From owner-svn-doc-head@freebsd.org Thu Jun 11 15:19:55 2020
Return-Path:
The release notes for FreeBSD 11.4-RELEASE contain + “®” symbol.
The release notes for FreeBSD 11.4-RELEASE contain a summary of the changes made to the FreeBSD base system on the 11.4-STABLE development line. This document lists applicable security advisories that were issued since the last @@ -72,19 +72,25 @@ checking
Incorrect user-controlled pointer use
Kernel memory disclosure with nested jails
Multiple denial of service
Invalid mbuf(9) handling
Insufficient packet length - validation
Memory disclosure vulnerability
Errata | Date | Topic |
---|---|---|
FreeBSD-EN-19:13.mds | 24 July 2019 | System crash from Intel CPU vulnerability + validation |
FreeBSD-SA-20:13.libalias | 12 May 2020 | Memory disclosure vulnerability |
FreeBSD-SA-20:17.usb | 9 June 2020 | HID descriptor parsing + error |
Errata | Date | Topic |
---|---|---|
FreeBSD-EN-19:13.mds | 24 July 2019 | System crash from Intel CPU vulnerability mitigation |
FreeBSD-EN-19:15.libunwind | 6 August 2019 | Incorrect exception handling |
FreeBSD-EN-19:16.bhyve | 20 August 2019 | Instruction emulation improvements |
FreeBSD-EN-19:17.ipfw | 20 August 2019 | "jail" keyword fix |
FreeBSD-EN-19:18.tzdata | 23 Oct ober 2019 | Timezone database information update |
FreeBSD-EN-20:01.ssp | 28 January 2020 | Imprecise orderring of canary initialization |
FreeBSD-EN-20:02.nmount | 28 January 2020 | Invalid pointer dereference |
FreeBSD-EN-20:04.pfctl | 18 March 2020 | Missing pfctl(8) tunable |
FreeBSD-EN-20:06.ipv6 | 18 March 2020 | Incorrect checksum calculations |
FreeBSD-EN-20:07.quotad | 21 April 2020 | Regression with certain NFS servers |
This section covers changes and additions to userland - applications, contributed software, and system utilities.
The + applications, contributed software, and system utilities.
The netatalk protocol has been removed + from services(5). [r358903]
The camcontrol(8) utility has been updated to include support for Accessible Max Address Configuration (AMA). [r350801] (Sponsored by iXsystems)
The camcontrol(8) utility has been
updated to support block descriptors with the
- modepage
subcommand. [r351582]
The usbconfig(8) utility has been
+ modepage
subcommand. [r351582]
The yp(8) subsystem has been updated
+ to increase the value of YPMAXRECORD
from
+ 1M to 16M for compatibility with Linux®. [r351694]
+ (Sponsored by
+ Mellanox Technologies)
The usbconfig(8) utility has been
updated to include the detach_kernel_driver
command. [r351843]
The jot(1) utility has been updated to allow an endless stream of random data within the specified @@ -129,15 +135,34 @@ openmp, compiler-rt utilities and libc++ have been updated to version - 10.0.0. [r360822]
This section covers changes to kernel configurations, system tuning, and system control parameters that are not otherwise categorized.
This section covers changes and additions to devices and - device drivers since 11.3-RELEASE.
This section covers general hardware support for physical + device drivers since 11.3-RELEASE.
The Kerberos + GSS API has been updated + to emit deprecation warnings for algorithms marked as + "SHOULD NOT" be used in RFCs 6649 and 8429. [r351243]
The crypto(4) driver has been + updated to emit deprecation warnings when the ARC4, Blowfish, + CAST128, DES, 3DES, MD5-HMAC, and Skipjack algorithms are + used. [r351246]
The ubsec(4) driver has been marked + as deprecated, and will be removed in FreeBSD 13.0. [r361049]
The aacraid(4) driver has been + updated to version 3.2.10. [r354965]
Support for JMicron® JMB582 and + JMB585 AHCI controllers has been + added. [r359971]
This section covers general hardware support for physical machines, hypervisors, and virtualization environments, as well as hardware changes and updates that do not otherwise fit in - other sections of this document.
This section covers changes and additions to file systems + other sections of this document.
Support for Intel® Cannon Lake PCH has + been added to snd_hda(4). [r359114]
This section covers changes and additions to file systems and other storage subsystems, both local and networked.
The ZFS ZIL (ZFS intent log) maximum block size is now tunable. [r359554]