Skip to content

4.0.8

Latest

Choose a tag to compare

@laffer1 laffer1 released this 28 Sep 18:18

20260925:
mport 2.8.2 Bug fix release: package creation and
schema upgrades now run in single transactions and roll back on
failure, a failed delete is rolled back and the registry write lock
is taken up front, shared-directory checks during delete use one
database query, and @(owner,group,mode) plist fields are parsed
positionally again.

memory leaks, NULL
dereferences, heap overflows and use-after-free fixes across libmport
and the mport CLI, TOCTOU fixes in file copy and mkdir, package
verification through open descriptors, MOVED/deprecation handling in
mport update, replacement of packages installed under an older OS
release, corrected exit codes for add, lock, unlock and download, and
a forced install now re-registers the package and rolls back on
failure.

20260922:
expat 2.8.5 (from 2.8.4). Fixes CVE-2026-93990: a high surrogate
not followed by a low surrogate was accepted during UTF-16 decoding,
letting malformed UTF-16 pass through the parser into the
application, with impact depending on how the application handled
it. Also fixes an out-of-memory related leak on a failed overflow
check, and XML declaration versions other than 1.[0-9]+ are now
rejected. Rebuild and install world, then restart all daemons that
use the library, or reboot.

Fixes CVE-2026-66046 and CVE-2026-76641
(quadratic runtime in attribute "isCdata" lookups, letting moderately
sized crafted XML cause a denial of service; default attribute
lookups now use a hash table instead of a linear scan) and
CVE-2026-76957 (custom encoding callbacks were not protected against
parser re-entry).  Note that a layer of compression around the XML
can significantly reduce the minimum attack payload size.

Upstream also fixes CVE-2026-76956, inverted getentropy() return
handling.  libbsdxml does not build random_getentropy.c and does not
define HAVE_GETENTROPY, so that issue does not affect MidnightBSD.

20260826:
OpenSSL: fix CVE-2026-63072 and reduce the exposure to CVE-2026-54874
in the 1.1.1 branch. cms_kek_cipher() sized its output buffer from
the cipher's reported output length, but AES-WRAP-PAD unwrap writes
and cleanses up to the input length on its integrity-failure paths,
giving an 8 byte out-of-bounds heap write; the buffer is now sized for
that worst case. The DTLS record layer also buffered up to 100
next-epoch records per connection, which a peer could use to force
disproportionate memory use; that queue is now capped at 16.

20260826:
posixshm: CVE-2026-58094 TOCTOU race in the FIOSSHMLPGCNF ioctl. The
handler tested whether a largepage shared memory object already had a
page size configured without holding the object's rangelock, so two
callers could race and leave the object claiming a larger page size
than the memory actually populated for it. The validation now runs
under the rangelock.

20260826:
tty: CVE-2026-58093 use-after-free via the TIOCSCTTY ioctl. The
handler drops the tty lock to take proctree_lock and did not
revalidate the terminal after relocking, so a terminal being torn
down concurrently could still be attached to the caller's session.
TIOCSPGRP had the same gap. Both now re-enter through
ttydev_enter() and fail with ENXIO if the device is gone. Rebuild
and install the kernel.

20260826:
ppp: CVE-2026-58095, CVE-2026-58096 and CVE-2026-58097, three memory
safety errors in the multilink endpoint discriminator code.
mp_Enddisc() sized its hex output buffer as if each byte took one
character rather than two, so a peer's endpoint option could overflow
a static buffer; LcpDecodeConfig() did not enforce the three byte
minimum option length from RFC 1717, so a short option caused an
out-of-bounds write; and "set enddisc psn" copied its argument into a
fixed size buffer with strcpy(). ppp(8) is installed setuid root.
Rebuild and install world, then restart any running ppp(8) instances.

20260826:
sound: CVE-2026-58091 use-after-free via the SNDCTL_DSP_SYNCSTART
ioctl. When dsp_oss_syncstart() could not acquire every channel lock
in a sync group it slept with the sync group list lock dropped, then
resumed walking the group's member list even though the group could
have been freed in the meantime. It now restarts the lookup after
sleeping. Systems with fewer than two sound devices are not affected.
Rebuild and install the kernel, or reload sound.ko.

20260826:
hwpmc: CVE-2026-58089 hwpmc(4) failed to detach performance counters
when a monitored process exec'ed a setuid or setgid binary. An
inverted return value in pmc_can_attach() made the exec-time
credential check allow exactly the cases it was meant to deny, so an
unprivileged user could keep monitoring a process across a privilege
transition. Rebuild and install the kernel, or reload hwpmc.ko.

20260817:
netipsec: validate PF_KEY socket address lengths before copying them into
fixed-size kernel structures. This prevents a kernel stack overflow and
potential local privilege escalation through a PF_KEY socket. Rebuild
and install the kernel.