FreeBSD 15.0-RELEASE Errata
Abstract
This document lists errata items for FreeBSD 15.0-RELEASE, containing significant information discovered after the release or too late in the release cycle to be otherwise included in the release documentation. This information includes security advisories, as well as news relating to the software or documentation that could affect its operation or usability. An up-to-date version of this document should always be consulted before installing this version of FreeBSD.
This errata document for FreeBSD 15.0-RELEASE will be maintained until the release of FreeBSD 15.1-RELEASE.
Table of Contents
Introduction
This errata document contains "late-breaking news" about FreeBSD 15.0-RELEASE. Before installing this version, it is important to consult this document to learn about any post-release discoveries or problems that may already have been found and fixed.
Any version of this errata document actually distributed with the release (for example, on a CDROM distribution) will be out of date by definition, but other copies are kept updated on the Internet and should be consulted as the "current errata" for this release. These other copies of the errata are located at https://www.nsoiwdjgsld.gq/releases/, plus any sites which keep up-to-date mirrors of this location.
Source and binary snapshots of FreeBSD 15-STABLE also contain up-to-date copies of this document (as of the time of the snapshot).
For a list of all FreeBSD CERT security advisories, see https://www.nsoiwdjgsld.gq/security/.
Security Advisories
| Advisory | Date | Topic |
|---|---|---|
16 December 2025 |
Remote code execution via ND6 Router Advertisements |
|
27 January 2026 |
Multiple vulnerabilities in OpenSSL |
|
10 February 2026 |
blocklistd(8) socket leak |
|
24 February 2026 |
Local DoS and possible privilege escalation via routing sockets |
|
26 March 2026 |
TCP: remotely exploitable DoS vector (mbuf leak) |
|
26 March 2026 |
Remote denial of service via null pointer dereference |
|
26 March 2026 |
Remote code execution via RPCSEC_GSS packet validation |
|
26 March 2026 |
pf silently ignores certain rules |
|
21 April 2026 |
Kernel use-after-free bug in the TIOCNOTTY handler |
|
21 April 2026 |
Missing large page handling in pmap_pkru_update_range() |
|
29 April 2026 |
Remote code execution via malicious DHCP options |
|
29 April 2026 |
Local privilege escalation via execve() |
|
29 April 2026 |
pf can overflow the stack parsing crafted SCTP packets |
|
29 April 2026 |
Remotely triggerable out-of-bounds heap write in dhclient |
|
29 April 2026 |
Stack overflow via select() file descriptor set overflow |
|
29 April 2026 |
Heap overflow in libnv |
|
20 May 2026 |
Stack buffer overflow via setcred(2) |
|
20 May 2026 |
Kernel use-after-free via file descriptor syscalls |
|
20 May 2026 |
Heap overflow in FUSE_LISTXATTR |
|
20 May 2026 |
Missing validation in ptrace(PT_SC_REMOTE) |
|
20 May 2026 |
select(2) file descriptor set overflow causes stack overflow |
|
20 May 2026 |
Remote code execution via installer Wi-Fi access point scans |
|
20 May 2026 |
Incorrect libcap_net limitation list manipulation |
Errata Notices
| Errata | Date | Topic |
|---|---|---|
16 December 2025 |
Unprivileged kernel NULL pointer dereference |
|
16 December 2025 |
bhyve(8) PCI passthru regression |
|
27 January 2026 |
devinfo output formatting regression |
|
27 January 2026 |
arm64 SVE signal context misalignment |
|
27 January 2026 |
The page fault handler fails to zero memory |
|
10 February 2026 |
Kernel panic when dumping process core on arm64 |
|
21 April 2026 |
The page fault handler fails to zero memory |
|
21 April 2026 |
Periodic timerfd(2) timers may produce incorrect results |
|
21 April 2026 |
Base packages fail to build with newer versions of libucl |
|
29 April 2026 |
Incorrect duplicate rule detection for automatic tables |
|
29 April 2026 |
Timezone database information update |
|
29 April 2026 |
TLB invalidation bug on AMD systems with INVLPGB |
|
1 May 2026 |
dhclient(8) lease validation is too strict |
|
1 May 2026 |
Source inconsistency between freebsd-update, EN/SAs, and git |
|
20 May 2026 |
freebsd-update attempts to merge a generated file |
Open Issues
-
ipfw(8) denies networking when booting a 15.0 kernel with 14.3 userland
Workaround: disable ipfw(8) or upgrade completely before rebooting ipfw(8) systems
State: open - https://bugs.freebsd.org/291562 -
devinfo(8) output format accidentally changed
Workaround: users parsing devinfo(8) must build it from a newer source
State: reverted in FreeBSD 15.0-RELEASE-p2 - https://www.nsoiwdjgsld.gq/security/advisories/FreeBSD-EN-26:01.devinfo.asc -
pkgbase(7) system upgrading from 14.3 to 15.0 is not supported
Workaround: systems installed with pkgbase(7) must backup and reinstall
State: works as intended, pkgbase(7) is an experimental preview -
FreeBSD/powerpc images do not boot on Apple G5 systems
Workaround: do not install this release on Apple G5 systems
State: fixed in main - https://bugs.freebsd.org/292341 -
loader.efi(8) has a regression preventing boot on some systems with remote serial console facilities including HPE systems
Workaround: unsethw.uart.consoleat the loader(8) prompt if it hangs and/or instant reboots when loading the kernel
State: fixed in main - https://bugs.freebsd.org/291461
Late-Breaking News
No late-breaking news.
Last modified on: May 21, 2026 by Philip Paeps