A user found a bug in portfind for FreeBSD. After 10 years now, I have submitted an update, which is now also in the Ports Tree.
portfind is a small program with which you can easily search the ports tree in FreeBSD.
A user found a bug in portfind for FreeBSD. After 10 years now, I have submitted an update, which is now also in the Ports Tree.
portfind is a small program with which you can easily search the ports tree in FreeBSD.
Perhaps the most significant news of the week: FreeBSD’s base system is now entirely free of GPL-licensed software. The last remaining GPL component was dialog, which had already been replaced by the BSD-licensed bsddialog in the installer over four years ago. The dpv utility was the last consumer of dialog, but hadn’t been built in over two years. With the removal of dialog, dpv, libdpv, and libfigpar, the entire gnu/ subdirectory has been removed from the source tree — a directory that had persisted for decades.
For end users, nothing changes in practice since the affected components were either already replaced or no longer being built. Symbolically, however, this is a milestone: it closes one of the longest-running technical transitions in FreeBSD history. The Ports Collection still contains thousands of GPL-licensed programs — this change affects only the base system.
Alfonso Siciliano, the driving force behind the KDE desktop installation option in the FreeBSD installer, published an update. After automatic GPU detection for Intel and AMD hardware was integrated in May, the focus is now on NVIDIA support. Automatic detection of the appropriate NVIDIA driver based on supported chipsets works technically — but automatic installation is currently blocked by unresolved NVIDIA licensing terms. Instead, users with NVIDIA GPUs will receive a manual driver selection menu. The desktop installation mode is targeted for FreeBSD 15.2 (planned for December 2026).
At the June FreeBSD Developer Summit, Sourojeet Adhikari, a FreeBSD Foundation intern, presented his work porting AMD’s ROCm compute stack to FreeBSD. FreeBSD already uses the AMDGPU DRM kernel driver (ported from the Linux kernel), but until now there has been no ROCm support for GPU compute. The initial goal is to run a simple vector addition with ROCm on FreeBSD — the full ROCm/HIP/OpenCL stack is too ambitious for a single internship period. If successful, this could provide a better alternative for GPU compute on FreeBSD than the unofficial CUDA support via Linux emulation or Podman containers.
Joe Maloney has revived NextBSD as NextBSD-redux — a project combining FreeBSD with components from Apple’s open-source Darwin stack. The plan: keep the FreeBSD kernel but use Darwin services like launchd in the userland. Maloney is also using Claude Code (Anthropic’s AI assistant) for research, design, and code generation, while he personally reviews all changes and leads the project. A graphical desktop is not yet available; the long-term goal is to integrate the homegrown Gershwin desktop environment (based on GNUstep and Xfce). The project shares code with ravynOS and helloSystem but follows its own approach.
Richard Bejtlich (Tao Security) reports that FreeBSD set a new project record with 25 security advisories in June 2026 — the previous record was 18 from January 2001. The driving force is increasing use of AI-powered vulnerability discovery tools: at least 9 of the June vulnerabilities were found with AI assistance. The Alpha-Omega project funds FreeBSD Security Team members on retainer to find and fix vulnerabilities, using AI models for discovery while patches are crafted manually.
The advisories published in late June affect critical components: – OpenZFS (CVE-2026-49429/49430): Kernel heap overflows via integer truncation in buffer sizes – libalias/RTSP (CVE-2026-49420): Buffer overflow enabling potential remote code execution on NAT gateways – TCP RACK (CVE-2026-49422): Use-after-free in the TCP stack – POSIX shared memory: Kernel memory freeing error with sendfile – KTLS: Denial of service via uninitialized memory access – compat32: Kernel stack disclosure in 32-bit compatibility mode – Linux compatibility layer: Kernel stack disclosure – iconv: Multiple vulnerabilities
Additionally, stack-protector-strong support (D56870) has been MFC’d to the stable/14 branch — an important hardening feature now enabled by default in the kernel.
The FreeBSD Enterprise Working Group (EWG) published results from its enterprise user survey. The Net Promoter Score (NPS) comes in at 51.6 — in the technology sector, an NPS above 50 is considered excellent. 86% of respondents report that FreeBSD’s enterprise usability has improved (52%) or remained stable (34%) over the past three years. Key improvement drivers: bhyve, Jails management, Zero Trust, Reproducible Builds, and SBOMs. Biggest gaps: cloud-native support, third-party enterprise app support, and long-term support.
The FreeBSD Foundation published its Laptop Project update for June. Key highlights: – Linux DRM 6.13: Graphics driver porting is complete and submitted for review. This is the first step toward DRM 6.18 (current LTS version). – Heterogeneous scheduling: Detailed ULE scheduler analysis performed; bug fixes submitted. An Intel Feedback Interface driver and HMP framework are in review. – S0ix/Suspend: Progress on D-state management for the AMD Framework Laptop; NVMe resume issues under investigation. – Hibernate (S4): A talk at the Developer Summit covered the current state of hibernate implementation. – Wi-Fi 6: Three drivers available (iwlwifi, rtw89, mt76); net80211 stack extensions still needed. – Perfetto: FreeBSD porting complete, pending review. – RFKILL/Keyboard: New driver for HID wireless radio control buttons (airplane mode toggle) added.
The official release schedule for FreeBSD 15.2 was published on July 15: – October 23, 2026: Code slush begins – November 6, 2026: releng/15.2 branch created + BETA1 – December 4, 2026: RELEASE builds begin – December 8, 2026: Release announcement – End-of-life: 15.1 on March 31, 2027; 15.2 on September 30, 2027
A selection of noteworthy commits in the FreeBSD source tree: – pfctl: Fix incorrect errno checks(kprovost) — Functions return error values but don’t set errno. – Revert “pkg: Add -j and -r options”(kevans91) — The options were reverted. – amd64 efirt: Register all runtime regions as fictitious(kostikbel) — Important for virtualization. – exterrctl(2): Add kern_exterrctl (brooksdavis) — CHERI upstreaming work, sponsored by DARPA. – ptrace(2): PTSETSC_RET request (kostikbel) — New ptrace functionality, sponsored by the FreeBSD Foundation. – malloc: Refactor redzone and KASAN handling(D58272) — Overhaul of memory debugging infrastructure.
Date: July 13, 2026
Period: Monday, July 6 – Sunday, July 12, 2026
The biggest security news of the past two weeks landed on June 30, when FreeBSD published 13 security advisories (SA-26:37 through SA-26:49) addressing multiple critical vulnerabilities. Key highlights:
sendfileis used with a specific flag, while active mappings still reference the freed memory. Local attackers can access freed kernel memory.All advisories affect FreeBSD 14.x and 15.x. Administrators should update their systems promptly. Systems not loading specific modules are partially unaffected; workarounds include disabling libalias, unloading the TCP RACK module, and restricting unprivileged ZFS access.
On the main branch (FreeBSD 16-CURRENT), several notable commits landed:
In the ports tree: – www/deno: Improve port (VVD, delphij): The Deno port received dependency fixes, PREFIX/LOCALBASE cleanup, and three patch correctness bugs were fixed.
A long-time Mac OS and later Linux user (10 years of Arch Linux with Sway/Wayland) describes their switch to FreeBSD as a daily driver. After a Linux kernel update broke their keyboard, they installed FreeBSD and have been happy for 6 months. Missing pieces: OBS browser source and AnyDesk/RustDesk (workaround: VM). Their verdict: “It works.” and the community has been very welcoming.
An excellent technical deep-dive into FreeBSD memory management. It explains why btop and fastfetch report wildly different memory usage on the same system (btop treats wired memory as “used,” fastfetch counts inactive+cache as “free”). The article covers page queues (Active, Inactive, Laundry, Wired, Free) and ZFS ARC — and why nearly free memory on a healthy FreeBSD system trends toward zero (by design).
A detailed guide for upgrading from 15.0-RELEASE to 15.1-RELEASE via both official paths: freebsd-update (distribution-set) and pkg (packaged-base). Particularly useful: the pkg which /usr/bin/uname distinction, the boot-loader update sequence, and the note about the June 30 errata. Updated on July 2 with the correct boot-loader procedure.
A guide to installing and setting up a GitLab server on FreeBSD. Compares GitLab with Gitea as on-premises alternatives to GitHub. Includes notes on Nginx, ZFS, and GELI-encrypted VMs.
A review of the new desktop installation option in FreeBSD 15.1, which lets you set up KDE directly during installation. FreeBSD 15.1 also received improved WiFi support (Linux 7.0 WLAN drivers) and a boot-time scheduler switch.
Third installment of a FreeBSD fundamentals series: from the loader through kernel boot to boot environments. Ideal for newcomers wanting to understand how FreeBSD starts up.
An in-depth two-hour interview with Marcus Hellberg, kernel engineer and core team member. Topics include the 14.x consolidation cycle, the WITHOUTASLR removal (ASLR is now non-optional), OpenZFS synchronization practices, and the jails roadmap. Notable quote on the ASLR debate: *”Removing WITHOUTASLR was a statement: this is not optional anymore.”* On the future of jails: standardized image formats and better orchestration tooling are on the wish list.
FreeBSD 15.1-RELEASE was announced on June 16, 2026. In the weeks following, upgrade guides and first-hand reports dominated the community. Key new features in 15.1:
Support timeline: 15.1 is supported until March 31, 2027. 15.0 reaches EOL on September 30, 2026.
The weekly “Valuable News” roundup from vermaden covers: FreeBSD boot process fundamentals, running pkgbasify on FreeBSD 15.1, upgrading from 15.0 to 15.1, and more community topics.
With 13 critical security vulnerabilities patched at the end of June, the most urgent task for all FreeBSD administrators is: update your systems. The 15.0 EOL is approaching (September 30), making an upgrade to 15.1 strongly recommended. Community discussions around desktop experience, memory monitoring, and jails orchestration show that FreeBSD continues to mature as both a workstation and server platform.
This has been one of the most eventful weeks in recent FreeBSD history: a new release, a new Core Team, a graphics driver milestone, and a proposal to overhaul the service manager. Here’s the roundup.
The biggest news of the week: FreeBSD 15.1-RELEASE was announced on June 16 – the second release of the stable/15 branch. The release was originally planned earlier but delayed by two weeks.
Highlights include:
kern.sched.name tunableThe release notes also include numerous base system changes: find(1) now supports -xattr and -xattrname, bectl(8) can create empty boot environments (-E), cron(8) gains full PAM session lifecycle support, and the default root shell has changed from csh to sh.
On June 24, the 2026 FreeBSD Core Team election results were announced. The nine elected members of the fourteenth Core Team are:
A bylaws amendment was also passed, tentatively taking effect with the 2028 election at the new core team’s discretion. The transition plan will be shared soon.
Outgoing core.13 members: Li-Wen Hsu, Allan Jude, Tobias C. Berner, Dave Cottlehuber, and Mathieu Arnold. Dag-Erling Smørgrav ran a flawless election.
The FreeBSD Foundation announced on June 16 that the drm-kmod port now includes the Linux 6.12 LTS graphics driver. This update brings:
The update requires FreeBSD 15.1 or later.
The FreeBSD Security Officer announced on June 20 that FreeBSD 14.3 reaches end-of-life on June 30, 2026, after which it will no longer receive security support. Users should upgrade immediately.
After June 30, the supported branches and releases are:
| Branch | Release | Estimated EoL |
|---|---|---|
| stable/15 | — | December 31, 2029 |
| releng/15.1 | 15.1-RELEASE | March 31, 2027 |
| releng/15.0 | 15.0-RELEASE | September 30, 2026 |
| stable/14 | — | November 30, 2028 |
| releng/14.4 | 14.4-RELEASE | December 31, 2026 |
On June 14, Baptiste Daroussin opened a discussion on freebsd-hackers about rcd(8), a new service manager daemon he’s been working on for years. The discussion continued throughout this week.
Key features:
pdfork(2) descriptors (no PID file races)procctl(2) (no orphaned process escape)rctl(2)jail(2) integrationprocctl(2) PROC_SPROTECTdhclient@em0)User interface: rcctl(8), familiar from OpenBSD but with FreeBSD-specific implementation.
100% backward compatibility is a hard requirement. rcd scans existing rc.d scripts, parses their PROVIDE/REQUIRE/BEFORE/KEYWORD headers, reads rc.conf, and wraps each script as a virtual “legacy” unit. The migration path is gradual: rc.d scripts will be converted to native UCL unit files at each maintainer’s pace, with no deadline.
The mailing list discussion was intense, with comparisons to launchd and debates over compatibility, daemon supervision, and the migration path.
On June 27, the OpenZFS merge (commit d0b3ecd) was integrated into the FreeBSD main branch. The change spans +6,983/-2,497 lines across 161 files, pulling in upstream PRs including #18509.
Additionally, on June 25, zfsd spare selection was improved (commit 6aaaf7b), porting OpenZFS PRs #18597 and #18578 from zed to zfsd. Spare selection now considers optimal spare distribution across pools.
On June 24, Dag-Erling Smørgrav (des) published a blog post showing how to convert a FreeBSD 15 system to packaged base (pkgbase) with a single command:
# pkg install -r FreeBSD-base --register-only FreeBSD-set-{base,lib32,kernels}{,-dbg} FreeBSD-set-{src,tests}
He walks through enabling the FreeBSD-base repository, creating a boot environment, and notes minor issues like pkg leaf not accounting for shared library dependencies.
Praetorian published a detailed blog post on June 17 describing how their team used Claude Opus 4.6 and Claude Code to find eight FreeBSD kernel vulnerabilities – including CVE-2026-3038, a stack overflow enabling jail escapes. This underscores the significance of the FreeBSD Foundation’s AI-assisted Vulnerability Discovery Project, launched June 15 with $250k funding from Alpha Omega.
While these advisories originated in the previous week, they remain relevant:
| Advisory | Module | Topic |
|---|---|---|
| SA-26:26.ktls | Kernel | Arbitrary file overwrite via KTLS receive path |
| SA-26:27.sound | Kernel | Multiple vulnerabilities in sound(4) mmap path |
| SA-26:29.ip6_multicast | Kernel | Use-after-free in IPV6_MSFILTER socket option |
| SA-26:30.linux | Kernel | Flaw in Linuxulator execution of setugid binaries |
| SA-26:31.arm64 | Kernel | ARM CPU errata may bypass page table permission changes |
| SA-26:32.elf | Kernel | ASLR bypass for setuid executables via procctl(2) |
| SA-26:33.unbound | Contrib | Multiple vulnerabilities in unbound |
| SA-26:34.vt | Kernel | Integer overflow in vt(4) CONS_HISTORY ioctl |
| SA-26:35.openssl | Contrib | Multiple vulnerabilities in OpenSSL |
| SA-26:36.ldns | Contrib | Insufficient response validation in ldns stub resolver |
All advisories affect FreeBSD 14.x and 15.x. Users should run freebsd-update immediately.
Week 26 was one of the densest in recent memory for FreeBSD: a new major release, a newly elected Core Team, a significant graphics driver jump, the unveiling of a new service manager proposal, and an EoL deadline for 14.3. If you’re still on 14.3, upgrade now – the clock runs out on June 30.
Links: – FreeBSD 15.1-RELEASE Announcement – Release Notes – FreeBSD Foundation Graphics Blog – New Core Team Announcement – rcd(8) Discussion – pkgbasify Blog Post – Praetorian FreeBSoD Blog – AI Vulnerability Discovery Project – FreeBSD 14.3 EoL
This week belonged to FreeBSD: the 15.1 release, a massive security advisory batch, a new AI-assisted vulnerability project, and the end-of-life announcement for 14.3 — plenty to digest.
The big headline: on June 16, the Release Engineering Team published FreeBSD 15.1-RELEASE. A critical x86 bootloader bug had delayed it by two weeks, but the second release from the stable/15 branch is now available.
WiFi drivers updated to Linux 6.7/7.0 level: The LinuxKPI-based wireless drivers (iwlwifi and others) have been brought up to the Linux kernel 7.0 level, delivering significantly better compatibility with modern WiFi hardware — especially Intel chipsets and select MediaTek/Realtek devices.
C23 support progresses: The compiler and standard library have made further strides toward full C23 compliance.
Graphics drivers upgraded to Linux 6.12 (LTS): The FreeBSD Foundation announced that the drm-kmod port now includes the Linux 6.12 graphics driver, an LTS kernel with planned maintenance through 2036 (CIP program). This brings better compatibility with current AMD Radeon and Intel GPUs and improved Wayland support. Available for FreeBSD 15.1 onward.
Other notable changes in 15.1:
-xattr and -xattrname primaries for searching by extended attributes (sponsored by Klara Systems)-u flag to disable soft updates-E flag to create empty boot environments without cloning-u to prevent automatic mounting of new datasets-L (logical), following POSIX semanticsRelease info: freebsd.org/releases/15.1R
On June 9 — before the release — the Security Team published nine advisories simultaneously, several rated core with critical impact:
| Advisory | Component | Category | Topic |
|---|---|---|---|
| SA-26:25.thr | kernel (thr) | core | Missing permission check in thr_kill2(2) |
| SA-26:26.ktls | kernel (ktls) | core | Arbitrary file overwrite via KTLS receive path |
| SA-26:27.sound | kernel (sound) | core | Multiple vulnerabilities in sound(4) mmap path |
| SA-26:29.ip6_multicast | kernel (ip6_multi) | core | Use-after-free in IPV6_MSFILTER |
| SA-26:30.linux | kernel (linux) | core | Flaw in Linuxulator execution of setugid binaries |
| SA-26:31.arm64 | kernel (arm64) | core | ARM CPU errata bypasses page table permission changes |
| SA-26:32.elf | kernel (elf) | core | ASLR bypass for setuid executables via procctl(2) |
| SA-26:34.vt | kernel (vt) | core | Integer overflow in vt(4) CONS_HISTORY ioctl |
| SA-26:35.openssl | openssl | contrib | Multiple OpenSSL vulnerabilities |
| SA-26:36.ldns | ldns | contrib | Insufficient response validation in ldns stub resolver |
All advisories are patched in 15.1-RELEASE. Users on older versions should update immediately.
On June 15, the FreeBSD Foundation announced the AI-assisted Vulnerability Discovery Project, funded by a $250,000 grant from the Linux Foundation’s Alpha Omega initiative (backed by Anthropic, AWS, GitHub, Google, Microsoft, and OpenAI).
Key points:
Coinciding with this, Praetorian published a detailed blog post about their own AI-powered research: using Claude Code (Opus 4.6), they found eight FreeBSD kernel vulnerabilities in just days, including CVE-2026-3038 (a stack overflow in the route subsystem, already patched in SA-26:05.route). The other seven are still being processed. The post walks through their methodology — from source analysis to crash reproduction to exploit development with jail escape.
On June 20, the Security Team announced that FreeBSD 14.3 reaches end-of-life on June 30, 2026 — no more security patches after that. Users should upgrade to 14.4 or 15.1. The stable/14 branch will remain maintained until November 2028.
pkgbasify — converting to packaged base elegantly: Dag-Erling Smørgrav (blog.des.no) describes his approach to converting FreeBSD 15.1 systems from distribution sets to pkgbase with a single pkg install command. He critiques the Foundation’s official pkgbasify script and offers a more direct alternative. If you’ve been meaning to try pkgbase, this is a practical guide.
Native inotify in FreeBSD: Klara Systems published a deep dive into the limitations of EVFILT_VNODE/kqueue for file monitoring and why FreeBSD needs a native inotify implementation. The existing libinotify userspace wrapper suffers from race conditions and scalability issues — the article explains the technical details and proposes solutions.
ZFS Vendor Import: Chris Longros reports that his ZFS commits have been upstreamed into the FreeBSD tree — a small but important milestone for ongoing ZFS maintenance.
Selected commits from the past week:
This week was dominated by the FreeBSD 15.1 release — one that noticeably improves laptop and desktop viability (WiFi, graphics, better suspend/resume). At the same time, the flood of security advisories and the new AI vulnerability project underscore how much the threat landscape is shifting: AI tools are drastically lowering the barrier to vulnerability discovery, and FreeBSD is responding in kind. Anyone still on 14.3 needs to act by June 30 at the latest.
The single most important development this week was the security advisory batch released on June 9, 2026, which brought no fewer than nine advisories — several rated core with critical impact:
thr_kill2(2). An unprivileged local user could send signals to arbitrary processes, even across jail boundaries. Discovered by researchers at Tsinghua University using GLM-5.1 (Z.ai) — a notable case of AI-assisted security research. CVE-2026-45256sendfile(2) + loopback), a local user could overwrite file contents including setuid binaries — achieving full privilege escalation. No workaround available. CVE-2026-45257, category: core.mmap vulnerabilities in the sound(4) driver (CVE-2026-45258, CVE-2026-49417) allowing unprivileged local users to read/write kernel memory via /dev/dsp, enabling privilege escalation.sigqueue(2) lacked a Capsicum mode check, allowing sandboxed processes to send signals to other processes, bypassing Capsicum restrictions.AT_SECURE to zero for setuid/setgid Linux binaries. Unprivileged users could inject shared libraries via LD_PRELOAD and escalate privileges.Bottom line: Anyone running FreeBSD in production should patch and reboot immediately — the ktls and thr vulnerabilities are particularly critical.
After two unplanned release candidates, FreeBSD 15.1-RC3 was published on June 6. The only but critical fix addressed the x86 boot loader / kernel handover: the system could hang during boot, especially when Intel microcode updates were being loaded.
The RELEASE date is now set for June 16, 2026 — tomorrow, barring further delays.
Highlights from the release notes:
installworld/installkernel blocked on pkgbase systems to prevent package database inconsistenciesfind(1) gains -xattr and -xattrname for extended attribute searchesbectl(8) gains -E flag to create empty boot environmentszfs clone gains -u to prevent automatic mountingnewfs(8) gains -u flag to disable soft updatesdaemon(8) supports configurable file modes for log outputdiff3(1) now GNU-compatible in merge modesetaudit(8) added as a new utility for audit policiesipfs(8) disabled by default, kernel support now optionalOn June 10, Jean-Sébastien Pédron (dumbbell) updated the DRM drivers in the Ports tree — commit messages indicate a version bump to Linux 6.12.85 (matching the recently released drm_v6.12.85_2). Anyone needing current Intel/AMD graphics should update their drm-*-kmod packages.
Klara Systems published an in-depth article on the shortcomings of the userspace inotify implementation (libinotify.so) on FreeBSD. The library translates inotify calls into kqueue/EVFILT_VNODE, which leads to sporadically missing CLOSE events. The article compares the inotify and kqueue APIs and discusses how a native kernel inotify implementation could resolve these reliability issues.
Another contribution covering FreeBSD Jails as a container isolation technique — a classic topic that keeps getting refreshed.
A third release candidate for FreeBSD 15.1, critical x86 bootloader bugs, a flood of AI-discovered vulnerabilities, and the Frankfurt hackathon recap – this week was packed for FreeBSD.
The week’s headline event: Colin Percival announced FreeBSD 15.1-RC3 on June 6. A third release candidate was needed because a critical bug in the x86 bootloader/kernel handoff was discovered that could cause systems to hang during boot – most commonly, but not exclusively, when Intel microcode updates are being loaded.
The announcement explicitly warns: when upgrading to RC3, you must install the updated EFI bootloader. The originally planned early-June release date has slipped to mid-June.
RC2 (May 31) had already re-introduced PadLock RNG support for VIA/Zhaoxin processors and integrated security fixes from SA-26:19 through SA-26:24. RC3 builds on that with the critical bootloader fix.
Available images include amd64, powerpc64(le), armv7, aarch64 (including RPI, PINE64, ROCK64), and riscv64, plus VM images (QCOW2, VHD, VMDK, raw), OCI container images, and Amazon EC2 AMI images.
The wave of security advisories published in late May (SA-26:18 through SA-26:24) continues to dominate discussions. Notably, most of these vulnerabilities were discovered through AI-driven security research:
A stack buffer overflow in the new setcred(2) system call that could lead to local privilege escalation (CVE-2026-45250).
Discovered by Calif.io. A use-after-free in the kernel through file descriptor system calls.
Discovered by the AISLE Research Team. A heap overflow in the FUSE file system code.
Found by researchers using GLM-5.1 from Z.ai. Unprivileged local users could escalate privileges to root.
Also from the AISLE Research Team. A file descriptor set overflow in select(2) led to a stack overflow. CVE-2026-39457 and CVE-2026-39461 were assigned.
A suitably crafted network name (SSID) could cause command execution via sub-shell during Wi-Fi scans in bsdinstall and bsdconfig.
Incorrect manipulation of permission lists in libcap_net could extend a process’s permissions.
Published April 29 but relevant context for the current wave: invalid SCTP packets could trigger unbounded recursion in pf, resulting in a stack overflow and kernel panic (CVE-2026-7164).
On May 25, the AISLE Research Team published a detailed blog post on discovering three separate stack buffer overflows in FreeBSD, all reachable through the same basic attack vector:
ping program retained. A local user could open many file descriptors and then execute /sbin/ping6, forcing later descriptors above 1023 and reaching unchecked FD_SET() calls.Particularly interesting: the ping6 bug had been fixed in closely related code back in 2002, but the corresponding guard was removed during a refactoring and never restored.
Calif.io published a comprehensive retrospective on their AI-driven audit campaign against FreeBSD. Result: 15 kernel bugs, including 3 Remote Code Execution (RCE), 5 Local Privilege Escalation (LPE), and 1 bhyve escape.
Another Calif.io article demonstrating how a single shell script was enough to gain root access on a FreeBSD system.
AISLE reports independently reproducing three of the eight FreeBSD security advisories from April 2026 that were also found by Nicholas Carlini at Anthropic (Claude Mythos).
CVE-2026-42511: A 21-year-old remote code execution vulnerability in dhclient, where the BOOTP file field was not properly escaped, allowing injection of arbitrary dhclient.conf directives.
The FreeBSD Foundation published a recap of the first regional hackathon in the Frankfurt area (April 24–26). Results: 120 closed bug reports, successful implementation of SBOM (Software Bill of Materials) functionality, and a German translation of Sylve.
A practical triage guide for admins: of the seven simultaneously published advisories, two are kernel-side and trivially exploitable by any local user – patch those first.
Gleb Smirnoff flagged on the freebsd-current list that the recent mtree(1) import from NetBSD constitutes a POLA (Principle of Least Astonishment) violation: checksum behavior has changed. Jose Luis Duran and Xin LI discussed potential corrections; a differential (D56013) was submitted to add missing entries.
Mailing list activity shows the typical end-of-cycle intensity: RC1, RC2, and RC3 were each announced on freebsd-stable. The delay from additional release candidates has drawn mixed reactions – understanding of the security fixes, but also impatience for the final release.
This was one of the most security-intensive weeks in recent FreeBSD history. Between AI-discovered vulnerabilities, a new release candidate, and the Foundation’s Executive Director daily-driving FreeBSD on a laptop, there was plenty to talk about.
On May 29, Colin Percival released the first release candidate for FreeBSD 15.1. RC1 includes a batch of security fixes (more below), improvements to the fwget firmware tool, and various small kernel bug fixes and man page updates.
The 15.1-RELEASE is planned for June, assuming no further surprises. The release cycle has been fairly smooth so far: BETA1 dropped on May 2, and RC1 is the latest milestone.
Download: https://download.freebsd.org/releases/ISO-IMAGES/15.1/
On May 20, FreeBSD published seven security advisories in a single day — enough to make even seasoned operators sweat. Xiujun Ma published an excellent triage guide that I recommend every admin read.
The two most critical:
The setcred(2) system call copies a user-supplied list of supplementary groups into a fixed-size kernel stack buffer without checking the length. The result: a kernel stack overflow that enables arbitrary kernel-level code execution. Any local user can trigger this, no special configuration required, all supported FreeBSD versions affected. Patch immediately.
Insufficient parameter validation in the PT_SC_REMOTE ptrace operation allows unprivileged local users to execute arbitrary system calls inside a target process. Local → root. On multi-user boxes and jail hosts, this is also a same-day patch.
The remaining five advisories:
| Advisory | Issue | Urgency |
|---|---|---|
| SA-26:24.cap_net | Capsicum permission limit bypass | This week |
| SA-26:22.libcasper | Stack overflow via select(2) with >1024 file descriptors (CVE-2026-45252) | This week |
| SA-26:23.bsdinstall | Root RCE via malicious Wi-Fi SSIDs during installer scanning (CVE-2026-45255) | Before next install/re-image |
| SA-26:20.fusefs | Kernel heap disclosure/injection via rogue FUSE daemon | Only if fusefs.kois loaded |
| SA-26:19.file | file(1) / libmagic issue | This week |
This is the big story of the week: AI systems are now actively finding FreeBSD kernel bugs.
Security research firm Calif.io published a detailed blog postdescribing their AI-driven audit of the FreeBSD kernel. Within a few weeks, the AI found:
In total, 15 kernel bugs, all reported to the FreeBSD security team. Notably, Calif.io coordinated with the FreeBSD team, focused on their priorities, and only reported high/critical bugs — no CVE-chasing, just targeted help.
One of the published exploits is setcred (CVE-2026-45250): a single-character sizeof confusion in kern_setcred_copyin_supp_groups that turns into a stack overflow and then a local root shell. Only FreeBSD 14.4 is exploitable, despite the same source bug being present in 14.3 and 15.0.
The AISLE Research Team also made waves. On May 25, they published a report on three stack buffer overflows in ping6, libnv, and libcasper — all reachable through the same fundamental mechanism: FD_SET() with file descriptors above 1023.
The ping6 bug is particularly notable: the binary runs setuid-root, meaning any local user can trigger the vulnerable path in a process with effective UID 0. Ironically, FreeBSD had already fixed this exact bug class in closely related code back in 2002 — the guard in ping6 disappeared during a later refactoring and never returned.
AISLE also discovered a 21-year-old RCE in dhclient (CVE-2026-42511) and reported that their autonomous system independently found three of the eight April security advisories — matching Anthropic’s “Claude Mythos” on capability.
Deb Goodkin, the FreeBSD Foundation’s Executive Director since 2005, spoke at the Open Source Summit + ELC NA 2026 in Minneapolis about her experience daily-driving FreeBSD on a Framework Laptop. Until recently, she hadn’t been running FreeBSD as her daily OS because it “felt like a mountain.”
Her takeaways:
This aligns with the Foundation’s ongoing Laptop Integration Testing Project, which aims to close the graphics and Wi-Fi driver gap with Linux in 2026.
The NVIDIA graphics driver in FreeBSD ports was updated to version 595.71.05. Anyone running NVIDIA hardware on FreeBSD should plan to update the port.
freebsd-stable and freebsd-current are ongoing.OpenBSD 7.9 was released on May 30 — with support for up to 255 CPU cores and WiFi 6. Not directly FreeBSD, but worth noting for anyone following the BSD ecosystem.
The big takeaway: AI-driven security research is no longer a theoretical concept — it’s actively finding kernel bugs in FreeBSD. At the same time, the cooperation between Calif.io/AISLE and the FreeBSD team shows what constructive engagement looks like: short reports, suggested patches, direct communication rather than CVE-count chasing.
FreeBSD 15.1-RELEASE is approaching and will include all of these fixes. If you operate multi-user systems, patch SA-26:18.setcred and SA-26:21.ptrace immediately — the rest of the advisories can wait until this week.
This past week was one of the most eventful for FreeBSD in recent memory: six security advisories dropped simultaneously, FreeBSD 15.1 hit release candidate status, and the FreeBSD Foundation’s executive director went public about daily-driving FreeBSD on a laptop.
On May 22, Colin Percival announced FreeBSD 15.1-RC1 — the first and likely only release candidate before the planned final release in early June. RC1 is available for amd64, powerpc64, powerpc64le, armv7, aarch64 (including RPI, PINE64, PINEBOOK, ROCK64, ROCKPRO64), and riscv64.
Changes since Beta 3 include:
/etc/ssl/cert.pemThe full set of installation images, VM images (QCOW2, VHD, VMDK, raw), OCI container images, and EC2 AMI images are available on the usual download mirrors.
On May 20, the FreeBSD Security Team released six security advisories simultaneously — several of which were discovered through AI-driven vulnerability research.
The most severe vulnerability of the week. A sizeof type error in kern_setcred_copyin_supp_groups()(sys/kern/kern_prot.c) causes a kernel stack buffer overflow in the setcred(2) system call. The bug: sizeof(*groups) evaluates to 8 bytes (pointer size) instead of the intended 4 bytes (sizeof(gid_t)). An unprivileged local user can exploit this to escalate to root — even on systems with SMAP/SMEP enabled. The vulnerability was disclosed by Przemyslaw Frasunek under the name “FatGid” and affects FreeBSD 14.3, 14.4, and 15.0.
Fixed in: 14.3-RELEASE-p14, 14.4-RELEASE-p5, 15.0-RELEASE-p9. FreeBSD 13.x and earlier are unaffected (the setcred(2)syscall doesn’t exist there).
A file descriptor system call flaw can lead to a kernel use-after-free condition. Discovered by Calif.io (AI-driven vulnerability discovery).
The kernel processes extended attribute lists from userspace FUSE daemons without verifying proper NUL termination, potentially allowing a malicious FUSE daemon to trigger a heap overflow. Discovered by the AISLE Research Team (autonomous vulnerability discovery).
Missing input validation allows unprivileged local users to escalate privileges to root. Discovered using GLM-5.1 by Z.ai.
An overflow of the file descriptor set in select(2) within libcasper leads to a stack overflow. Discovered by the AISLE Research Team.
A specially crafted network name (SSID) can trigger arbitrary command execution via sub-shell during Wi-Fi access point scanning in bsdinstall and bsdconfig. Practically relevant when installing in Wi-Fi environments.
Faulty manipulation of limitation lists in libcap_net can extend a process’s permissions beyond what was intended. Discovered by the AISLE Research Team.
Takeaway: What’s notable is that several of these vulnerabilities were discovered through AI-based tools (Calif.io, GLM-5.1, AISLE Research Team). This marks a turning point in OS security auditing — AI-driven discovery is now producing real, exploitable findings.
The third beta of FreeBSD 15.1, released the previous weekend, brought important updates:
pkg upgrade on first boot to apply security updatesDeb Goodkin, Executive Director of the FreeBSD Foundation since 2005, presented at the Open Source Summit North America (OSS 2026) in Minneapolis about her experience daily-driving FreeBSD on a Framework Laptop. Previously, every attempt to run FreeBSD on laptops “felt like a mountain” — time-consuming and ultimately getting stuck. With the KDE desktop, the touchscreen “just worked,” as did peripherals like a wireless mouse. Challenges remained: Zoom required effort to get working, the webcam needed manual steps to enable, and Microsoft Teams only partially worked. An encouraging sign, but also an honest assessment of the remaining gaps in desktop support.
Ian Wagner published a helpful blog post on configuring different package repositories per jail under FreeBSD. Using AppJail for declarative jail management, the post demonstrates how to switch specific jails to the latest ports branch when newer packages are needed while others remain on quarterly.
A thorough guide on resource monitoring and troubleshooting on FreeBSD systems — from “the server feels slow” to concrete diagnostic tools and techniques.
A blog that ran on Ubuntu 16.04 for 10 years reported on its migration to FreeBSD, motivated by Ubuntu 16.04’s end-of-life and the promise of long-term stability.
The weekly link roundup from vermaden offers its usual comprehensive overview of BSD and UNIX-related articles.
Discussions around the pkgbase upgrade path from 15.0-RELEASE to 15.1-BETA2 reveal that the transition to the new default installation method isn’t entirely smooth yet. Issues with kernel modules (kmods) and the pkgbase-quarterly repos were extensively discussed.
Garrett Wollman reported issues with booting his server fleet, sparking a discussion about boot-time behavior and error handling.
Daniel Braniss and Bjoern Zeeb discussed problems with diskless setups under FreeBSD 15.1 that can cause hangs during boot.
If all goes according to plan, FreeBSD 15.1-RELEASE is expected around June 2, 2026. The KDE desktop installation option has been deferred to FreeBSD 15.2 (expected December 2026). Until then, manual installation via pkg remains the recommended approach for a KDE desktop on FreeBSD.
This week saw the third beta of FreeBSD 15.1, a critical execve() privilege escalation vulnerability, the KDE desktop installer option being pushed to 15.2, and two libnv security advisories that remain highly relevant. Here’s your summary.
FreeBSD 15.1-BETA3 was released over the weekend as the latest weekly test candidate. The release is entering its final stretch — the Release Candidate (RC) is expected next week, and if all goes well, FreeBSD 15.1-RELEASE is targeted for June 2, 2026.
Key changes in Beta 3:
pkg upgrade on first boot to apply security updates to the base system. A sensible improvement for cloud deployments that often start from stale images.The beta cycle has been relatively smooth so far. BETA1 and BETA2 in previous weeks brought Zstd 1.5.7, userland fixes for ifconfig, lockf, stat, tail, and certctl, plus kernel fixes for nullfs, so_splice, and VT.
pkg.freebsd.org for package bootstrapA serious kernel vulnerability disclosed in late April continues to generate discussion. FreeBSD-SA-26:13.execdescribes an operator-precedence error in the execve(2) implementation that leads to a buffer overflow. Attacker-controlled data can spill into adjacent argument buffers, corrupt kernel state, and grant unprivileged users root access.
The flaw affects all supported FreeBSD releases (13.5 through the 15 branch). Patches were published within hours, adding explicit parentheses to enforce the intended evaluation order and tightening size checks.
Also disclosed on April 29, two libnv vulnerabilities remain relevant for anyone who hasn’t patched yet:
select() file descriptor set overflow — when a socket descriptor exceeds FD_SETSIZE (1024), select(2) overflows its file descriptor set. An attacker who can force a program to open many descriptors can trigger stack corruption and potentially escalate privileges via setuid-root programs. Discovered by Joshua Rogers (AISLE Research Team).Both affect all supported FreeBSD versions with no workaround. Upgrade and reboot are mandatory.
The long-awaited KDE desktop installation option in the FreeBSD installer has been delayed again — this time from 15.1 to FreeBSD 15.2 (expected December 2026). Originally planned for 15.0, then moved to 15.1, the installation script needs updates for new NVIDIA drivers and removal of obsolete components. After committing to CURRENT, a testing period in STABLE is required, which no longer fits the 15.1 timeline.
Until then, KDE Plasma can be set up manually via pkg after installation.
Bob Prohaska kicked off a discussion about preferred update strategies for self-hosted FreeBSD systems. On stable branches, freebsd-update is straightforward. On current, things get more complex. Warner Losh, Rick Macklem, Mark Millard, and others weighed in on the trade-offs of different approaches — a worthwhile read for anyone running current in production.
Vermaden asked about the upgrade path from FreeBSD 15.0-RELEASE to 15.1-BETA2 using the PKGBASE model. Colin Percival confirmed this path isn’t fully documented yet. The PKGBASE system remains marked as experimental, and the minor-release upgrade workflow needs more work.
The FreeBSD Foundation published a detailed report on the Beach Cleaning Project in late April that continues to draw attention:
The project was funded by Alpha-Omega and produced practical tooling, security assessments, and implementation plans that will serve FreeBSD development well beyond the project’s lifespan.
Vermaden published a practical guide for upgrading FreeBSD 15.0 to 15.1-BETA2 using PKGBASE and ZFS Boot Environments. The walkthrough covers creating a new BE, configuring the pkg repository, upgrading the base system, and rolling back if needed — including an alternative approach using --chroot.
Pete shared a personal blog post about returning to BSD after decades on Linux. He describes moving from Arch Linux to FreeBSD, setting up mail servers with Bastille jails, and appreciating the simplicity of the rc system compared to systemd. A nostalgic and practical read.
Next week will see the Release Candidate for FreeBSD 15.1. If no unexpected issues arise, the final release is expected on June 2, 2026. Administrators should patch the three security vulnerabilities (execve, libnv x2) immediately if they haven’t already.
Sources: Phoronix, FreeBSD Mailing Lists, FreeBSD Security Advisories, FreeBSD Foundation, Vermaden Blog, LavX News, peteftw.com