856: Added support for the SIOCGI2C ioctl.
  • MFC r343038: Use TD_IS_IDLETHREAD instead of unrolled version.

dim (1):

  • Pull in r337861 from upstream llvm trunk (by Hideki Saito):

emaste (3):

  • MFC r343043: scp: disallow empty or current directory
  • MFC r343153: freebsd-update.8: mandoc -Tlint fixes
  • MFC linuxulator stack memory disclosure fixes

gjb (1):

  • MFC r343259: Correct a typo: was -> way.

gonzo (2):

  • MFC r335675:
  • MFC r339523:

hselasky (5):

  • MFC r342730: Improve USB generic debug messages. Print process ID and name when opening and closing usb/ugenX.Y character device nodes.
  • MFC r342778: Reduce timeout for reading the USB HUB port status to 1000ms and try to filter out dead USB HUB devices by implementing an error counter, so that the USB enumeration thread does not spend all its time reading from non-responding devices, blocking user-space access in the end.
  • MFC r342884: Fix loopback traffic when using non-lo0 link local IPv6 addresses.
  • MFC r343451: Add full support for PCI_ANY_ID when matching PCI IDs in the LinuxKPI.
  • MFC r343453: Add new USB quirk.

jhb (1):

  • MFC 340206: Treat the memory lengths for CHELSIO_T4_GET_MEM as unsigned.

jilles (1):

  • MFC r343105: libedit: Avoid out of bounds read in 'bind' command

joerg (1):

  • MFC r342791: fix a typo in chio(4) (which propagates into chio(1))

kib (9):

  • MFC r343108: Trim whitespace at EoL, use tabs instead of spaces for indent.
  • MFC r343081: Trim spaces at the end of lines.
  • MFC r343086: Remove unused prototype.
  • MFC r343302: Remove unused *_sysinit_flags() declarations.
  • MFC r328433: EMFILE errno documented.
  • MFC r343082: Implement shmat(2) flag SHM_REMAP.
  • MFC r343484: Remove now redundand ifunc relocation code which should have been removed as part of r341441.
  • MFC r343607: Reserve a bit in the FreeBSD feature control note for marking the image as not compatible with ASLR.
  • MFC r343780: amd64: clear callee-preserved registers on syscall exit.

kp (6):

  • MFC r342591,342599:
  • MFC r342989
  • MFC r343130
  • MFC r343041
  • MFC r343295:
  • MFC r343418:

marius (2):

  • MFC: r333745, r333764, r337533, r339375, r341041
  • MFC: r342634 (partial)

markj (6):

  • MFC r342887: Stop setting if_linkmib in vlan(4) ifnets.
  • MFC r342864: Specify the correct option level when emulating SO_PEERCRED.
  • MFC r343265: hwpmc: Plug memory disclosures from PMC_OP_{GETPMCINFO,GETCPUINFO}.
  • MFC r343286: nfs: Zero the buffers exported by NFSSVC_DUMPCLIENTS and DUMPLOCKS.
  • MFC r343348: ocs_fc: Ensure that we zero-initialize memory before copying it out.
  • MFC r343784: Avoid leaking fp references when truncating SCM_RIGHTS control messages.

mav (7):

  • MFC r340425 (by cem): amdsmn(4)/amdtemp(4): Attach to Ryzen 2 hostbridges
  • MFC r340426 (by cem): amdtemp(4): Fix temperature reporting on AMD 2990WX
  • MFC r342977 (by cem): amdtemp(4): Add support for Family 15h, Model >=60h
  • MFC r342400: Increase MTX_POOL_SLEEP_SIZE from 128 to 1024.
  • MFC r342546: Add descriptions to NVMe interrupts.
  • MFC r342558: Switch from mutexes to atomics in GEOM_DEV I/O path.
  • MFC r342557, r342559: Reimplement nvd(4) detach handling.

mckusick (1):

  • MFC of 343449 and 343483

mw (3):

  • MFC: First part of Amazon ENA driver fixes and improvements
  • MFC: Second part of Amazon ENA driver fixes and improvements
  • MFC: r336114:

np (1):

  • MFC r342603: cxgbe(4): Attach to two T540 variants.

nyan (1):

  • MFC: r342964

pfg (2):

  • MFC r343023: msun: reduce diff between src/e_j0.c and src/e_j0f.c
  • MFC r343459: (parcial) ext2fs: Add some extra consistency checks for the superblock.

rgrimes (1):

  • MFC: 325765 (imp) Add notes about overlapping copies.

sef (1):

  • MFC r342928: Change ZFS quotas to return EINVAL when not present (matches man page).

shurd (1):

  • MFC r342855:

tuexen (4):

  • MFC r338137:
  • MFC r338138:
  • MFC r342857:
  • MFC r343089:

vmaffione (4):

  • MFC r343413
  • ixl: remove unnecessary limitations related to netmap
  • MFC r343552
  • netmap: small cleanup on em, lem, igb, ixgbe

wulf (2):

  • MFC r340912,r340913:
  • MFC r340926:

Stable release: HardenedBSD-stable 12-STABLE v1200058.2

HardenedBSD-12-STABLE-v1200058.2 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • MFC r343043: scp: disallow empty or current directory (40c2d4eb5cda74b65cc1d2d1187e11d87e3231d5) [CVE-2018-20685 FreeBSD-SA-candidate]
  • MFC r342887: Stop setting if_linkmib in vlan(4) ifnets. (9752824a67b8e026c748df9f55d7a4dc34cc3e5b) [FreeBSD-SA-candidate]
  • MFC r342849: libbe(3): Don't allow bootfs to be destroyed (43c025931749622500ddd40f733833a2326eb8c3)
  • MFC r342792, r342805: Provide rc_service variable for rc service scripts (43d929cc947061353022f4fd65f384bf5e5b623d)
  • MFC r342966: net80211: fix possible panic for some drivers after r342463 (afe64a5242c51756aa8e7278a93e78bef8ffbccf)
  • MFC r342883: net80211: fix panic when device is removed during initialization (86c848990612b065fd125e3d067494a9ca62d302)
  • MFC r342787: Add a bounds check to the tws(4) passthrough ioctl handler. (09c4a5a5c19860d0f062452a120bf3db56bec588) [FreeBSD-SA-candidate]
  • MFC r342575, r342580: ar: detect and error out on 32-bit symbol table overflow (932f2a3ad15b84e2f4584e8b4cc4930acaa94b36)
  • MFC r342686: Avoid setting PG_U unconditionally in pmap_enter_quick_locked(). (6a790261240984576e7ab3ae4982feda89938f4a)
  • MFC of 342135 and 342290 Properly respond to error from VFS_ROOT() during mount. (3d8c9836cc1b5b82f970b571dabd1cc4c524d6b2)
  • MFC r342362-r342363: config(8) duplicate option handling (b43601807a39b452a3a234d5a9ef33ba0bf6370c)
  • MFC r341101-r341103, r341148, r341391, r341422-r341423, r341454, r341780-r341781, r341805, r342026 Make powerpc booke kernels boot from ubldr. (5f1960a5ad7dcf7320f04827f86d2543a9cec92a)
  • MFC 339899: Make battery emptying rate available as sysctl variable. (fcad6d3887e9e0df176d8d9a4d01ce8e4dd1c780)
  • MFC 339620: Add a "live" mode to ktrdump. (9eec96ef7c166142d06d0bed137f98ee55c3b9e6)
  • MFC 340460: Convert the number of MSI IRQs on x86 from a constant to a tunable. (38147cee96c0cdfbd10ce81c8eb8d11ce87d0c93)
  • MFC: r342286 Fix the NFSv4 server to obey vfs.nfsd.nfs_privport. (9e714b03dcf913fc1daeaab8f970f37bd6a91367)
  • MFC r341998: pf: Fix endless loop on NAT exhaustion with sticky-address (8df6e4a6eaf85ac40c35fe353f2150a99f5685be) [FreeBSD-SA-candidate]
  • MFC r342211: net80211: fix out-of-bounds read in ieee80211_amrr(9) (d8b9265f4a6ad7c6a1e2446b98e7f6e9a7ccd4b8)
  • MFC r341833: pf: Prevent integer overflow in PF when calculating the adaptive timeout. (4e14cefd62c1612b7eba62cd71097429fd6d29fc)
  • MFC r339746,339751,339794,340866,340939,342042: Sync libarchive with vendor. (7e7a6e66b6497594e376667d1b0f653787927a6e)
  • MFC r342183: Update sqlite3-3.23.1 --> sqlite3-3.26.0 (3260000) (5f41f06ad996ced8460e267ae51526eb89dc661d)
  • HBSD: log pkg changes to /var/log/pkg.log (9135625701b316445fd42809c2ccefada1b39c93)
  • MFC r342030: Plug memory leak for AES_*_NIST_GMAC algorithms. (1f3faa484174d1cb5e572cdd3b1910764cfd326c)
  • amd64 string primitive optimizations
  • asmc updates
  • cxgbe updates
  • ichwd updates
  • loader updates
  • mrsas updates
  • netmap updates
  • riscv updates
  • rtwn updates
  • sfxge updates
  • tzdata updates
  • zfs updates

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-12-STABLE-v1200058.2-amd64-bootonly.iso) = a962a3debf7fe72392e0d2f90bc2df3808f6c301f9ade0f5c6e197ce896723057431c8cd29df494c5ee071694a429c13354b2f34d0ae73cc1952a57f0da8bfec
SHA512 (HardenedBSD-12-STABLE-v1200058.2-amd64-disc1.iso) = a06cd6492e30f1cb121573da0a2e61cb8d0f14e131da26b86bd54fa5dccd62537c0927c950daf13127b39cc5ee476c48c5e6298d128803c6b86c314cf5db976d
SHA512 (HardenedBSD-12-STABLE-v1200058.2-amd64-memstick.img) = 21b4345d6389bb80f145bcfb47ffdfa4f44aef1e14752b4d1edfd867c5f4ecf9c54f6e7babfb422a30fb9a0e00237a1dd3abb2a333faaaee8b12abc5399f515c
SHA512 (HardenedBSD-12-STABLE-v1200058.2-amd64-mini-memstick.img) = 9e274ea3b563fca0b9ff190a876c450ef537248c6270bf14ffa257857da7326ecc1872b3d267f5566b6c13c73912a031e2a397f2f64af9177e519326a35b46d3

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlxCnLsACgkQgZsRom/9
GI2M3BAAjqSbp3xQqHw7gt5wz8lKJRWXmvr9sdSsOjQlqb+4agrXVWdIV1FPpzME
+Xb/DUeCVKLBC3wVHd1BV+r3zZs7dK085k5GQssAjC/VXfkGGa1fU+UYq0Jx35lu
zKovC0ce1WDo7IaF4fmU8fBysnuqOfg/DOxXAcJPHDCiHRXturIEEIhVsa17lSmI
hHZDxqazEqLeKk12isHtVu4EqS33FgzTvxcflnqnH0hgKDXb47pvqDN/F5faM9+C
NO8Fn5Vd5p3676fGuB6EFCN8NLVBjlIEW0bXpCUtnmpwmXGf9nk0AhkQcVkzWbkw
aWCJNbCzQc7LvCtGKbS/3c/lMdkROzhMuUc93VldgaBqCFbBT89fTGUFLq/Ui123
qtAVgv7gQa2S0PzMCHA9Gh7aetHJ1/HwHKQKze2tcHJDqSZJ2ARicxjvpH526WUH
ymcx5BnlCG+sNWt+uOVO2AYKf8nCUk2KD5o5azn0MirEaXOvmYDSVTtjZyn+kIx8
IZvfqUydjchyi7sYiV8mrMyOa52+YLU1AnFDeEByvef2fQGPvvkdn/zINvVsMD83
q4J4xC4TwO5J8bXJk2ZK2rppkLobWXLaYUPb7kzrl7fsWbN36EiTizjW0quE++Mu
Oc0psPw6rD4hfLa9dDXg15b8NWkTDVBqwOzjaH2W5AxKGtB7fVQ=
=ld5O
-----END PGP SIGNATURE-----

Stable release: HardenedBSD-stable 11-STABLE v1100056.12

HardenedBSD-11-STABLE-v1100056.12 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • MFC r305074-r305075, r327275, r327570: newfs_msdos updates (5c2dc4965571d306fec98cc07f59e3d9b0770f35)
  • MFC r342640: Ensure buffer is nul-terminated. (a5529f8274c6e262a96221ef07ceb11e0e0639bc)
  • MFC r342966: net80211: fix possible panic for some drivers after r342464 (d72ddcc7912e0b3078dcd31123a58ae3e5ab1014)
  • MFC r342883: net80211: fix panic when device is removed during initialization (7f8b81b93a714b7a8807d32e1bde933651f70f97)
  • MFC r342810: powerd(8): allow to force a method of battery state query (48d38e36ce7fd50398514fe106ae73ff57d84b0d)
  • MFC r342787: Add a bounds check to the tws(4) passthrough ioctl handler. (5a404946700fc485ddc81aa41a97bbe6333ac014)
  • MFC r342686: Avoid setting PG_U unconditionally in pmap_enter_quick_locked(). (6b926a8ea46f4dfac7d8d6d9a311de9ecd9bdcf7)
  • MFC r342362-r342363: config(8) duplicate option handling (0368474a6a610d15c7de92010fde161d9e465180)
  • MFC 339899: Make battery emptying rate available as sysctl variable. (6bb14494cc5721af5f373f1f6f82225e41c7d935)
  • MFC: r342286 Fix the NFSv4 server to obey vfs.nfsd.nfs_privport (4b9098849df19a547ce70e31e6bd5975a27abc03)
  • MFC r341998: pf: Fix endless loop on NAT exhaustion with sticky-address (955c6a36425f6f83bc210ca3178b73219555a550)
  • MFC r342211: net80211: fix out-of-bounds read in ieee80211_amrr(9) (a94de320dbe8ed631d21535fd5a797f757d3bb08)
  • MFC r339746,339751,339794,340866,340939,342042: Sync libarchive with vendor. (250ab274d51bec04e50452ba7196798e4336897f)
  • MFC r333352 & r342183: Update sqlite3-3.23.1 --> sqlite3-3.26.0 (3260000)
  • ZFS updates
  • sfxge updates
  • mrsas updates
  • netmap updates

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v1100056.12-amd64-bootonly.iso) = 56ecd76d13f1dc47414681137fd2dfac2172c0fc2705d25eb4120adac5a60159f97e442d0bc0f45a52feef5c76f208f5d38dab569f48ecc57cf3e74d7b2ae543
SHA512 (HardenedBSD-11-STABLE-v1100056.12-amd64-disc1.iso) = 0b9440b1f6df1dd70601555d00135bfe6bb9fe3ac1ec2e079675dd6be3683710a994f1715c8e113a8aecf896e0ff218f6bae35bc596247854096a526bd0219e7
SHA512 (HardenedBSD-11-STABLE-v1100056.12-amd64-memstick.img) = eea300215730ea9cac2ebdeb6221116bae4b93ea0e5be6e86ceeadc3eb89918eb0d6b41d250bc4d3ee9f8206ee41f9228ca79e9a3bd0ce1712b122004fc54869
SHA512 (HardenedBSD-11-STABLE-v1100056.12-amd64-mini-memstick.img) = e913c02d3c9bcdb1274ceaba7e43a1abf422ebefa6a4d9915c02df1c36a1238748ff296266878e8ce3a1397ee69ed2a383a0123e54f1cacf5033714b9e68c883

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlw+ocEACgkQgZsRom/9
GI27NhAAjGZtV4QOnHYmFNFDvUb98GM+XmAKhHusH3Kwg6r8Rkpu0cxnafOb0bIv
uQ7EZLi43U5YLqqaytSjeVRaQ9RlEVIfkIRF4ZmMkwGP2yZKOyill0zRLX4ywwVJ
KLZNtqJmYllvdBcGe8Pe99+gt8LR+9tc/32bV7AEQqWBlrYNYimwk1jw2VHRqhZ7
JYlOTHvYekTlkXrwYxybXFxkYK5SKYUhh6yZbJ1QTtEnZo+EmzSl2QtVoPKLywC1
MHXYayrupu4x62OvMb6bo0AIY/8XQWXYloXUEHq9cr2xV86qdIttW/A9Krwtdq6z
3Th+TvXjisZd62aAJjbzr3rfm/7uN4KFDdLwsmogj/DYWJnteFZQWb7/Y4wsWSI0
5XiHCI1tk3zEihN06PJZ3yN3z+KFwPW7hK+DgWW0KtFBcrbNkWfWom5HafcpCBgl
E9nYlWwos2ZJZ1/BYqoFdQIYpoKwMFUdPWCqeq+r3CGGGxvlIOXYkD2cTRXx7l5T
YHmrBYYDXevdfdaaFdp13hJy/yaqPM7e6vIe7ZGCNcYKcpGWiZOXKiJDfuL6Pnh6
88AYJwVXcJCQa5ek5VOYgZ3pX2eDg1KDeUjqJ+cYXHZ4fngEyhM4wnbVu4+6hmhA
Al5yDTYZ0JcrzmcF3Mj5WIAcyt0a6WFH506GsBgZz1d9+6knX5I=
=RgXk
-----END PGP SIGNATURE-----

Stable release: HardenedBSD-stable 12-STABLE v1200058.1

HardenedBSD-12-STABLE-v1200058.1 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • MFC r342227: bootpd: validate hardware type (cc913fb4818ab0f1ffdb93ddc0145798964b98ba) [FreeBSD-SA-18:15.bootpd]
  • MFC r339909: Allow changing lagg(4) MTU. (8b8bd1f610ade0928bf728a849b344f74b33dcb3)
  • MFC: r340090, r342056 Merge ACPICA 20181031 and 20181213. (2f4ca9c8f0a8780b44ccba39043972baa0c01a92)
  • MFC r342125: Fix bugs in plugable CC algorithm and siftr sysctls. (92b6550b7f9b8b4b1bb75882de619dadd72851a7) [CVE-candidate]
  • MFC r342127 Revert r331567 CC Cubic: fix underflow for cubic_cwnd() (38ba9644182faa835efb437e0bec504161ba3c69)

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-12-STABLE-v1200058.1-amd64-bootonly.iso) = 8f99acab3e53955cf6863b401fda4f45c2424150d6d8390ac891b7529050c4a46389b9ebe2eb440f0fd4f494d105d3e0998cdb509b571e949666291a868495e9
SHA512 (HardenedBSD-12-STABLE-v1200058.1-amd64-disc1.iso) = 0260437d461b57fcaabb3a695684ee6fbba219b3506695a52630a676baa35173e00e59e524b6156f825831b392a4e60bcd4526d8d1813dd91d9e74fa31d89437
SHA512 (HardenedBSD-12-STABLE-v1200058.1-amd64-memstick.img) = c0d3b3d8664d1104187f4f907da7b03aaff6b0cb484774565d0ff1c15515d539ac7c86574c139f715acefb88125de18123e7a4ef1ef951ef30fe1eff565517de
SHA512 (HardenedBSD-12-STABLE-v1200058.1-amd64-mini-memstick.img) = 48972f624b03fb13f92cfcd6f83d7d9e938cb284d9159a0f2e63afbd97c75057bc45a2da1d98884a16a6f71e86eba84b817b40796d7b753b1fb920328691fe41

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlwa9LwACgkQgZsRom/9
GI2SuRAAjzS+OSy5WHPhcTJXHA/KIZzywI3++KY1bhvnR7hVDKHkaOeT/q1Q3z3f
i2w7jSnf76mrmWAQx3h/tshjQ+l51kUdj8Fn7FHsQ2ub7DwVkN05U1V5TJdw84ma
gbmDlnodV257rQUVoUb+OcDXClhrPzvJshKZQgOcq512P3mWvsRfCyTUcbiCyhDk
4IDG68/7Xud3/ZAvP0NQsZ//XbCyHIukl8LoY5ZeOcPW/vePK159PyeKbS5iYRmM
+q58JT71Nc2mz96wgb1QCj3f1w7F4Jpc7VdQ0qAb4Km48g4QrDtBPksx/4bIwU7E
tBbBsvESoRP2b7DTO8FVWvNzclFIg4iL92NcxMv53zPTzXOm3zQ6t3SZk6wM70Xz
NZ551Aqnkip3Y/VxxcUIUmgFIqmM/XaD5zPBgOeaKyNmj96VraPhbCArblHKHZlK
B/KVgFb+5QMHGD/Nk2T05Zn2VG7Qldp37AR4+GeYQGN5yeu9a9NgREPXuJmawB/N
58yQiUZKTVzSsyy9kEFAIgBRaEs8sM+GxmQyqZH4AgikBX22X8oYLsL4L+SE8bYM
7dQHSnjx727tguGvQfst/rIR4ARSmCeoziOHTmrCZbWSGQ4foRW96AshJ3fWAGAT
9OFr6vPLlMzpY4tuNC2+kpNd5jeG9rA3llAkoo3AT6ed0dfQppg=
=nv3j
-----END PGP SIGNATURE-----

Stable release: HardenedBSD-stable 11-STABLE v1100056.11

HardenedBSD-11-STABLE-v1100056.11 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • MFC r342030: Plug memory leak for AES_*_NIST_GMAC algorithms. (1ab95dc20c0f79f2d5b347e572904ef355aec886)
  • MFC r342227: bootpd: validate hardware type (dc1918c7f951e0c048665e5428f341e1cccad25a) [FreeBSD-SA-18:15.bootpd]
  • MFC r339909: Allow changing lagg(4) MTU (d055422cc148b2fffbe4ba2a2fcf0fc887bcddc5)
  • Partial MFC of r342125: Fix bugs in plugable CC algorithm and siftr sysctls. (f445d2ac303ef82d01bdb265c7b73f4eed5d8c99) [CVE-candidate]
  • MFC r341990: Fix a possible mbuf double free in bwn_dma_tx_start(). (84fc627d53884d2d1a08864a55536699ee3a2f52) [CVE-candidate]
  • MFC r341441: Some fixes for LD_BIND_NOW + ifuncs. (65520f2661bfb6e75d862ed693ab66f633a5bc9e)
  • MFC r340046, r340050 Add support ps/2 scancodes for NumLock, ScrollLock and numerical keypad keys (c321d531cfeb7c0408fb4160df20b9c1a2b91d40)
  • MFC r341375: Allow to create swap zone larger than v_page_count / 2. (61710bbfdf016232e290b03ef4e247bc1cb0b8b8)
  • MFC r341008: Fix possible panic during ifnet detach in rtsock. (7a2718d69b304f4e6b9db7b38932cdddcdf12a6f)
  • netmap updates
  • mlx5* security and feature updates
  • infiniband security and feature updates
  • linuxkpi updates

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v1100056.11-amd64-bootonly.iso) = ae8bf3897c9a3c76da066cde1781abda0a9ea3b413702d96ba60004d8f264edf1151e84b6cd42e4098d933b344cb54f3fc5bde48b55c1839582d965223bdf41d
SHA512 (HardenedBSD-11-STABLE-v1100056.11-amd64-disc1.iso) = 0b5e100a039300927127ec53e4c28947718435e37056ac23128394e71f67d9c00bd5d4a65110a25d9feadecc074ac85b4b303569ad3c6bca9352e96505fee35d
SHA512 (HardenedBSD-11-STABLE-v1100056.11-amd64-memstick.img) = a33a946d9671104baa39054321bb4a8f81ed2c3a526c7415253ea35c8cd4aec982ced35c9bd482b1761e87bbaf01eaa819d31d05d5b64abf78f303020ccceed8
SHA512 (HardenedBSD-11-STABLE-v1100056.11-amd64-mini-memstick.img) = 5c9151bad95f9bbc14dd3107332c388275696b01238dfac4a21b724f3f0652aac0ee85fae334b1f9c3e16cf2bb53a0e067220fdd980e829005d53c83d3c9b624

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlwcA48ACgkQgZsRom/9
GI3OtA/+Jt9GA3OSNiX2ZhmKnDEwQLjpqK4R9Gv9O5PmelPoTh6HExywnVvWQSYS
3M98Oz393HaoZnw0v9uq6ycKJ1+dwrveSJuOV4Nd+TnMxixEGMjIq4rNsvHxbVNl
tQuJY5MFAgl9s8IaGm7uaDwyxdVDJyA31XocQ38vvaca97s+BxEgGJusEzMvVakV
Hd6xBW0G6CqNzlVoKJhj0rGrLm8vGsMsWBcvNLjh8WUJiy02y9KhuJ6iHYI3Y5Pi
D9Ri6vX+rss0L6pF43K78ihoEsYa55LyTKwCd3kUox0g1zwJSM06PZhNJf36h5uH
oyJNkfqqk7aUsy7bIyEZ5z5UPZtSD9vmpEL6BEFSMd/6f6epfYWE5ghjcMqJ3Vlw
iV8O3oUh5JY7nZnTD25sRZjIBsjrCR5iyHB9niL0T0ZwQmK7aR6Sy61gyidrRCrz
hs0E2Wr07hJlz9UwM+FCPQ7v2/iZGsSLTkcGkX5d1q/480DsbMV3Jo4pABw75ozT
VLFxSdBkiNiAXKJxjeRDXI5scsn2VoUSBRgfycUNQy1iz202tSaiZBwifCgtRW/k
LERX7o5YJC0Qf5J+Y8BHP5gxra8U5PhpjiziNrUdMNG6Mxkj2qlM6UqQzQfGXBKB
+JxBxLyz4Vf8w/RnnhlZ5PAW+mXTCyJvRwK5K0G7Th2dKgM0jFQ=
=h1hi
-----END PGP SIGNATURE-----

Stable release: HardenedBSD-stable 12-STABLE v1200058

Introducing HardenedBSD 12-STABLE

The first public release of hardened/12-stable/master branch, which contains lots of security improvements over 11-STABLE.

Among those improvements are:

  • Non-Cross-DSO Control-Flow Integrity (CFI) for applications on amd64 and arm64. At this time, CFI is not applied to the kernel. More info on CFI is below.
  • Jailed bhyve.
  • Per-jail toggles for unprivileged process debugging (the security.bsd.unprivileged_process_debug sysctl node).
  • Spectre v2 mitigation with retpoline applied to the entirety of base and ports.
  • Symmetric Multi-Threading (SMT) disabled by default (re-enable by setting machdep.hyperthreading_allowed to 1 in loader.conf(5)).
  • Migration of more compiler toolchain components to llvm's implementations (llvm-ar, llvm-nm, and llvm-objdump).
  • Compilation of applications with Link-Time Optimization (LTO).

Non-Cross-DSO CFI

Non-Cross-DSO CFI is an exploit mitigation technique that helps prevent attackers from modifying the behavior of a program and jumping to undefined or arbitrary memory locations. Microsoft has implemented a variant of CFI, which they term Control Flow Guard, or CFG. The PaX team has spent the last few years perfecting their Reuse Attack Protector, RAP. CFI, CFG, and RAP all attempt to accomplish the same goal, with RAP being the most complete and effective implementation. Clang's CFI is stronger than Microsoft's CFG and PaX Team's RAP is stronger than both CFI and CFG. RAP would be a great addition to HardenedBSD; however, it requires a GPLv3 toolchain and is patented.

Clang's CFI requires a linker that supports Link-Time Optimization (LTO). HardenedBSD 12-STABLE ships with lld as the default linker. All CFI schemes have been enabled for nearly all applications in base. Please note that any application that calls function pointers resolved via dlopen + dlsym will require the cfi-icall scheme to be disabled.

Installer images

http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/ISO-IMAGES/HardenedBSD-12-STABLE-v1200058/

CHECKSUM.SHA512

SHA512 (FreeBSD-12.0-STABLE-amd64-bootonly.iso) = ead39af6bc301c96c5a222884b79ec6f3b4d4ea3dedbec9f12526c2ac59360ed4fe681e49eb2982312c9d7d0d0b567751e338318a4f717cb7bed0aaa0ed3a211
SHA512 (FreeBSD-12.0-STABLE-amd64-disc1.iso) = 9b0d77db60c557e6011cc2388b70576834e4305bdb6e05d7f1e9fce95bc6cc119874120c88189753ca2ce117ab167b706a2aa35cf0563f6152407629996e10fc
SHA512 (FreeBSD-12.0-STABLE-amd64-memstick.img) = 97a70f614785df0de323c634b1e6f2b8a5f2d8b53e4584192f95f8f15fc346d31e52183fa19d1513e2e69dd2b002b42004f17e7fe85d8a00fab05a4d49bf999d
SHA512 (FreeBSD-12.0-STABLE-amd64-mini-memstick.img) = 11aff5393fbdbce0840332b70794265b141c083ecc7b2f49a3cbca0618aca55bebbeb7472a984d6d853b4b40751e239daca58b75e40a6334ae5ba128cda4552e

CHECKSUM.SHA512.asc

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlwXGq0ACgkQgZsRom/9
GI2M1w//btTs6Ek9HEcyRgv5kxpXwlf//E7YZNwpgF88CSdRhvfTDmyySjGmotaQ
ZSuL1x+nYVDqPc7vTeSU0wFdYjBWOLJpqecLmHSY+0fbZCRgRFd2pgQgxS6fhybb
M41V57GTQn5ogoeKQsCko2J7L8OzKhJh9c4FWD5L4H7YZTvv5aBWEIVqZvCEGEiY
XJZt2wpMICXwALyeVXSBN2S+DoMj2cD2W40pdbg3DdfVi6cAPZ/YQvPqG7h15+DP
ajFYsdU9UeNSHupp/qB3WkcQDgcnohx8ZbIjmTthHpocQXqKvwTvMHn3pByzoBoI
QYIYs6DEF1XynMDudzb2OtkvoskShpTE0h462VTn6Hm2BDcRlHZU+yNZSP4N8ut6
XNztkYe0b2JyKShUpG1pwkPIBgvM6eNDl5D+XKz2Cru2DEgpC40VVSGz5W7L9eYQ
O5xPKruIUWF6aS5g3/ooBpOAz25hqYHBsd0hPcqczgsfRhcjOSHUCSeiFJwAq7Av
gVN7rrzvHQPY/D1s7k20K+vjku5gOTyICuY5rdmZIOuMmAKbOijgY+Lp595XLneE
wEdvb1vXHbm6P1XhJNP+WPnENu18KHt4xWQ8lnCS0SUlL0qiN2gLvgRDhv22muzh
VSa82LishLniWf9TdMyN7Enxj2jofsMnDXn2vTmCwP9P+U09ipw=
=KDI2
-----END PGP SIGNATURE-----

Stable release: HardenedBSD-stable 11-STABLE v1100056.10

HardenedBSD-11-STABLE-v1100056.10 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • HBSD MFC r341470: ggated: do not expose stack data in sendfail() 370912d064f22772cd539ea28587ca7a1bca6c9c [FreeBSD-SA-candidate]
  • MFC r341442, r341443: Plug memory disclosures via ptrace(2). (600baf4f2d9e7039632b5bf5503097edb31c3da3) [FreeBSD-SA-candidate]
  • MFC r341484 Always treat firmware request and response sizes as unsigned. (5b0911ed9405a15d0fddd237377ecaf0684142a0) [FreeBSD-SA-18:14.bhyve CVE-2018-17160]
  • MFC r337812,r337814,r337820,r341068: Fix several memory leaks (r337812 & r337814). (4a6ee6982ea1014b8d06511c23c76b849fa694f1) [FreeBSD-SA-candidate]
  • MFC r340968: Plug routing sysctl leaks. (fe7eaf6c881cc3948b430c5241b34e2c1189dc03)
  • MFC r340995 Prevent kernel stack disclosure in signal delivery (ee1166b9e2f474622f098aad4dd78869880379c8) [FreeBSD-SA-candidate]
  • MFC r340994 Prevent kernel stack disclosure in getcontext/swapcontext (88ba4e0711d85c593ac41f9c9a054cf4e66d050a) [FreeBSD-EN-18:12.mem CVE-2018-17155]
  • netmap updates

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v1100056.10-amd64-bootonly.iso) = 6ca4a5de222683ff4716090d55ffd1b19f50e98b7bef0012e94acf6ef73d61e2aaabe87026e2e58f1df4f797e5dd31130a4bac4d5cee82299bb75d215c5d1462
SHA512 (HardenedBSD-11-STABLE-v1100056.10-amd64-disc1.iso) = 40e2a44bd010fb2b1e14b4b8b90ee86ac86cf0bb9f629c9a121cb24ed2e25fc6b5a3e821b770c483e922fd2a5de535b4ecfde9b759888775f51478e2fb183713
SHA512 (HardenedBSD-11-STABLE-v1100056.10-amd64-memstick.img) = 2e57b96f5d9f75b277792052690947a849ca85a0e0860474b37cce06a623a5f566f60738b762ee6966081847be129a821ca199f17b3f286dafdbdbe6e1c70e0e
SHA512 (HardenedBSD-11-STABLE-v1100056.10-amd64-mini-memstick.img) = a216932ecf6c218b7f8984ca55524c18ab85e5bcce163d11effdf889883e28ba6feb4546ff3e28c9e2a29440f147363ae4444e75f56bd18b6a02176db5f8810c

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlwHBLoACgkQgZsRom/9
GI3zlg//dLtnJmc52UuttbSD1NV2h2hv4mNW/UteFjxGtJgdOCkjRGpx3sI4Vm1j
ks5NPMzi4Wy8r9l/bWv+k/bCvkxvjvt8gQKIBbDt8IauB1Bk+uxeWr3IcLn9eiPV
eC0diLLpUzTkbhN9NbnXbbugrrq4AeWFbOl06HIAw9HJolIYtLInOlH9XZToUItR
kbVD+AXjVmfntDWXPtkgCZdEEPe6zYAUgA39iyrcb5X3y+AVc9hDIoOGfPVoMIRR
rhEu1jwJPuT8C6r2hcareVpmfOESJTljh+yNw9iq/brkNXPW2UcPFwwkt7ajubaP
KW22bl9jGTTqA3JhpPHRwqFjyZzItD9TR4qPr/Fu2WTzYACyjNvWyCK/KJOvS6MX
ewepZ06yUhsLEjEiGpllJ4XipUn8c2hbTXLoKE/JOBvwhxIognoQ8yiEE645Vrb8
VCPLab5CK4y+CSZLEA2DWpiuWO7D/Z8pRIbV0tWKh1HrN5QPOjXeDDi+59t/016v
vb/i8YR0GhHgg3mPYCCUUgMey1e7vIjnmcj0OkZRyyx7bi2fP+37C/XBV9L7bFC7
kLO1pAX7hwWOp/H0dbrJCuLyWFLHjkgNODrxmmYk1OeWQoUT9KX1SFfYCKsNlpAn
Pq+17qjcl/Amswrpmw7a/WfXXLiNA46OyOU/aG9r1Z+8/Emd4YA=
=fwqX
-----END PGP SIGNATURE-----

Stable release: HardenedBSD-stable 11-STABLE v1100056.9

HardenedBSD-11-STABLE-v1100056.9 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • MFC r340899: Plug some kernel memory disclosures via kevent(2). (57fd4999023fbedc45061430d5dbcdb98547b407) [FreeBSD-EN-18:12.mem CVE-2018-17155]
  • MFC r340856: Ensure that directory entry padding bytes are zeroed. (3dc6e9a2e5b3a446ecb0c2c198bca46619f8590d) [FreeBSD-EN-18:12.mem CVE-2018-17155]
  • MFC r339818: rcorder(8): Add support for /etc/rc.resume (9837413dd9835df60a41e4cf3e30338bee65f358)
  • MFC r339808: Prevent ip_input() from panicing due to unprotected access to INADDR_HASH. [CVE candidate]
  • MFC r340783: Plug some networking sysctl leaks. (e1128261727c1eedda33c25158753d4f09545d5b) [FreeBSD-EN-18:12.mem CVE-2018-17155]
  • MFC r340772: Clear unused bytes in ia32_osendsig(). (782079682d680e076598653d244323b8a5b90a8a) [FreeBSD-EN-18:12.mem CVE-2018-17155]
  • MFC r340771: proto: change device permissions to 0600 (91dc34763d7783d5cc2e3d268e4c8ed85ff3b166) [CVE candidate]
  • MFC r340663 (rmacklem): Improve sanity checking for the dircount hint argument to NFSv3's ReaddirPlus and NFSv4's Readdir operations. (3bb4648083f3148398021abd35df925aa5c003f2) [FreeBSD-SA-18:13.nfs CVE-2018-17157 CVE-2018-17158 CVE-2018-17159]
  • MFC r340699: Clear pad bytes in the struct exported by kern.ntp_pll.gettime. 6c88f7d90bde0d335bc0687a41bc141ffb55e2bf [FreeBSD-EN-18:12.mem CVE-2018-17155]
  • MFC r340674: Fix another user address dereference in linux_sendmsg syscall (1162e5190b51c01b6386baec10dbcd0ddcaf4b38)
  • MFC r340631: Do proper copyin of control message data in the Linux sendmsg syscall. (a7710016b5015643786ff0ceb070cae982e80ddb)
  • Merge OpenSSL 1.0.2q (9424b8c43e2d3d7b45201e34799fd5c5193f7f68) [CVE-2018-5407 CVE-2018-0734]
  • MFC r340205: Avoid specifying VM_PROT_EXECUTE in mappings from pipe_map and exec_map. (a1e236f6c4f29f04befe42250d20312424c12deb)
  • MFC r339465: rc.initdiskless: add support for auxiliary NVRAM. (889791af8eb9cb4b19cd96d2891836e4205473f0)
  • MFC 339312,339364: Restore more descriptors during VM exits. (5093c36b3316b62e306dc18ff9e2bf7eac33dbe1) [CVE candidate]
  • MFC 338511: bhyve: Use MAP_GUARD when mapping guest memory ranges. (6dc9464d89d89a37d4d114ba519d004ee25649b5)
  • MFC r340260 (emaste): Avoid buffer underwrite in icmp_error (6033b7ab1ac6064008c8d99b64d95ebb815e1e74) [CVE-2018-17156]
  • HBSD MFC r340205: Avoid specifying VM_PROT_EXECUTE in mappings from pipe_map and exec_map. (a408354173f2c5724a9a603831936ab42c11fe82)

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v1100056.9-amd64-bootonly.iso) = 6ba911b277a345fe7985e68695f2c83d5ff16d13e947084638652d1f5613f76e126d7976e08eab78dff36062e1e3e6958a2e625958cc3086c902a3a753db5945
SHA512 (HardenedBSD-11-STABLE-v1100056.9-amd64-disc1.iso) = 5a395012cbb2d75e478c9d110d0495488721f3814c13053d43c0a0fc833ea84229b46e09632dbdf86248724ef7f9e1cf76326dd95438405dd96cd3237d3614c5
SHA512 (HardenedBSD-11-STABLE-v1100056.9-amd64-memstick.img) = 803dd1d2a0f8560f075406cf3a98a2fb354b75aacb5c2580332111e8a99fbd3a2acc32efa0ae3361d9e5b00d087c23bd916b763002915d739e91ca6503f6f2bd
SHA512 (HardenedBSD-11-STABLE-v1100056.9-amd64-mini-memstick.img) = 9034ebe006ce99ba9dac8550285d9ca3d83b2df8c1146b37209a4822cc3937b7631ecd910805e34581dbec19969b2691aaa53db64bdbd279409a51017a6a70bd

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlv+BkQACgkQgZsRom/9
GI2sug/+NYCxrjbWNpq5BTAmzJ+Ld5BEGDZ0Vh4crVqZAVlPaj+UIiHeAh7wHD3M
hDtNvRPk905YLt7RDdb0ieSf9oeIlqHF/Y1oY0EbQBsxcG3soiltd1QdivjraBDA
rew6WRy1RdxStChJa/ZEbmS9XFMhvfMY89MSta0FTAVYxJq8cltSbnJqHh2H34an
0QF3iIi8G6g5C7cUr6tnZRRk4e+gDhwdzrkUwQc3eA0H5y9galYI/K46GWhKIz5p
qBopHts3zHTnYJjT9k+F1DTp60SPCtDK3WKyiCsCDqoOUODO+9gTcLjQQDgcuG6A
HRmcM/+DCtmmqZPFFTRCQcglfVB1Vu1SuCEhJm/8/43UN2HgtUr7IkGzE8dTmNCs
glDGWJUPEgUPirgwlZhl0XdOgd6XjT+ybempDQaNGFnd1fPuwTcljK5imLZ6txEC
Tj/OGVyNvQla7cPRGqYHL7bMAjd4huRYezj1LLu3uvjnLHPZliv9z/Ijo6U9ssvq
RKrd5cu4wtRUvyPerP0Y7HIkv5To2Zm66ofzN3P04DnMJ+niCOebu+gE7mhiYpbo
6SgS84eWuiKZ+55NVDGrjUta0fKKvqaIjMxSxQnd3iWegEEeLDGgbZLP+IubsyPJ
P2JQahY82EaRCMWPS/BRfxvs28JZYec6Lz1JCrRKmzNQCDrwNJo=
=H8Ge
-----END PGP SIGNATURE-----

Stable release: HardenedBSD-stable 11-STABLE v1100056.8

HardenedBSD-11-STABLE-v1100056.8 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • HBSD MFC r340077: m_pulldown() may reallocate n. Update the oip pointer after the m_pulldown() call. (fec14b22fcff136c352237afb47036d1614ee692) [FreeBSD-SA-Candidate, CVE-2018-4407]
  • MFC 338360,338415,338624,338630,338631,338725: Dynamic x86 IRQ layout. (160aee5ecc8a289fb54eb7b431cdab3017e9d9c3)
  • MFC r339681: Allow the bhyve VNC server to listen on IPv6 for incoming connections. (5e060e63804e1ecc636b29714d32113e483d6c60)
  • MFC 338408: Don't directly dereference a user pointer in the VPD ioctl. (b035f90113747066819a750566d008f6fae812be)
  • hwpmc: Enable hwpmc support for AMD Family 17H devices (1235e4abcc9d407b7f094039bca7531f4444ccc5)
  • MFC r339582: Drop sequencer mutex around uiomove() and make sure we don't move more bytes than is available, else a panic might happen. (4b875542b959aa18eb4a9a3594f6d548298fb59e) [FreeBSD-EN-Candidate, DoS]
  • MFC r339581: Fix off-by-one which can lead to panics. [FreeBSD-SA-Candidate]
  • elfcopy: avoid stripping relocations from static binaries (8e4b64478895d6b9ae0ea05d5962af093d757cfd)
  • MFC r339509: Fix loader.conf(5) "password" feature (9a6d83553b2b9b32be437e7d0a79aeda1162384a)
  • MFC r339547: vlan: Fix panic with lagg and vlan (1fda50699ae90ff2d1eb680f3e24c2f3d5324da6)
  • MFC r339331: bhyve: emulate CLFLUSH and CLFLUSHOPT. (9e85f7a5bf64f3f8ba9db7ef8a9413e94e208652)
  • LLD updates
  • ZFS updates
  • LinuxKPI updates
  • VNET fixes
  • libsysdecode fixes

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v1100056.8-amd64-bootonly.iso) = e9b4dc37c3914f14573222c3bec8303ba2516783a7daadbba42d9c42cfd1b68c6ed55a9f50c8ff394038ed5885880adaa230e3f89ea335be2e728d09331eac70
SHA512 (HardenedBSD-11-STABLE-v1100056.8-amd64-disc1.iso) = 3a9d91a4b9ffb0c69cde6639bd39896c31e3d140f024b0f66fe113799daa8cf19622b7b06564dbe455481327cb4bf44e8763903f57e01ea2bd460a040b4e3b24
SHA512 (HardenedBSD-11-STABLE-v1100056.8-amd64-memstick.img) = aa7101825ff05262dc1eac97ac8fd34614f82263dc2825a2087c1faf1094cc708f7703e39503ba4469d78db385bb642a6899ee30d6c832c80dc8b267ace88a9a
SHA512 (HardenedBSD-11-STABLE-v1100056.8-amd64-mini-memstick.img) = 633bb097e6bacfe0c1fb6d6de8e8175fb3be91af1632e240aa6a96c237bd7aabae9157cf0d3ec41d1aebbdb40da53a0c2b5fa497e0f564f2670ee6b60a227a42

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlvfps8ACgkQgZsRom/9
GI2AJQ//Z30QApEHelaPy7fcej9N5cJv1rFKxzfqVmt8pvEAA+tGRFoUNMz+7xG6
92u5sGHkfyGV761XqVK7gJXk6eMj2Sl5ITy4c1L3zjGRXutfB/F77eKzsQtA+1cA
Moxz9pwJrFvyL3HouT5CaOysXwlYmJVIqF/P8sHulHImshWnlBg8khHvPesCD7wi
0tb9xdyE3+xAmkqwJMgW1U92TaPOzfwTK5BLbXelw5eWT/qiB2OR9HcFmdfAh/MG
LlvFAeBZh6k298KYjYE0aR7qo35Cu3kD0PfUDmVaZNZpORbFBz1ZcLSMt8sZBHOx
HVPSWTnRbJpuh0SJphvSvnbY++nsT0PbhxVnPiSG/naXKTTYOw1hyPYrJaBXL8n2
gClDR7DRxhUi0F4MqMzqLg05kwwaSu3lwuBwjdS9YjcHV+IyVgA9YK11BbdOecpE
vEpPTjtQpjYFydwQFqUy8FbYhEnBpiJCBB9StM04w4gOOWS/RzMO+GQ+ysjoatlg
C0CxgQ/yuwmlvw8VpKKWYwS5UxTN+XbBX8GCz/8IpBgSajfbrKIGf8wMdptYKdjY
bSy9HgR4XQNBiXeHzXTCra8Z5kive7VlhQsLqfjah8pLcKsHTGzpS7LSlobxTqyh
n+At7jjhYiwgXKKrkcxY4IxqwvY5rtLpb9fcByoGlSpWDgHhoV8=
=lzsa
-----END PGP SIGNATURE-----

Stable release: HardenedBSD-stable 11-STABLE v1100056.7

HardenedBSD-11-STABLE-v1100056.7 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Highlights:

  • MFC r333569: cpucontrol: improve Intel microcode revision check (cf3b425994272a0d0b1602846bbe51028fd67442)
  • MFC r339019: clang: allow ifunc resolvers to accept arguments (d10325d074c2f9aeff283511c3acb06b3c1fcb5a)
  • MFC 338976: Don't clear DR6 for debug exceptions from userland. (4de0836180159ccb2485c64e4639544254abd941)
  • MFC r339025: Update x86/ifunc.h. (59e3462397fe61451f33846b1d0c56142b6a816d)
  • MFC r338947: Add "src-ip" or "dst-ip" keyword to the output, when we are printing the rest of rule options. (cfea277e33577e9ec8653cfa010f60a39dde358a)
  • MFC r338216: tftpd: Fix data corruption bug with netascii (6068c2761de987bc97d4c472acdc1076d91fc7e8)
  • MFC r336310: Let geli deal with lost devices without crashing. (35d45fa28dc67d17e535455e202de0584763f70e)
  • ZFS updates
  • cxgbe updates

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-11-STABLE-v1100056.7-amd64-bootonly.iso) = 76e6957dd5124525e62f59baac626eeb4c60b622d64b458aa838e4a374f6bc521647376bf41882a19b0ed5767c445dd4420883ab7b1e095a02e15b5874f18347
SHA512 (HardenedBSD-11-STABLE-v1100056.7-amd64-disc1.iso) = 1e2668998564e26911499875d2d163d9bb120746969dc96d6771f5c7c5213ba9dab434a16ba7c49d891fe8f496df6f08026701231abafa7cb1238a5b4f5fcbff
SHA512 (HardenedBSD-11-STABLE-v1100056.7-amd64-memstick.img) = 6e635997ab76acf56b8b0fc44591049b061a4a7e47ef19e1b6603be245430a0d45566d35e19ae04cb693714c9e871bf8d5dcdc71af0a4625fa537486dc439c91
SHA512 (HardenedBSD-11-STABLE-v1100056.7-amd64-mini-memstick.img) = ef95a77087998ea680d3c463c619ee749aa2b5794abed284cd5976b137c651aa3648c512c1af281f073f763df4d2e9a91f3cb79a5205234d321f950e0537b9f9

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlvH8GcACgkQgZsRom/9
GI1stw/+IM/kl6O9HIeCRZidthUtVA/Rk0ZGrvTilOpRwS+ahZks+D7d0ap8IC4d
WiQtuAOcG+RO0USYmv1Gmn0wh1bm0HhEFh6p/S4hnAgNTnRN1u4u/fBhqy7+jahc
IzBfvyRJ2+ym08trSBJthUtOmEcRvPwFOU7Vqj7cb9OpeAlQF7o5x6p3F5/W4VUf
G029GDJ8wyUQYSgQ+T6GgA96YUeEGNHcDZgUnEhyisyHCh60apYsrgRFKvmTqVff
91W6gRY/FhKgCmOJA1vIeXv5eiWGAlAAYTCWfbcsJ6SQAUzghxZTxUkhJEdy1XSg
XohwIoPU7TUKA7KDi9yP0SDdfCrDOeYlFwsYoOrDjxHLLDFGKNDT0BM3J9M8rh+N
gerwQQxZQ5ZYV8lohg5YSGfcvwgUoq3Th7EyqmtQbODAprvAlQYp8Ly1JuLkblHy
qR2DyoqVZfyEEmpTrt6AB+n5ck8QxZz9iYGSdwcdOKocqIcdZ96Znfo1oJDUMLe0
aYSimT/MTaeTCnjuo7jSz0Bvewi0zWfi5yqeOeE2X0tYlIvuuRh4/g6aovvaZuAJ
ZWOH4klex79aNvVRwqKToeq3OPjOT9D4KVTUnUu0oTRdxy7KAl0+YreGMdZQi7XA
wAheaZb3zZ8u/56EEMwWJwpn0ZvXSQ+BsOX0/USBQi/6+/Ir2Hk=
=S0Uc
-----END PGP SIGNATURE-----

Pages

Subscribe to HardenedBSD RSS