Greetings all. I am running FreeBSD 13.5-RELEASE-p10 on two systems here. The periodic daily security job alerted about a new
patch to fix a vulnerability, specifically:
I ran
the machines last night.
Today the periodic security job is still reporting the same vulnerability on both machines. A quick check with
What did I miss? I would expect patch 11 on both the userland and the kernel, so I am not sure what went wrong.
Thanks in advance for any insight.
patch to fix a vulnerability, specifically:
Code:
FreeBSD-kernel-13.5_10 is vulnerable:
FreeBSD -- Remote code execution via RPCSEC_GSS packet validation
CVE: CVE-2026-4747
WWW: https://vuxml.FreeBSD.org/freebsd/733febba-28d2-11f1-b35e-bc241121aa0a.html
I ran
freebsd-update fetch and freebsd-update install yesterday on both machines, and even rebooted one of the machines last night.
Today the periodic security job is still reporting the same vulnerability on both machines. A quick check with
freebsd-version -ku shows that the userland is now at patch level 11, where it should be, but the kernel is a patch level 10.What did I miss? I would expect patch 11 on both the userland and the kernel, so I am not sure what went wrong.
Thanks in advance for any insight.