--- title: "FreeBSD 10.1-RELEASE Errata" sidenav: download --- = FreeBSD 10.0-RELEASE Errata == Abstract This document lists errata items for FreeBSD 10.1-RELEASE, containing significant information discovered after the release or too late in the release cycle to be otherwise included in the release documentation. This information includes security advisories, as well as news relating to the software or documentation that could affect its operation or usability. An up-to-date version of this document should always be consulted before installing this version of FreeBSD. This errata document for FreeBSD 10.1-RELEASE will be maintained until the release of FreeBSD 10.2-RELEASE. === Table of Contents * <> * <> * <> * <> * <> [[intro]] == Introduction This errata document contains "late-breaking news" about FreeBSD 10.1-RELEASE Before installing this version, it is important to consult this document to learn about any post-release discoveries or problems that may already have been found and fixed. Any version of this errata document actually distributed with the release (for example, on a CDROM distribution) will be out of date by definition, but other copies are kept updated on the Internet and should be consulted as the "current errata" for this release. These other copies of the errata are located at http://www.FreeBSD.org/releases/, plus any sites which keep up-to-date mirrors of this location. Source and binary snapshots of FreeBSD 10.1-STABLE also contain up-to-date copies of this document (as of the time of the snapshot). For a list of all FreeBSD CERT security advisories, see http://www.FreeBSD.org/security/ or ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/. [[security]] == Security Advisories [width="100%",cols="40%,30%,30%",options="header",] |=== |Advisory |Date |Topic |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-14:27.stdio.asc[FreeBSD-SA-14:27.stdio] |10 December 2014 |Buffer overflow in stdio |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-14:28.file.asc[FreeBSD-SA-14:28.file] |10 December 2014 |Multiple vulnerabilities in http://www.FreeBSD.org/cgi/man.cgi?query=file&sektion=1[file(1)] and http://www.FreeBSD.org/cgi/man.cgi?query=libmagic&sektion=3[libmagic(3)] |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-14:30.unbound.asc[FreeBSD-SA-14:30.unbound] |17 December 2014 |Remote denial of service vulnerability |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-14:31.ntp.asc[FreeBSD-SA-14:31.ntp] |23 December 2014 |Multiple vulnerabilities in NTP suite |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:01.openssl.asc[FreeBSD-SA-15:01.openssl] |14 January 2015 |Multiple vulnerabilities in OpenSSL |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:02.kmem.asc[FreeBSD-SA-15:02.kmem] |27 January 2015 |SCTP kernel memory corruption and disclosure vulnerability |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:03.sctp.asc[FreeBSD-SA-15:03.sctp] |27 January 2015 |SCTP stream reset vulnerability |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:04.igmp.asc[FreeBSD-SA-15:04.igmp] |25 February 2015 |Integer overflow in IGMP protocol |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:06.openssl.asc[FreeBSD-SA-15:06.openssl] |19 March 2015 |Multiple vulnerabilities |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:07.ntp.asc[FreeBSD-SA-15:07.ntp] |7 April 2015 |Multiple vulnerabilities |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:08.bsdinstall.asc[FreeBSD-SA-15:08.bsdinstall] |7 April 2015 |Insecure default GELI key file permissions |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:09.ipv6.asc[FreeBSD-SA-15:09.ipv6] |7 April 2015 |Router advertisement Denial of Service |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:10.openssl.asc[FreeBSD-SA-15:10.openssl] |16 June 2015 |Multiple vulnerabilities |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:12.openssl.asc[FreeBSD-SA-15:12.openssl] |9 July 2015 |OpenSSL alternate chains certificate forgery vulnerability (Note: This does not affect FreeBSD 10.1-RELEASE) |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:13.tcp.asc[FreeBSD-SA-15:13.tcp] |21 July 2015 |resource exhaustion due to sessions stuck in `LAST_ACK` state. |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:14.bsdpatch.asc[FreeBSD-SA-15:14.bsdpatch] |28 July 2015 |Shell injection vulnerability |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:15.tcp.asc[FreeBSD-SA-15:15.tcp] |28 July 2015 |resource exhaustion in TCP reassembly |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:16.openssh.asc[FreeBSD-SA-15:16.openssh] |28 July 2015 |Multiple vulnerabilities |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:18.bsdpatch.asc[FreeBSD-SA-15:18.bsdpatch] |5 August 2015 |Shell injection vulnerability |https://www.FreeBSD.org/security/advisories/FreeBSD-SA-15:19.routed.asc[FreeBSD-SA-15:19.routed] |5 August 2015 |Remote denial of service vulnerability |=== [[errata]] == Errata Notices [width="100%",cols="40%,30%,30%",options="header",] |=== |Errata |Date |Topic |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-14:13.freebsd-update.asc[FreeBSD-EN-14:13.freebsd-update] |23 December 2014 |Fixed directory deletion issue in http://www.FreeBSD.org/cgi/man.cgi?query=freebsd-update&sektion=8[freebsd-update(8)] |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:01.vt.asc[FreeBSD-EN-15:01.vt] |25 February 2015 |http://www.FreeBSD.org/cgi/man.cgi?query=vt&sektion=4[vt(4)] crash with improper ioctl parameters |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:02.openssl.asc[FreeBSD-EN-15:02.openssl] |25 February 2015 |OpenSSL update |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:03.freebsd-update.asc[FreeBSD-EN-15:03.freebsd-update] |25 February 2015 |http://www.FreeBSD.org/cgi/man.cgi?query=freebsd-update&sektion=8[freebsd-update(8)] updates libraries in suboptimal order |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:04.freebsd-update.asc[FreeBSD-EN-15:04.freebsd-update] |13 May 2015 |http://www.FreeBSD.org/cgi/man.cgi?query=freebsd-update&sektion=8[freebsd-update(8)] does not ensure the previous upgrade has completed |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:05.ufs.asc[FreeBSD-EN-15:05.ufs] |13 May 2015 |Deadlock on reboot with UFS tuned with SU+J |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:06.file.asc[FreeBSD-EN-15:06.file] |9 June 2015 |Multiple denial of service issues |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:07.zfs.asc[FreeBSD-EN-15:07.zfs] |9 June 2015 |ZFS reliability improvements |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:08.sendmail.asc[FreeBSD-EN-15:08.sendmail] |30 June 2015 (revised) |Sendmail TLS/DH interoperability improvement |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:09.xlocale.asc[FreeBSD-EN-15:09.xlocale] |30 June 2015 |Fix inconsistency between locale and rune locale states |https://www.FreeBSD.org/security/advisories/FreeBSD-EN-15:10.iconv.asc[FreeBSD-EN-15:10.iconv] |30 June 2015 |Improved http://www.FreeBSD.org/cgi/man.cgi?query=iconv&sektion=3[iconv(3)] UTF-7 support |=== [[open-issues]] == Open Issues * FreeBSD/i386 10.1-RELEASE running as a guest operating system on VirtualBox can have a problem with disk I/O access. It depends on some specific hardware configuration and does not depend on a specific version of VirtualBox or host operating system. + It causes various errors and makes FreeBSD quite unstable. Although the cause is still unclear, disabling unmapped I/O works as a workaround. To disable it, choose `Escape to loader prompt` in the boot menu and enter the following lines from http://www.FreeBSD.org/cgi/man.cgi?query=loader&sektion=8[loader(8)] prompt, after an `OK`: + [.screen] ---- set vfs.unmapped_buf_allowed=0 boot ---- + Note that the following line has to be added to [.filename]`/boot/loader.conf` after a boot. It disables unmapped I/O at every boot: + [.programlisting] ---- vfs.unmapped_buf_allowed=0 ---- + [2014-04-03 update] It has been reported that instability may be present on virtual machines running on other hypervisors, such as Xen or KVM. * FreeBSD/i386 10.1-RELEASE configured with a multi-disk ZFS dataset (mirror, raidz1, raidz2, raidz3) may crash during boot when the ZFS pool mount is attempted while booting an unmodified `GENERIC` kernel. + As described in [.filename]`/usr/src/UPDATING` entry `20121223`, rebuilding the kernel with `options KSTACK_PAGES=4` has been observed to resolve the boot-time crash. This, however, is not an ideal solution for inclusion in the `GENERIC` kernel configuration, as increasing `KSTACK_PAGES` implicitly decreases available usermode threads in an environment that is already resource-starved. + Taking into account the heavy resource requirements of ZFS, in addition to the i386-specific tuning requirements for general workloads, using ZFS with the FreeBSD/i386 `GENERIC` kernel is strongly discouraged. + [.warning] *Warning*: It is extremely important to take note that, by default, http://www.FreeBSD.org/cgi/man.cgi?query=freebsd-update&sektion=8[freebsd-update(8)] will install the `GENERIC` kernel configuration, and as such, http://www.FreeBSD.org/cgi/man.cgi?query=freebsd-update&sektion=8[freebsd-update(8)] consumers are strongly encouraged to avoid FreeBSD-provided kernel binary upgrades with such configurations. + [.note] *Note*: Although there is slight change in how the crash manifests on FreeBSD/i386 between 10.0-RELEASE and 10.1-RELEASE, and given the date of the [.filename]`/usr/src/UPDATING` entry, there is no evidence suggesting this is a regression between FreeBSD 10.0-RELEASE and FreeBSD 10.1-RELEASE directly. * Due to an incompatibility between http://www.FreeBSD.org/cgi/man.cgi?query=bsdconfig&sektion=8[bsdconfig(8)] and http://www.FreeBSD.org/cgi/man.cgi?query=pkg&sektion=8[pkg(8)] version 1.3, packages included on the FreeBSD dvd installer will not be recognized by http://www.FreeBSD.org/cgi/man.cgi?query=bsdconfig&sektion=8[bsdconfig(8)]. + To install packages from the `dvd1.iso` installer, create the [.filename]`/dist` target directory, and manually mount the `dvd1.iso` ISO: + [.screen] ---- # mkdir -p /dist # mount -t cd9660 /dev/cd0 /dist ---- + [.note] *Note*: Be sure to use the correct [.filename]`/dev` device path for the `dvd1.iso` ISO installer. + Next, set `REPOS_DIR` to the path of the [.filename]`repos/` directory within the installer so http://www.FreeBSD.org/cgi/man.cgi?query=pkg&sektion=8[pkg(8)] will use the correct repository metadata. + If using http://www.FreeBSD.org/cgi/man.cgi?query=sh&sektion=1[sh(1)]: + [.screen] ---- # export REPOS_DIR=/dist/packages/repos ---- + If using http://www.FreeBSD.org/cgi/man.cgi?query=csh&sektion=1[csh(1)]: + [.screen] ---- # setenv REPOS_DIR /dist/packages/repos ---- + [.note] *Note*: Keep in mind that `REPOS_DIR` will need to be set again after the current shell session is terminated, if continuing to use the packages provided on the `dvd1.iso` installer. + Finally, bootstrap http://www.FreeBSD.org/cgi/man.cgi?query=pkg&sektion=8[pkg(8)] from the ISO, and install required packages: + [.screen] ---- # pkg bootstrap # pkg install xorg-server xorg gnome2 [...] ---- * [2015-02-06] _Affects binary upgrade users:_ The second phase of `freebsd-update install`, the phase where the running userland is upgraded, fails on systems deployed with `nss_ldap` enabled in http://www.FreeBSD.org/cgi/man.cgi?query=nsswitch.conf&sektion=5[nsswitch.conf(5)] when upgrading from 10.0-RELEASE to 10.1-RELEASE. A workaround is to disable `nss_ldap` in http://www.FreeBSD.org/cgi/man.cgi?query=nsswitch.conf&sektion=5[nsswitch.conf(5)] prior to running `freebsd-update install` to upgrade the userland, after which it can be enabled again when the upgrade process is completed. The problem is being investigated, and an Errata Notice is expected to be issued when a solution to the problem is identified. * [2015-03-31] Several reports were received regarding the QCOW2 FreeBSD virtual machine images crashing on boot. As result of this, these images have been removed from the FTP mirrors, and the hashes removed from [.filename]`CHECKSUM.SHA256` and [.filename]`CHECKSUM.MD5` in the [.filename]`VM-IMAGES/` directory on the FTP mirrors. [[late-news]] == Late-Breaking News No news.