FreeBSD

FreeBSD 12 — xwayland-devel — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — xwayland-devel — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 June 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xorg server — Multiple vulnerabilities Related CVEs: CVE-2022-4283 CVE-2022-46340 CVE-2022-46341 CVE-2022-46342 CVE-2022-46343 CVE-2022-46344 CVE-2023-0494 CVE-2023-1393  +11 more Upstream summary: The X.Org project reports: CVE-2024-31080: Heap buffer overread/data leakage in ProcXIGetSelectedEvents […]

Read more
FreeBSD 12 — minio — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — minio — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 June 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: minio — Privilege Escalation via Session Policy Bypass in Service Accounts and STS Related CVEs: CVE-2021-41137 CVE-2021-43858 CVE-2022-24842 CVE-2024-24747 CVE-2024-36107 CVE-2025-62506 Upstream summary: mino reports: A privilege escalation vulnerability allows […]

Read more
FreeBSD 13 — kea-devel — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — kea-devel — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 June 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ISC KEA — Invalid characters cause assert Related CVEs: CVE-2025-11232 CVE-2025-40779 Upstream summary: Internet Systems Consortium, Inc. reports: To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" […]

Read more
FreeBSD 12 — erlang-runtime — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — erlang-runtime — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 June 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Erlang – Absolute Path in Zip Module Related CVEs: CVE-2025-32433 CVE-2025-4748 Upstream summary: https://github.com/erlang/otp/security/advisories/GHSA-9g37-pgj9-wrhc reports: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP […]

Read more
FreeBSD 13 — libsodium — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libsodium — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 June 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: security/libsodium — crypto_core_ed25519_is_valid_point mishandles checks for whether an elliptic curve point is valid Related CVEs: CVE-2025-69277 Upstream summary: Libsodium maintainer reports: The function crypto_core_ed25519_is_valid_point(), a low-level function used to check […]

Read more
FreeBSD 14 — wolfssl — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — wolfssl — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 June 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wolfssl — multiple issues Related CVEs: CVE-2015-6925 CVE-2015-7744 CVE-2020-12966 CVE-2021-46744 CVE-2022-34293 CVE-2025-11931 CVE-2025-11932 CVE-2025-11933  +5 more Upstream summary: wolfSSL blog reports: This release includes multiple fixes across TLS 1.2, TLS […]

Read more
FreeBSD 14 — filezilla — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — filezilla — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 June 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PuTTY and embedders (f.i., filezilla) — biased RNG with NIST P521/ecdsa-sha2-nistp521 signatures permits recovering private key Related CVEs: CVE-2024-31497 Upstream summary: Simon Tatham reports: ECDSA signatures using 521-bit keys (the […]

Read more
FreeBSD 14 — vscode — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — vscode — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 June 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vscode — security feature bypass vulnerability Related CVEs: CVE-2023-29338 CVE-2023-33144 CVE-2023-36742 CVE-2024-43601 CVE-2025-21264 CVE-2025-24039 CVE-2025-24042 Upstream summary: VSCode developers report: A security feature bypass vulnerability exists in VS Code 1.100.0 […]

Read more
FreeBSD 13 — minio — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — minio — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 June 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: minio — Privilege Escalation via Session Policy Bypass in Service Accounts and STS Related CVEs: CVE-2021-41137 CVE-2021-43858 CVE-2022-24842 CVE-2024-24747 CVE-2024-36107 CVE-2025-62506 Upstream summary: mino reports: A privilege escalation vulnerability allows […]

Read more
CHAT