diff --git a/website/data/security/advisories.toml b/website/data/security/advisories.toml
index 3dee86a4c6..7c3d11c7c1 100644
--- a/website/data/security/advisories.toml
+++ b/website/data/security/advisories.toml
@@ -1,3015 +1,3039 @@
# Sort advisories by year, month and day
# $FreeBSD$
+[[advisories]]
+name = "FreeBSD-SA-26:55.elf"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:54.sysvsem"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:53.ktrace"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:52.if_wg"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:51.ktimer"
+date = "2026-07-29"
+
+[[advisories]]
+name = "FreeBSD-SA-26:50.kqueue"
+date = "2026-07-29"
+
[[advisories]]
name = "FreeBSD-SA-26:49.iconv"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:48.compat32"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:47.linux"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:46.ktls"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:45.audit"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:44.posixshm"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:43.tcp"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:42.unlinkat"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:41.libalias"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:40.zfs"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:39.execve"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:38.jail"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:37.vm"
date = "2026-06-30"
[[advisories]]
name = "FreeBSD-SA-26:36.ldns"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:35.openssl"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:34.vt"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:33.unbound"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:32.elf"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:31.arm64"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:30.linux"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:29.ip6_multicast"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:28.capsicum"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:27.sound"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:26.ktls"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:25.thr"
date = "2026-06-09"
[[advisories]]
name = "FreeBSD-SA-26:24.cap_net"
date = "2026-05-20"
[[advisories]]
name = "FreeBSD-SA-26:23.bsdinstall"
date = "2026-05-20"
[[advisories]]
name = "FreeBSD-SA-26:22.libcasper"
date = "2026-05-20"
[[advisories]]
name = "FreeBSD-SA-26:21.ptrace"
date = "2026-05-20"
[[advisories]]
name = "FreeBSD-SA-26:20.fusefs"
date = "2026-05-20"
[[advisories]]
name = "FreeBSD-SA-26:19.file"
date = "2026-05-20"
[[advisories]]
name = "FreeBSD-SA-26:18.setcred"
date = "2026-05-20"
[[advisories]]
name = "FreeBSD-SA-26:17.libnv"
date = "2026-04-29"
[[advisories]]
name = "FreeBSD-SA-26:16.libnv"
date = "2026-04-29"
[[advisories]]
name = "FreeBSD-SA-26:15.dhclient"
date = "2026-04-29"
[[advisories]]
name = "FreeBSD-SA-26:14.pf"
date = "2026-04-29"
[[advisories]]
name = "FreeBSD-SA-26:13.exec"
date = "2026-04-29"
[[advisories]]
name = "FreeBSD-SA-26:12.dhclient"
date = "2026-04-29"
[[advisories]]
name = "FreeBSD-SA-26:11.amd64"
date = "2026-04-21"
[[advisories]]
name = "FreeBSD-SA-26:10.tty"
date = "2026-04-21"
[[advisories]]
name = "FreeBSD-SA-26:09.pf"
date = "2026-03-26"
[[advisories]]
name = "FreeBSD-SA-26:08.rpcsec_gss"
date = "2026-03-26"
[[advisories]]
name = "FreeBSD-SA-26:07.nvmf"
date = "2026-03-26"
[[advisories]]
name = "FreeBSD-SA-26:06.tcp"
date = "2026-03-26"
[[advisories]]
name = "FreeBSD-SA-26:05.route"
date = "2026-02-24"
[[advisories]]
name = "FreeBSD-SA-26:04.jail"
date = "2026-02-24"
[[advisories]]
name = "FreeBSD-SA-26:03.blocklistd"
date = "2026-02-10"
[[advisories]]
name = "FreeBSD-SA-26:02.jail"
date = "2026-01-27"
[[advisories]]
name = "FreeBSD-SA-26:01.openssl"
date = "2026-01-27"
[[advisories]]
name = "FreeBSD-SA-25:12.rtsold"
date = "2025-12-16"
[[advisories]]
name = "FreeBSD-SA-25:11.ipfw"
date = "2025-12-16"
[[advisories]]
name = "FreeBSD-SA-25:10.unbound"
date = "2025-11-26"
[[advisories]]
name = "FreeBSD-SA-25:09.netinet"
date = "2025-10-22"
[[advisories]]
name = "FreeBSD-SA-25:08.openssl"
date = "2025-09-30"
[[advisories]]
name = "FreeBSD-SA-25:07.libarchive"
date = "2025-08-08"
[[advisories]]
name = "FreeBSD-SA-25:06.xz"
date = "2025-07-02"
[[advisories]]
name = "FreeBSD-SA-25:05.openssh"
date = "2025-02-21"
[[advisories]]
name = "FreeBSD-SA-25:04.ktrace"
date = "2025-01-29"
[[advisories]]
name = "FreeBSD-SA-25:03.etcupdate"
date = "2025-01-29"
[[advisories]]
name = "FreeBSD-SA-25:02.fs"
date = "2025-01-29"
[[advisories]]
name = "FreeBSD-SA-25:01.openssh"
date = "2025-01-29"
[[advisories]]
name = "FreeBSD-SA-24:19.fetch"
date = "2024-10-29"
[[advisories]]
name = "FreeBSD-SA-24:18.ctl"
date = "2024-10-29"
[[advisories]]
name = "FreeBSD-SA-24:17.bhyve"
date = "2024-10-29"
[[advisories]]
name = "FreeBSD-SA-24:16.libnv"
date = "2024-09-19"
[[advisories]]
name = "FreeBSD-SA-24:15.bhyve"
date = "2024-09-19"
[[advisories]]
name = "FreeBSD-SA-24:14.umtx"
date = "2024-09-04"
[[advisories]]
name = "FreeBSD-SA-24:13.openssl"
date = "2024-09-04"
[[advisories]]
name = "FreeBSD-SA-24:12.bhyve"
date = "2024-09-04"
[[advisories]]
name = "FreeBSD-SA-24:11.ctl"
date = "2024-09-04"
[[advisories]]
name = "FreeBSD-SA-24:10.bhyve"
date = "2024-09-04"
[[advisories]]
name = "FreeBSD-SA-24:09.libnv"
date = "2024-09-04"
[[advisories]]
name = "FreeBSD-SA-24:08.openssh"
date = "2024-08-07"
[[advisories]]
name = "FreeBSD-SA-24:07.nfsclient"
date = "2024-08-07"
[[advisories]]
name = "FreeBSD-SA-24:06.ktrace"
date = "2024-08-07"
[[advisories]]
name = "FreeBSD-SA-24:05.pf"
date = "2024-08-07"
[[advisories]]
name = "FreeBSD-SA-24:04.openssh"
date = "2024-07-01"
[[advisories]]
name = "FreeBSD-SA-24:03.unbound"
date = "2024-03-28"
[[advisories]]
name = "FreeBSD-SA-24:02.tty"
date = "2024-02-14"
[[advisories]]
name = "FreeBSD-SA-24:01.bhyveload"
date = "2024-02-14"
[[advisories]]
name = "FreeBSD-SA-23:19.openssh"
date = "2023-12-19"
[[advisories]]
name = "FreeBSD-SA-23:18.nfsclient"
date = "2023-12-12"
[[advisories]]
name = "FreeBSD-SA-23:17.pf"
date = "2023-12-05"
[[advisories]]
name = "FreeBSD-SA-23:16.cap_net"
date = "2023-11-08"
[[advisories]]
name = "FreeBSD-SA-23:15.stdio"
date = "2023-11-08"
[[advisories]]
name = "FreeBSD-SA-23:14.smccc"
date = "2023-10-03"
[[advisories]]
name = "FreeBSD-SA-23:13.capsicum"
date = "2023-10-03"
[[advisories]]
name = "FreeBSD-SA-23:12.msdosfs"
date = "2023-10-03"
[[advisories]]
name = "FreeBSD-SA-23:11.wifi"
date = "2023-09-06"
[[advisories]]
name = "FreeBSD-SA-23:10.pf"
date = "2023-09-06"
[[advisories]]
name = "FreeBSD-SA-23:09.pam_krb5"
date = "2023-08-01"
[[advisories]]
name = "FreeBSD-SA-23:08.ssh"
date = "2023-08-01"
[[advisories]]
name = "FreeBSD-SA-23:07.bhyve"
date = "2023-08-01"
[[advisories]]
name = "FreeBSD-SA-23:06.ipv6"
date = "2023-08-01"
[[advisories]]
name = "FreeBSD-SA-23:05.openssh"
date = "2023-06-21"
[[advisories]]
name = "FreeBSD-SA-23:04.pam_krb5"
date = "2023-06-21"
[[advisories]]
name = "FreeBSD-SA-23:03.openssl"
date = "2023-02-16"
[[advisories]]
name = "FreeBSD-SA-23:02.openssh"
date = "2023-02-16"
[[advisories]]
name = "FreeBSD-SA-23:01.geli"
date = "2023-02-08"
[[advisories]]
name = "FreeBSD-SA-22:15.ping"
date = "2022-11-29"
[[advisories]]
name = "FreeBSD-SA-22:14.heimdal"
date = "2022-11-15"
[[advisories]]
name = "FreeBSD-SA-22:13.zlib"
date = "2022-08-30"
[[advisories]]
name = "FreeBSD-SA-22:12.lib9p"
date = "2022-08-09"
[[advisories]]
name = "FreeBSD-SA-22:11.vm"
date = "2022-08-09"
[[advisories]]
name = "FreeBSD-SA-22:10.aio"
date = "2022-08-09"
[[advisories]]
name = "FreeBSD-SA-22:09.elf"
date = "2022-08-09"
[[advisories]]
name = "FreeBSD-SA-22:08.zlib"
date = "2022-04-06"
[[advisories]]
name = "FreeBSD-SA-22:07.wifi_meshid"
date = "2022-04-06"
[[advisories]]
name = "FreeBSD-SA-22:06.ioctl"
date = "2022-04-06"
[[advisories]]
name = "FreeBSD-SA-22:05.bhyve"
date = "2022-04-06"
[[advisories]]
name = "FreeBSD-SA-22:04.netmap"
date = "2022-04-06"
[[advisories]]
name = "FreeBSD-SA-22:03.openssl"
date = "2022-03-15"
[[advisories]]
name = "FreeBSD-SA-22:02.wifi"
date = "2022-03-15"
[[advisories]]
name = "FreeBSD-SA-22:01.vt"
date = "2022-01-11"
[[advisories]]
name = "FreeBSD-SA-21:17.openssl"
date = "2021-08-24"
[[advisories]]
name = "FreeBSD-SA-21:16.openssl"
date = "2021-08-24"
[[advisories]]
name = "FreeBSD-SA-21:15.libfetch"
date = "2021-08-24"
[[advisories]]
name = "FreeBSD-SA-21:14.ggatec"
date = "2021-08-24"
[[advisories]]
name = "FreeBSD-SA-21:13.bhyve"
date = "2021-08-24"
[[advisories]]
name = "FreeBSD-SA-21:12.libradius"
date = "2021-05-26"
[[advisories]]
name = "FreeBSD-SA-21:11.smap"
date = "2021-05-26"
[[advisories]]
name = "FreeBSD-SA-21:10.jail_mount"
date = "2021-04-06"
[[advisories]]
name = "FreeBSD-SA-21:09.accept_filter"
date = "2021-04-06"
[[advisories]]
name = "FreeBSD-SA-21:08.vm"
date = "2021-04-06"
[[advisories]]
name = "FreeBSD-SA-21:07.openssl"
date = "2021-03-25"
[[advisories]]
name = "FreeBSD-SA-21:06.xen"
date = "2021-02-24"
[[advisories]]
name = "FreeBSD-SA-21:05.jail_chdir"
date = "2021-02-24"
[[advisories]]
name = "FreeBSD-SA-21:04.jail_remove"
date = "2021-02-24"
[[advisories]]
name = "FreeBSD-SA-21:03.pam_login_access"
date = "2021-02-24"
[[advisories]]
name = "FreeBSD-SA-21:02.xenoom"
date = "2021-01-29"
[[advisories]]
name = "FreeBSD-SA-21:01.fsdisclosure"
date = "2021-01-29"
[[advisories]]
name = "FreeBSD-SA-20:33.openssl"
date = "2020-12-08"
[[advisories]]
name = "FreeBSD-SA-20:32.rtsold"
date = "2020-12-01"
[[advisories]]
name = "FreeBSD-SA-20:31.icmp6"
date = "2020-12-01"
[[advisories]]
name = "FreeBSD-SA-20:30.ftpd"
date = "2020-09-15"
[[advisories]]
name = "FreeBSD-SA-20:29.bhyve_svm"
date = "2020-09-15"
[[advisories]]
name = "FreeBSD-SA-20:28.bhyve_vmcs"
date = "2020-09-15"
[[advisories]]
name = "FreeBSD-SA-20:27.ure"
date = "2020-09-15"
[[advisories]]
name = "FreeBSD-SA-20:26.dhclient"
date = "2020-09-02"
[[advisories]]
name = "FreeBSD-SA-20:25.sctp"
date = "2020-09-02"
[[advisories]]
name = "FreeBSD-SA-20:24.ipv6"
date = "2020-09-02"
[[advisories]]
name = "FreeBSD-SA-20:23.sendmsg"
date = "2020-08-05"
[[advisories]]
name = "FreeBSD-SA-20:22.sqlite"
date = "2020-08-05"
[[advisories]]
name = "FreeBSD-SA-20:21.usb_net"
date = "2020-08-05"
[[advisories]]
name = "FreeBSD-SA-20:20.ipv6"
date = "2020-07-08"
[[advisories]]
name = "FreeBSD-SA-20:19.unbound"
date = "2020-07-08"
[[advisories]]
name = "FreeBSD-SA-20:18.posix_spawnp"
date = "2020-07-08"
[[advisories]]
name = "FreeBSD-SA-20:17.usb"
date = "2020-06-09"
[[advisories]]
name = "FreeBSD-SA-20:16.cryptodev"
date = "2020-05-12"
[[advisories]]
name = "FreeBSD-SA-20:15.cryptodev"
date = "2020-05-12"
[[advisories]]
name = "FreeBSD-SA-20:14.sctp"
date = "2020-05-12"
[[advisories]]
name = "FreeBSD-SA-20:13.libalias"
date = "2020-05-12"
[[advisories]]
name = "FreeBSD-SA-20:12.libalias"
date = "2020-05-12"
[[advisories]]
name = "FreeBSD-SA-20:11.openssl"
date = "2020-04-21"
[[advisories]]
name = "FreeBSD-SA-20:10.ipfw"
date = "2020-04-21"
[[advisories]]
name = "FreeBSD-SA-20:09.ntp"
date = "2020-03-19"
[[advisories]]
name = "FreeBSD-SA-20:08.jail"
date = "2020-03-19"
[[advisories]]
name = "FreeBSD-SA-20:07.epair"
date = "2020-03-19"
[[advisories]]
name = "FreeBSD-SA-20:06.if_ixl_ioctl"
date = "2020-03-19"
[[advisories]]
name = "FreeBSD-SA-20:05.if_oce_ioctl"
date = "2020-03-19"
[[advisories]]
name = "FreeBSD-SA-20:04.tcp"
date = "2020-03-19"
[[advisories]]
name = "FreeBSD-SA-20:03.thrmisc"
date = "2020-01-28"
[[advisories]]
name = "FreeBSD-SA-20:02.ipsec"
date = "2020-01-28"
[[advisories]]
name = "FreeBSD-SA-20:01.libfetch"
date = "2020-01-28"
[[advisories]]
name = "FreeBSD-SA-19:26.mcu"
date = "2019-11-12"
[[advisories]]
name = "FreeBSD-SA-19:25.mcepsc"
date = "2019-11-12"
[[advisories]]
name = "FreeBSD-SA-19:24.mqueuefs"
date = "2019-08-20"
[[advisories]]
name = "FreeBSD-SA-19:23.midi"
date = "2019-08-20"
[[advisories]]
name = "FreeBSD-SA-19:22.mbuf"
date = "2019-08-20"
[[advisories]]
name = "FreeBSD-SA-19:21.bhyve"
date = "2019-08-06"
[[advisories]]
name = "FreeBSD-SA-19:20.bsnmp"
date = "2019-08-06"
[[advisories]]
name = "FreeBSD-SA-19:19.mldv2"
date = "2019-08-06"
[[advisories]]
name = "FreeBSD-SA-19:18.bzip2"
date = "2019-08-06"
[[advisories]]
name = "FreeBSD-SA-19:17.fd"
date = "2019-07-24"
[[advisories]]
name = "FreeBSD-SA-19:16.bhyve"
date = "2019-07-24"
[[advisories]]
name = "FreeBSD-SA-19:15.mqueuefs"
date = "2019-07-24"
[[advisories]]
name = "FreeBSD-SA-19:14.freebsd32"
date = "2019-07-24"
[[advisories]]
name = "FreeBSD-SA-19:13.pts"
date = "2019-07-24"
[[advisories]]
name = "FreeBSD-SA-19:12.telnet"
date = "2019-07-24"
[[advisories]]
name = "FreeBSD-SA-19:11.cd_ioctl"
date = "2019-07-02"
[[advisories]]
name = "FreeBSD-SA-19:10.ufs"
date = "2019-07-02"
[[advisories]]
name = "FreeBSD-SA-19:09.iconv"
date = "2019-07-02"
[[advisories]]
name = "FreeBSD-SA-19:08.rack"
date = "2019-06-19"
[[advisories]]
name = "FreeBSD-SA-19:07.mds"
date = "2019-05-14"
[[advisories]]
name = "FreeBSD-SA-19:06.pf"
date = "2019-05-14"
[[advisories]]
name = "FreeBSD-SA-19:05.pf"
date = "2019-05-14"
[[advisories]]
name = "FreeBSD-SA-19:04.ntp"
date = "2019-05-14"
[[advisories]]
name = "FreeBSD-SA-19:03.wpa"
date = "2019-05-14"
[[advisories]]
name = "FreeBSD-SA-19:02.fd"
date = "2019-02-05"
[[advisories]]
name = "FreeBSD-SA-19:01.syscall"
date = "2019-02-05"
[[advisories]]
name = "FreeBSD-SA-18:15.bootpd"
date = "2018-12-19"
[[advisories]]
name = "FreeBSD-SA-18:14.bhyve"
date = "2018-12-04"
[[advisories]]
name = "FreeBSD-SA-18:13.nfs"
date = "2018-11-27"
[[advisories]]
name = "FreeBSD-SA-18:12.elf"
date = "2018-09-12"
[[advisories]]
name = "FreeBSD-SA-18:11.hostapd"
date = "2018-08-14"
[[advisories]]
name = "FreeBSD-SA-18:10.ip"
date = "2018-08-14"
[[advisories]]
name = "FreeBSD-SA-18:09.l1tf"
date = "2018-08-14"
[[advisories]]
name = "FreeBSD-SA-18:08.tcp"
date = "2018-08-06"
[[advisories]]
name = "FreeBSD-SA-18:07.lazyfpu"
date = "2018-06-21"
[[advisories]]
name = "FreeBSD-SA-18:06.debugreg"
date = "2018-05-08"
[[advisories]]
name = "FreeBSD-SA-18:05.ipsec"
date = "2018-04-04"
[[advisories]]
name = "FreeBSD-SA-18:04.vt"
date = "2018-04-04"
[[advisories]]
name = "FreeBSD-SA-18:03.speculative_execution"
date = "2018-03-14"
[[advisories]]
name = "FreeBSD-SA-18:02.ntp"
date = "2018-03-07"
[[advisories]]
name = "FreeBSD-SA-18:01.ipsec"
date = "2018-03-07"
[[advisories]]
name = "FreeBSD-SA-17:12.openssl"
date = "2017-12-09"
[[advisories]]
name = "FreeBSD-SA-17:11.openssl"
date = "2017-11-29"
[[advisories]]
name = "FreeBSD-SA-17:10.kldstat"
date = "2017-11-15"
[[advisories]]
name = "FreeBSD-SA-17:09.shm"
date = "2017-11-15"
[[advisories]]
name = "FreeBSD-SA-17:08.ptrace"
date = "2017-11-15"
[[advisories]]
name = "FreeBSD-SA-17:07.wpa"
date = "2017-10-17"
[[advisories]]
name = "FreeBSD-SA-17:06.openssh"
date = "2017-08-10"
[[advisories]]
name = "FreeBSD-SA-17:05.heimdal"
date = "2017-07-12"
[[advisories]]
name = "FreeBSD-SA-17:04.ipfilter"
date = "2017-04-27"
[[advisories]]
name = "FreeBSD-SA-17:03.ntp"
date = "2017-04-12"
[[advisories]]
name = "FreeBSD-SA-17:02.openssl"
date = "2017-02-23"
[[advisories]]
name = "FreeBSD-SA-17:01.openssh"
date = "2017-01-11"
[[advisories]]
name = "FreeBSD-SA-16:39.ntp"
date = "2016-12-22"
[[advisories]]
name = "FreeBSD-SA-16:38.bhyve"
date = "2016-12-06"
[[advisories]]
name = "FreeBSD-SA-16:37.libc"
date = "2016-12-06"
[[advisories]]
name = "FreeBSD-SA-16:36.telnetd"
date = "2016-12-06"
[[advisories]]
name = "FreeBSD-SA-16:35.openssl"
date = "2016-11-02"
[[advisories]]
name = "FreeBSD-SA-16:34.bind"
date = "2016-11-02"
[[advisories]]
name = "FreeBSD-SA-16:33.openssh"
date = "2016-11-02"
[[advisories]]
name = "FreeBSD-SA-16:32.bhyve"
date = "2016-10-25"
[[advisories]]
name = "FreeBSD-SA-16:31.libarchive"
date = "2016-10-10"
[[advisories]]
name = "FreeBSD-SA-16:30.portsnap"
date = "2016-10-10"
[[advisories]]
name = "FreeBSD-SA-16:29.bspatch"
date = "2016-10-10"
[[advisories]]
name = "FreeBSD-SA-16:28.bind"
date = "2016-10-10"
[[advisories]]
name = "FreeBSD-SA-16:27.openssl"
date = "2016-10-10"
[[advisories]]
name = "FreeBSD-SA-16:26.openssl"
date = "2016-09-23"
[[advisories]]
name = "FreeBSD-SA-16:25.bspatch"
date = "2016-07-25"
[[advisories]]
name = "FreeBSD-SA-16:24.ntp"
date = "2016-06-04"
[[advisories]]
name = "FreeBSD-SA-16:23.libarchive"
date = "2016-05-31"
[[advisories]]
name = "FreeBSD-SA-16:22.libarchive"
date = "2016-05-31"
[[advisories]]
name = "FreeBSD-SA-16:21.43bsd"
date = "2016-05-31"
[[advisories]]
name = "FreeBSD-SA-16:20.linux"
date = "2016-05-31"
[[advisories]]
name = "FreeBSD-SA-16:19.sendmsg"
date = "2016-05-17"
[[advisories]]
name = "FreeBSD-SA-16:18.atkbd"
date = "2016-05-17"
[[advisories]]
name = "FreeBSD-SA-16:17.openssl"
date = "2016-05-04"
[[advisories]]
name = "FreeBSD-SA-16:16.ntp"
date = "2016-04-29"
[[advisories]]
name = "FreeBSD-SA-16:15.sysarch"
date = "2016-03-16"
[[advisories]]
name = "FreeBSD-SA-16:14.openssh"
date = "2016-03-16"
[[advisories]]
name = "FreeBSD-SA-16:13.bind"
date = "2016-03-10"
[[advisories]]
name = "FreeBSD-SA-16:12.openssl"
date = "2016-03-10"
[[advisories]]
name = "FreeBSD-SA-16:11.openssl"
date = "2016-01-30"
[[advisories]]
name = "FreeBSD-SA-16:10.linux"
date = "2016-01-27"
[[advisories]]
name = "FreeBSD-SA-16:09.ntp"
date = "2016-01-27"
[[advisories]]
name = "FreeBSD-SA-16:08.bind"
date = "2016-01-27"
[[advisories]]
name = "FreeBSD-SA-16:07.openssh"
date = "2016-01-14"
[[advisories]]
name = "FreeBSD-SA-16:06.bsnmpd"
date = "2016-01-14"
[[advisories]]
name = "FreeBSD-SA-16:05.tcp"
date = "2016-01-14"
[[advisories]]
name = "FreeBSD-SA-16:04.linux"
date = "2016-01-14"
[[advisories]]
name = "FreeBSD-SA-16:03.linux"
date = "2016-01-14"
[[advisories]]
name = "FreeBSD-SA-16:02.ntp"
date = "2016-01-14"
[[advisories]]
name = "FreeBSD-SA-16:01.sctp"
date = "2016-01-14"
[[advisories]]
name = "FreeBSD-SA-15:27.bind"
date = "2015-12-16"
[[advisories]]
name = "FreeBSD-SA-15:26.openssl"
date = "2015-12-06"
[[advisories]]
name = "FreeBSD-SA-15:25.ntp"
date = "2015-10-26"
[[advisories]]
name = "FreeBSD-SA-15:24.rpcbind"
date = "2015-09-29"
[[advisories]]
name = "FreeBSD-SA-15:23.bind"
date = "2015-09-02"
[[advisories]]
name = "FreeBSD-SA-15:22.openssh"
date = "2015-08-25"
[[advisories]]
name = "FreeBSD-SA-15:21.amd64"
date = "2015-08-25"
[[advisories]]
name = "FreeBSD-SA-15:20.expat"
date = "2015-08-18"
[[advisories]]
name = "FreeBSD-SA-15:19.routed"
date = "2015-08-05"
[[advisories]]
name = "FreeBSD-SA-15:18.bsdpatch"
date = "2015-08-05"
[[advisories]]
name = "FreeBSD-SA-15:17.bind"
date = "2015-07-28"
[[advisories]]
name = "FreeBSD-SA-15:16.openssh"
date = "2015-07-28"
[[advisories]]
name = "FreeBSD-SA-15:15.tcp"
date = "2015-07-28"
[[advisories]]
name = "FreeBSD-SA-15:14.bsdpatch"
date = "2015-07-28"
[[advisories]]
name = "FreeBSD-SA-15:13.tcp"
date = "2015-07-21"
[[advisories]]
name = "FreeBSD-SA-15:12.openssl"
date = "2015-07-09"
[[advisories]]
name = "FreeBSD-SA-15:11.bind"
date = "2015-07-07"
[[advisories]]
name = "FreeBSD-SA-15:10.openssl"
date = "2015-06-12"
[[advisories]]
name = "FreeBSD-SA-15:09.ipv6"
date = "2015-04-07"
[[advisories]]
name = "FreeBSD-SA-15:08.bsdinstall"
date = "2015-04-07"
[[advisories]]
name = "FreeBSD-SA-15:07.ntp"
date = "2015-04-07"
[[advisories]]
name = "FreeBSD-SA-15:06.openssl"
date = "2015-03-19"
[[advisories]]
name = "FreeBSD-SA-15:05.bind"
date = "2015-02-25"
[[advisories]]
name = "FreeBSD-SA-15:04.igmp"
date = "2015-02-25"
[[advisories]]
name = "FreeBSD-SA-15:03.sctp"
date = "2015-01-27"
[[advisories]]
name = "FreeBSD-SA-15:02.kmem"
date = "2015-01-27"
[[advisories]]
name = "FreeBSD-SA-15:01.openssl"
date = "2015-01-14"
[[advisories]]
name = "FreeBSD-SA-14:31.ntp"
date = "2014-12-23"
[[advisories]]
name = "FreeBSD-SA-14:30.unbound"
date = "2014-12-17"
[[advisories]]
name = "FreeBSD-SA-14:29.bind"
date = "2014-12-10"
[[advisories]]
name = "FreeBSD-SA-14:28.file"
date = "2014-12-10"
[[advisories]]
name = "FreeBSD-SA-14:27.stdio"
date = "2014-12-10"
[[advisories]]
name = "FreeBSD-SA-14:26.ftp"
date = "2014-11-04"
[[advisories]]
name = "FreeBSD-SA-14:25.setlogin"
date = "2014-11-04"
[[advisories]]
name = "FreeBSD-SA-14:24.sshd"
date = "2014-11-04"
[[advisories]]
name = "FreeBSD-SA-14:23.openssl"
date = "2014-10-21"
[[advisories]]
name = "FreeBSD-SA-14:22.namei"
date = "2014-10-21"
[[advisories]]
name = "FreeBSD-SA-14:21.routed"
date = "2014-10-21"
[[advisories]]
name = "FreeBSD-SA-14:20.rtsold"
date = "2014-10-21"
[[advisories]]
name = "FreeBSD-SA-14:19.tcp"
date = "2014-09-16"
[[advisories]]
name = "FreeBSD-SA-14:18.openssl"
date = "2014-09-09"
[[advisories]]
name = "FreeBSD-SA-14:17.kmem"
date = "2014-07-08"
[[advisories]]
name = "FreeBSD-SA-14:16.file"
date = "2014-06-24"
[[advisories]]
name = "FreeBSD-SA-14:15.iconv"
date = "2014-06-24"
[[advisories]]
name = "FreeBSD-SA-14:14.openssl"
date = "2014-06-05"
[[advisories]]
name = "FreeBSD-SA-14:13.pam"
date = "2014-06-03"
[[advisories]]
name = "FreeBSD-SA-14:12.ktrace"
date = "2014-06-03"
[[advisories]]
name = "FreeBSD-SA-14:11.sendmail"
date = "2014-06-03"
[[advisories]]
name = "FreeBSD-SA-14:10.openssl"
date = "2014-05-13"
[[advisories]]
name = "FreeBSD-SA-14:09.openssl"
date = "2014-04-30"
[[advisories]]
name = "FreeBSD-SA-14:08.tcp"
date = "2014-04-30"
[[advisories]]
name = "FreeBSD-SA-14:07.devfs"
date = "2014-04-30"
[[advisories]]
name = "FreeBSD-SA-14:06.openssl"
date = "2014-04-08"
[[advisories]]
name = "FreeBSD-SA-14:05.nfsserver"
date = "2014-04-08"
[[advisories]]
name = "FreeBSD-SA-14:04.bind"
date = "2014-01-14"
[[advisories]]
name = "FreeBSD-SA-14:03.openssl"
date = "2014-01-14"
[[advisories]]
name = "FreeBSD-SA-14:02.ntpd"
date = "2014-01-14"
[[advisories]]
name = "FreeBSD-SA-14:01.bsnmpd"
date = "2014-01-14"
[[advisories]]
name = "FreeBSD-SA-13:14.openssh"
date = "2013-11-19"
[[advisories]]
name = "FreeBSD-SA-13:13.nullfs"
date = "2013-09-10"
[[advisories]]
name = "FreeBSD-SA-13:12.ifioctl"
date = "2013-09-10"
[[advisories]]
name = "FreeBSD-SA-13:11.sendfile"
date = "2013-09-10"
[[advisories]]
name = "FreeBSD-SA-13:10.sctp"
date = "2013-08-22"
[[advisories]]
name = "FreeBSD-SA-13:09.ip_multicast"
date = "2013-08-22"
[[advisories]]
name = "FreeBSD-SA-13:08.nfsserver"
date = "2013-07-26"
[[advisories]]
name = "FreeBSD-SA-13:07.bind"
date = "2013-07-26"
[[advisories]]
name = "FreeBSD-SA-13:06.mmap"
date = "2013-06-18"
[[advisories]]
name = "FreeBSD-SA-13:05.nfsserver"
date = "2013-04-29"
[[advisories]]
name = "FreeBSD-SA-13:04.bind"
date = "2013-04-02"
[[advisories]]
name = "FreeBSD-SA-13:03.openssl"
date = "2013-04-02"
[[advisories]]
name = "FreeBSD-SA-13:02.libc"
date = "2013-02-19"
[[advisories]]
name = "FreeBSD-SA-13:01.bind"
date = "2013-02-19"
[[advisories]]
name = "FreeBSD-SA-12:08.linux"
date = "2012-11-22"
[[advisories]]
name = "FreeBSD-SA-12:07.hostapd"
date = "2012-11-22"
[[advisories]]
name = "FreeBSD-SA-12:06.bind"
date = "2012-11-22"
[[advisories]]
name = "FreeBSD-SA-12:05.bind"
date = "2012-08-06"
[[advisories]]
name = "FreeBSD-SA-12:04.sysret"
date = "2012-06-12"
[[advisories]]
name = "FreeBSD-SA-12:03.bind"
date = "2012-06-12"
[[advisories]]
name = "FreeBSD-SA-12:02.crypt"
date = "2012-05-30"
[[advisories]]
name = "FreeBSD-SA-12:01.openssl"
date = "2012-05-30"
[[advisories]]
name = "FreeBSD-SA-11:10.pam"
date = "2011-12-23"
[[advisories]]
name = "FreeBSD-SA-11:09.pam_ssh"
date = "2011-12-23"
[[advisories]]
name = "FreeBSD-SA-11:08.telnetd"
date = "2011-12-23"
[[advisories]]
name = "FreeBSD-SA-11:07.chroot"
date = "2011-12-23"
[[advisories]]
name = "FreeBSD-SA-11:06.bind"
date = "2011-12-23"
[[advisories]]
name = "FreeBSD-SA-11:05.unix"
date = "2011-09-28"
[[advisories]]
name = "FreeBSD-SA-11:04.compress"
date = "2011-09-28"
[[advisories]]
name = "FreeBSD-SA-11:03.bind"
date = "2011-09-28"
[[advisories]]
name = "FreeBSD-SA-11:02.bind"
date = "2011-05-28"
[[advisories]]
name = "FreeBSD-SA-11:01.mountd"
date = "2011-04-20"
[[advisories]]
name = "FreeBSD-SA-10:10.openssl"
date = "2010-11-29"
[[advisories]]
name = "FreeBSD-SA-10:09.pseudofs"
date = "2010-11-10"
[[advisories]]
name = "FreeBSD-SA-10:08.bzip2"
date = "2010-09-20"
[[advisories]]
name = "FreeBSD-SA-10:07.mbuf"
date = "2010-07-13"
[[advisories]]
name = "FreeBSD-SA-10:06.nfsclient"
date = "2010-05-27"
[[advisories]]
name = "FreeBSD-SA-10:05.opie"
date = "2010-05-27"
[[advisories]]
name = "FreeBSD-SA-10:04.jail"
date = "2010-05-27"
[[advisories]]
name = "FreeBSD-SA-10:03.zfs"
date = "2010-01-06"
[[advisories]]
name = "FreeBSD-SA-10:02.ntpd"
date = "2010-01-06"
[[advisories]]
name = "FreeBSD-SA-10:01.bind"
date = "2010-01-06"
[[advisories]]
name = "FreeBSD-SA-09:17.freebsd-update"
date = "2009-12-03"
[[advisories]]
name = "FreeBSD-SA-09:16.rtld"
date = "2009-12-03"
[[advisories]]
name = "FreeBSD-SA-09:15.ssl"
date = "2009-12-03"
[[advisories]]
name = "FreeBSD-SA-09:14.devfs"
date = "2009-10-02"
[[advisories]]
name = "FreeBSD-SA-09:13.pipe"
date = "2009-10-02"
[[advisories]]
name = "FreeBSD-SA-09:12.bind"
date = "2009-07-29"
[[advisories]]
name = "FreeBSD-SA-09:11.ntpd"
date = "2009-06-10"
[[advisories]]
name = "FreeBSD-SA-09:10.ipv6"
date = "2009-06-10"
[[advisories]]
name = "FreeBSD-SA-09:09.pipe"
date = "2009-06-10"
[[advisories]]
name = "FreeBSD-SA-09:08.openssl"
date = "2009-04-22"
[[advisories]]
name = "FreeBSD-SA-09:07.libc"
date = "2009-04-22"
[[advisories]]
name = "FreeBSD-SA-09:06.ktimer"
date = "2009-03-23"
[[advisories]]
name = "FreeBSD-SA-09:05.telnetd"
date = "2009-02-16"
[[advisories]]
name = "FreeBSD-SA-09:04.bind"
date = "2009-01-13"
[[advisories]]
name = "FreeBSD-SA-09:03.ntpd"
date = "2009-01-13"
[[advisories]]
name = "FreeBSD-SA-09:02.openssl"
date = "2009-01-07"
[[advisories]]
name = "FreeBSD-SA-09:01.lukemftpd"
date = "2009-01-07"
[[advisories]]
name = "FreeBSD-SA-08:13.protosw"
date = "2008-12-23"
[[advisories]]
name = "FreeBSD-SA-08:12.ftpd"
date = "2008-12-23"
[[advisories]]
name = "FreeBSD-SA-08:11.arc4random"
date = "2008-11-24"
[[advisories]]
name = "FreeBSD-SA-08:10.nd6"
date = "2008-10-02"
[[advisories]]
name = "FreeBSD-SA-08:09.icmp6"
date = "2008-09-03"
[[advisories]]
name = "FreeBSD-SA-08:08.nmount"
date = "2008-09-03"
[[advisories]]
name = "FreeBSD-SA-08:07.amd64"
date = "2008-09-03"
[[advisories]]
name = "FreeBSD-SA-08:06.bind"
date = "2008-07-13"
[[advisories]]
name = "FreeBSD-SA-08:05.openssh"
date = "2008-04-17"
[[advisories]]
name = "FreeBSD-SA-08:04.ipsec"
date = "2008-02-14"
[[advisories]]
name = "FreeBSD-SA-08:03.sendfile"
date = "2008-02-14"
[[advisories]]
name = "FreeBSD-SA-08:02.libc"
date = "2008-01-14"
[[advisories]]
name = "FreeBSD-SA-08:01.pty"
date = "2008-01-14"
[[advisories]]
name = "FreeBSD-SA-07:10.gtar"
date = "2007-11-29"
[[advisories]]
name = "FreeBSD-SA-07:09.random"
date = "2007-11-29"
[[advisories]]
name = "FreeBSD-SA-07:08.openssl"
date = "2007-10-03"
[[advisories]]
name = "FreeBSD-SA-07:07.bind"
date = "2007-08-01"
[[advisories]]
name = "FreeBSD-SA-07:06.tcpdump"
date = "2007-08-01"
[[advisories]]
name = "FreeBSD-SA-07:05.libarchive"
date = "2007-07-12"
[[advisories]]
name = "FreeBSD-SA-07:04.file"
date = "2007-05-23"
[[advisories]]
name = "FreeBSD-SA-07:03.ipv6"
date = "2007-04-26"
[[advisories]]
name = "FreeBSD-SA-07:02.bind"
date = "2007-02-09"
[[advisories]]
name = "FreeBSD-SA-07:01.jail"
date = "2007-01-11"
[[advisories]]
name = "FreeBSD-SA-06:26.gtar"
date = "2006-12-06"
[[advisories]]
name = "FreeBSD-SA-06:25.kmem"
date = "2006-12-06"
[[advisories]]
name = "FreeBSD-SA-06:24.libarchive"
date = "2006-11-08"
[[advisories]]
name = "FreeBSD-SA-06:22.openssh"
date = "2006-09-30"
[[advisories]]
name = "FreeBSD-SA-06:23.openssl"
date = "2006-09-28"
[[advisories]]
name = "FreeBSD-SA-06:21.gzip"
date = "2006-09-19"
[[advisories]]
name = "FreeBSD-SA-06:20.bind"
date = "2006-09-06"
[[advisories]]
name = "FreeBSD-SA-06:19.openssl"
date = "2006-09-06"
[[advisories]]
name = "FreeBSD-SA-06:18.ppp"
date = "2006-08-23"
[[advisories]]
name = "FreeBSD-SA-06:17.sendmail"
date = "2006-06-14"
[[advisories]]
name = "FreeBSD-SA-06:16.smbfs"
date = "2006-05-31"
[[advisories]]
name = "FreeBSD-SA-06:15.ypserv"
date = "2006-05-31"
[[advisories]]
name = "FreeBSD-SA-06:14.fpu"
date = "2006-04-19"
[[advisories]]
name = "FreeBSD-SA-06:13.sendmail"
date = "2006-03-22"
[[advisories]]
name = "FreeBSD-SA-06:12.opie"
date = "2006-03-22"
[[advisories]]
name = "FreeBSD-SA-06:11.ipsec"
date = "2006-03-22"
[[advisories]]
name = "FreeBSD-SA-06:10.nfs"
date = "2006-03-01"
[[advisories]]
name = "FreeBSD-SA-06:09.openssh"
date = "2006-03-01"
[[advisories]]
name = "FreeBSD-SA-06:08.sack"
date = "2006-02-01"
[[advisories]]
name = "FreeBSD-SA-06:07.pf"
date = "2006-01-25"
[[advisories]]
name = "FreeBSD-SA-06:06.kmem"
date = "2006-01-25"
[[advisories]]
name = "FreeBSD-SA-06:05.80211"
date = "2006-01-18"
[[advisories]]
name = "FreeBSD-SA-06:04.ipfw"
date = "2006-01-11"
[[advisories]]
name = "FreeBSD-SA-06:03.cpio"
date = "2006-01-11"
[[advisories]]
name = "FreeBSD-SA-06:02.ee"
date = "2006-01-11"
[[advisories]]
name = "FreeBSD-SA-06:01.texindex"
date = "2006-01-11"
[[advisories]]
name = "FreeBSD-SA-05:21.openssl"
date = "2005-10-11"
[[advisories]]
name = "FreeBSD-SA-05:20.cvsbug"
date = "2005-09-07"
[[advisories]]
name = "FreeBSD-SA-05:19.ipsec"
date = "2005-07-27"
[[advisories]]
name = "FreeBSD-SA-05:18.zlib"
date = "2005-07-27"
[[advisories]]
name = "FreeBSD-SA-05:17.devfs"
date = "2005-07-20"
[[advisories]]
name = "FreeBSD-SA-05:16.zlib"
date = "2005-07-06"
[[advisories]]
name = "FreeBSD-SA-05:15.tcp"
date = "2005-06-29"
[[advisories]]
name = "FreeBSD-SA-05:14.bzip2"
date = "2005-06-29"
[[advisories]]
name = "FreeBSD-SA-05:13.ipfw"
date = "2005-06-29"
[[advisories]]
name = "FreeBSD-SA-05:12.bind9"
date = "2005-06-09"
[[advisories]]
name = "FreeBSD-SA-05:11.gzip"
date = "2005-06-09"
[[advisories]]
name = "FreeBSD-SA-05:10.tcpdump"
date = "2005-06-09"
[[advisories]]
name = "FreeBSD-SA-05:09.htt"
date = "2005-05-13"
[[advisories]]
name = "FreeBSD-SA-05:08.kmem"
date = "2005-05-06"
[[advisories]]
name = "FreeBSD-SA-05:07.ldt"
date = "2005-05-06"
[[advisories]]
name = "FreeBSD-SA-05:06.iir"
date = "2005-05-06"
[[advisories]]
name = "FreeBSD-SA-05:05.cvs"
date = "2005-04-22"
[[advisories]]
name = "FreeBSD-SA-05:04.ifconf"
date = "2005-04-15"
[[advisories]]
name = "FreeBSD-SA-05:03.amd64"
date = "2005-04-06"
[[advisories]]
name = "FreeBSD-SA-05:02.sendfile"
date = "2005-04-04"
[[advisories]]
name = "FreeBSD-SA-05:01.telnet"
date = "2005-03-28"
[[advisories]]
name = "FreeBSD-SA-04:17.procfs"
date = "2004-12-01"
[[advisories]]
name = "FreeBSD-SA-04:16.fetch"
date = "2004-11-18"
[[advisories]]
name = "FreeBSD-SA-04:15.syscons"
date = "2004-10-04"
[[advisories]]
name = "FreeBSD-SA-04:14.cvs"
date = "2004-09-19"
[[advisories]]
name = "FreeBSD-SA-04:13.linux"
date = "2004-06-30"
[[advisories]]
name = "FreeBSD-SA-04:12.jailroute"
date = "2004-06-07"
[[advisories]]
name = "FreeBSD-SA-04:11.msync"
date = "2004-05-19"
[[advisories]]
name = "FreeBSD-SA-04:10.cvs"
date = "2004-05-19"
[[advisories]]
name = "FreeBSD-SA-04:09.kadmind"
date = "2004-05-05"
[[advisories]]
name = "FreeBSD-SA-04:08.heimdal"
date = "2004-05-05"
[[advisories]]
name = "FreeBSD-SA-04:07.cvs"
date = "2004-04-15"
[[advisories]]
name = "FreeBSD-SA-04:06.ipv6"
date = "2004-03-29"
[[advisories]]
name = "FreeBSD-SA-04:05.openssl"
date = "2004-03-17"
[[advisories]]
name = "FreeBSD-SA-04:04.tcp"
date = "2004-03-02"
[[advisories]]
name = "FreeBSD-SA-04:03.jail"
date = "2004-02-25"
[[advisories]]
name = "FreeBSD-SA-04:02.shmat"
date = "2004-02-05"
[[advisories]]
name = "FreeBSD-SA-04:01.mksnap_ffs"
date = "2004-01-30"
[[advisories]]
name = "FreeBSD-SA-03:19.bind"
date = "2003-11-28"
[[advisories]]
name = "FreeBSD-SA-03:15.openssh"
date = "2003-10-05"
[[advisories]]
name = "FreeBSD-SA-03:18.openssl"
date = "2003-10-03"
[[advisories]]
name = "FreeBSD-SA-03:17.procfs"
date = "2003-10-03"
[[advisories]]
name = "FreeBSD-SA-03:16.filedesc"
date = "2003-10-02"
[[advisories]]
name = "FreeBSD-SA-03:14.arp"
date = "2003-09-23"
[[advisories]]
name = "FreeBSD-SA-03:13.sendmail"
date = "2003-09-17"
[[advisories]]
name = "FreeBSD-SA-03:12.openssh"
date = "2003-09-16"
[[advisories]]
name = "FreeBSD-SA-03:11.sendmail"
date = "2003-08-26"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1170"
[[advisories]]
name = "FreeBSD-SA-03:10.ibcs2"
date = "2003-08-10"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1164"
[[advisories]]
name = "FreeBSD-SA-03:09.signal"
date = "2003-08-10"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1163"
[[advisories]]
name = "FreeBSD-SA-03:08.realpath"
date = "2003-08-03"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1158"
[[advisories]]
name = "FreeBSD-SN-03:02"
date = "2003-04-08"
[[advisories]]
name = "FreeBSD-SN-03:01"
date = "2003-04-07"
[[advisories]]
name = "FreeBSD-SA-03:07.sendmail"
date = "2003-03-30"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1122"
[[advisories]]
name = "FreeBSD-SA-03:06.openssl"
date = "2003-03-21"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1118"
[[advisories]]
name = "FreeBSD-SA-03:05.xdr"
date = "2003-03-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1117"
[[advisories]]
name = "FreeBSD-SA-03:04.sendmail"
date = "2003-03-03"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1112"
[[advisories]]
name = "FreeBSD-SA-03:03.syncookies"
date = "2003-02-24"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1106"
[[advisories]]
name = "FreeBSD-SA-03:02.openssl"
date = "2003-02-24"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1105"
[[advisories]]
name = "FreeBSD-SA-03:01.cvs"
date = "2003-02-04"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1100"
[[advisories]]
name = "FreeBSD-SA-02:44.filedesc"
date = "2003-01-07"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1090"
[[advisories]]
name = "FreeBSD-SA-02:43.bind"
date = "2002-11-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1084"
[[advisories]]
name = "FreeBSD-SA-02:41.smrsh"
date = "2002-11-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1082"
[[advisories]]
name = "FreeBSD-SA-02:42.resolv"
date = "2002-11-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1083"
[[advisories]]
name = "FreeBSD-SA-02:40.kadmind"
date = "2002-11-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1081"
[[advisories]]
name = "FreeBSD-SN-02:06"
date = "2002-10-10"
[[advisories]]
name = "FreeBSD-SA-02:39.libkvm"
date = "2002-09-16"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1051"
[[advisories]]
name = "FreeBSD-SN-02:05"
date = "2002-08-28"
[[advisories]]
name = "FreeBSD-SA-02:38.signed-error"
date = "2002-08-19"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1041"
[[advisories]]
name = "FreeBSD-SA-02:37.kqueue"
date = "2002-08-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1033"
[[advisories]]
name = "FreeBSD-SA-02:36.nfs"
date = "2002-08-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1032"
[[advisories]]
name = "FreeBSD-SA-02:35.ffs"
date = "2002-08-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1031"
[[advisories]]
name = "FreeBSD-SA-02:33.openssl"
date = "2002-08-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1023"
[[advisories]]
name = "FreeBSD-SA-02:34.rpc"
date = "2002-08-01"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1024"
[[advisories]]
name = "FreeBSD-SA-02:32.pppd"
date = "2002-07-31"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1022"
[[advisories]]
name = "FreeBSD-SA-02:31.openssh"
date = "2002-07-15"
[[advisories]]
name = "FreeBSD-SA-02:30.ktrace"
date = "2002-07-12"
[[advisories]]
name = "FreeBSD-SA-02:29.tcpdump"
date = "2002-07-12"
[[advisories]]
name = "FreeBSD-SA-02:28.resolv"
date = "2002-06-26"
[[advisories]]
name = "FreeBSD-SN-02:04"
date = "2002-06-19"
[[advisories]]
name = "FreeBSD-SA-02:27.rc"
date = "2002-05-29"
[[advisories]]
name = "FreeBSD-SA-02:26.accept"
date = "2002-05-29"
[[advisories]]
name = "FreeBSD-SN-02:03"
date = "2002-05-28"
[[advisories]]
name = "FreeBSD-SA-02:25.bzip2"
date = "2002-05-20"
[[advisories]]
name = "FreeBSD-SA-02:24.k5su"
date = "2002-05-20"
[[advisories]]
name = "FreeBSD-SN-02:02"
date = "2002-05-13"
[[advisories]]
name = "FreeBSD-SA-02:23.stdio"
date = "2002-04-22"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/1021"
[[advisories]]
name = "FreeBSD-SA-02:22.mmap"
date = "2002-04-18"
[[advisories]]
name = "FreeBSD-SA-02:21.tcpip"
date = "2002-04-17"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/980"
[[advisories]]
name = "FreeBSD-SA-02:20.syncache"
date = "2002-04-16"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/979"
[[advisories]]
name = "FreeBSD-SN-02:01"
date = "2002-03-30"
[[advisories]]
name = "FreeBSD-SA-02:19.squid"
date = "2002-03-26"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/960"
[[advisories]]
name = "FreeBSD-SA-02:18.zlib"
date = "2002-03-18"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/978"
[[advisories]]
name = "FreeBSD-SA-02:17.mod_frontpage"
date = "2002-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/954"
[[advisories]]
name = "FreeBSD-SA-02:16.netscape"
date = "2002-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/953"
[[advisories]]
name = "FreeBSD-SA-02:15.cyrus-sasl"
date = "2002-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/952"
[[advisories]]
name = "FreeBSD-SA-02:14.pam-pgsql"
date = "2002-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/951"
[[advisories]]
name = "FreeBSD-SA-02:13.openssh"
date = "2002-03-07"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/945"
[[advisories]]
name = "FreeBSD-SA-02:12.squid"
date = "2002-02-21"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/938"
[[advisories]]
name = "FreeBSD-SA-02:11.snmp"
date = "2002-02-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/936"
[[advisories]]
name = "FreeBSD-SA-02:10.rsync"
date = "2002-02-06"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/928"
[[advisories]]
name = "FreeBSD-SA-02:09.fstatfs"
date = "2002-02-06"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/927"
[[advisories]]
name = "FreeBSD-SA-02:08.exec"
date = "2002-01-24"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/923"
[[advisories]]
name = "FreeBSD-SA-02:07.k5su"
date = "2002-01-18"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/912"
[[advisories]]
name = "FreeBSD-SA-02:06.sudo"
date = "2002-01-16"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/909"
[[advisories]]
name = "FreeBSD-SA-02:05.pine"
date = "2002-01-04"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/894"
[[advisories]]
name = "FreeBSD-SA-02:04.mutt"
date = "2002-01-04"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/893"
[[advisories]]
name = "FreeBSD-SA-02:03.mod_auth_pgsql"
date = "2002-01-04"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/892"
[[advisories]]
name = "FreeBSD-SA-02:02.pw"
date = "2002-01-04"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/891"
[[advisories]]
name = "FreeBSD-SA-02:01.pkg_add"
date = "2002-01-04"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/898"
[[advisories]]
name = "FreeBSD-SA-01:64.wu-ftpd"
date = "2001-12-04"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/870"
[[advisories]]
name = "FreeBSD-SA-01:63.openssh"
date = "2001-12-02"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/871"
[[advisories]]
name = "FreeBSD-SA-01:62.uucp"
date = "2001-10-08"
[[advisories]]
name = "FreeBSD-SA-01:61.squid"
date = "2001-10-08"
[[advisories]]
name = "FreeBSD-SA-01:60.procmail"
date = "2001-09-24"
[[advisories]]
name = "FreeBSD-SA-01:59.rmuser"
date = "2001-09-04"
[[advisories]]
name = "FreeBSD-SA-01:58.lpd"
date = "2001-08-30"
[[advisories]]
name = "FreeBSD-SA-01:57.sendmail"
date = "2001-08-27"
[[advisories]]
name = "FreeBSD-SA-01:56.tcp_wrappers"
date = "2001-08-23"
[[advisories]]
name = "FreeBSD-SA-01:55.procfs"
date = "2001-08-21"
[[advisories]]
name = "FreeBSD-SA-01:54.ports-telnetd"
date = "2001-08-20"
[[advisories]]
name = "FreeBSD-SA-01:53.ipfw"
date = "2001-08-17"
[[advisories]]
name = "FreeBSD-SA-01:52.fragment"
date = "2001-08-06"
[[advisories]]
name = "FreeBSD-SA-01:51.openssl"
date = "2001-07-30"
[[advisories]]
name = "FreeBSD-SA-01:50.windowmaker"
date = "2001-07-27"
[[advisories]]
name = "FreeBSD-SA-01:49.telnetd"
date = "2001-07-23"
[[advisories]]
name = "FreeBSD-SA-01:48.tcpdump"
date = "2001-07-17"
[[advisories]]
name = "FreeBSD-SA-01:47.xinetd"
date = "2001-07-10"
[[advisories]]
name = "FreeBSD-SA-01:46.w3m"
date = "2001-07-10"
[[advisories]]
name = "FreeBSD-SA-01:45.samba"
date = "2001-07-10"
[[advisories]]
name = "FreeBSD-SA-01:44.gnupg"
date = "2001-07-10"
[[advisories]]
name = "FreeBSD-SA-01:43.fetchmail"
date = "2001-07-10"
[[advisories]]
name = "FreeBSD-SA-01:42.signal"
date = "2001-07-10"
[[advisories]]
name = "FreeBSD-SA-01:41.hanterm"
date = "2001-07-09"
[[advisories]]
name = "FreeBSD-SA-01:40.fts"
date = "2001-06-04"
[[advisories]]
name = "FreeBSD-SA-01:39.tcp-isn"
date = "2001-05-02"
[[advisories]]
name = "FreeBSD-SA-01:38.sudo"
date = "2001-04-23"
[[advisories]]
name = "FreeBSD-SA-01:37.slrn"
date = "2001-04-23"
[[advisories]]
name = "FreeBSD-SA-01:36.samba"
date = "2001-04-23"
[[advisories]]
name = "FreeBSD-SA-01:35.licq"
date = "2001-04-23"
[[advisories]]
name = "FreeBSD-SA-01:34.hylafax"
date = "2001-04-23"
[[advisories]]
name = "FreeBSD-SA-01:33.ftpd-glob"
date = "2001-04-17"
[[advisories]]
name = "FreeBSD-SA-01:32.ipfilter"
date = "2001-04-16"
[[advisories]]
name = "FreeBSD-SA-01:31.ntpd"
date = "2001-04-06"
[[advisories]]
name = "FreeBSD-SA-01:30.ufs-ext2fs"
date = "2001-03-22"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/738"
[[advisories]]
name = "FreeBSD-SA-01:29.rwhod"
date = "2001-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/732"
[[advisories]]
name = "FreeBSD-SA-01:28.timed"
date = "2001-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/731"
[[advisories]]
name = "FreeBSD-SA-01:27.cfengine"
date = "2001-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/730"
[[advisories]]
name = "FreeBSD-SA-01:26.interbase"
date = "2001-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/729"
[[advisories]]
name = "FreeBSD-SA-01:23.icecast"
date = "2001-03-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/728"
[[advisories]]
name = "FreeBSD-SA-01:25.kerberosIV"
date = "2001-02-14"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/716"
[[advisories]]
name = "FreeBSD-SA-01:24.ssh"
date = "2001-02-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/715"
[[advisories]]
name = "FreeBSD-SA-01:22.dc20ctrl"
date = "2001-02-07"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/714"
[[advisories]]
name = "FreeBSD-SA-01:21.ja-elvis"
date = "2001-02-07"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/713"
[[advisories]]
name = "FreeBSD-SA-01:20.mars_nwe"
date = "2001-02-07"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/712"
[[advisories]]
name = "FreeBSD-SA-01:19.ja-klock"
date = "2001-02-07"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/707"
[[advisories]]
name = "FreeBSD-SA-01:18.bind"
date = "2001-01-31"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/706"
[[advisories]]
name = "FreeBSD-SA-01:17.exmh"
date = "2001-01-29"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/705"
[[advisories]]
name = "FreeBSD-SA-01:16.mysql"
date = "2001-01-29"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/704"
[[advisories]]
name = "FreeBSD-SA-01:15.tinyproxy"
date = "2001-01-29"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/703"
[[advisories]]
name = "FreeBSD-SA-01:14.micq"
date = "2001-01-29"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/702"
[[advisories]]
name = "FreeBSD-SA-01:13.sort"
date = "2001-01-29"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/701"
[[advisories]]
name = "FreeBSD-SA-01:12.periodic"
date = "2001-01-29"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/700"
[[advisories]]
name = "FreeBSD-SA-01:11.inetd"
date = "2001-01-29"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/699"
[[advisories]]
name = "FreeBSD-SA-01:10.bind"
date = "2001-01-23"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/698"
[[advisories]]
name = "FreeBSD-SA-01:09.crontab"
date = "2001-01-23"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/697"
[[advisories]]
name = "FreeBSD-SA-01:08.ipfw"
date = "2001-01-23"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/696"
[[advisories]]
name = "FreeBSD-SA-01:07.xfree86"
date = "2001-01-23"
[[advisories]]
name = "FreeBSD-SA-01:06.zope"
date = "2001-01-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/669"
[[advisories]]
name = "FreeBSD-SA-01:05.stunnel"
date = "2001-01-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/668"
[[advisories]]
name = "FreeBSD-SA-01:04.joe"
date = "2001-01-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/667"
[[advisories]]
name = "FreeBSD-SA-01:03.bash1"
date = "2001-01-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/666"
[[advisories]]
name = "FreeBSD-SA-01:02.syslog-ng"
date = "2001-01-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/665"
[[advisories]]
name = "FreeBSD-SA-01:01.openssh"
date = "2001-01-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/664"
[[advisories]]
name = "FreeBSD-SA-00:81.ethereal"
date = "2000-12-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/651"
[[advisories]]
name = "FreeBSD-SA-00:80.halflifeserver"
date = "2000-12-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/650"
[[advisories]]
name = "FreeBSD-SA-00:79.oops"
date = "2000-12-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/649"
[[advisories]]
name = "FreeBSD-SA-00:78.bitchx"
date = "2000-12-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/648"
[[advisories]]
name = "FreeBSD-SA-00:77.procfs"
date = "2000-12-18"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/647"
[[advisories]]
name = "FreeBSD-SA-00:76.tcsh-csh"
date = "2000-11-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/628"
[[advisories]]
name = "FreeBSD-SA-00:75.php"
date = "2000-11-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/627"
[[advisories]]
name = "FreeBSD-SA-00:74.gaim"
date = "2000-11-20"
[[advisories]]
name = "FreeBSD-SA-00:73.thttpd"
date = "2000-11-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/626"
[[advisories]]
name = "FreeBSD-SA-00:72.curl"
date = "2000-11-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/625"
[[advisories]]
name = "FreeBSD-SA-00:71.mgetty"
date = "2000-11-20"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/624"
[[advisories]]
name = "FreeBSD-SA-00:70.ppp-nat"
date = "2000-11-14"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/623"
[[advisories]]
name = "FreeBSD-SA-00:69.telnetd"
date = "2000-11-14"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/622"
[[advisories]]
name = "FreeBSD-SA-00:68.ncurses"
date = "2000-11-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/621"
[[advisories]]
name = "FreeBSD-SA-00:67.gnupg"
date = "2000-11-10"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/620"
[[advisories]]
name = "FreeBSD-SA-00:66.netscape"
date = "2000-11-06"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/619"
[[advisories]]
name = "FreeBSD-SA-00:65.xfce"
date = "2000-11-06"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/618"
[[advisories]]
name = "FreeBSD-SA-00:64.global"
date = "2000-11-06"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/617"
[[advisories]]
name = "FreeBSD-SA-00:63.getnameinfo"
date = "2000-11-01"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/589"
[[advisories]]
name = "FreeBSD-SA-00:62.top"
date = "2000-11-01"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/616"
[[advisories]]
name = "FreeBSD-SA-00:61.tcpdump"
date = "2000-10-31"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/615"
[[advisories]]
name = "FreeBSD-SA-00:60.boa"
date = "2000-10-30"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/586"
[[advisories]]
name = "FreeBSD-SA-00:59.pine"
date = "2000-10-30"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/585"
[[advisories]]
name = "FreeBSD-SA-00:58.chpass"
date = "2000-10-30"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/584"
[[advisories]]
name = "FreeBSD-SA-00:57.muh"
date = "2000-10-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/570"
[[advisories]]
name = "FreeBSD-SA-00:56.lprng"
date = "2000-10-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/569"
[[advisories]]
name = "FreeBSD-SA-00:55.xpdf"
date = "2000-10-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/568"
[[advisories]]
name = "FreeBSD-SA-00:54.fingerd"
date = "2000-10-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/567"
[[advisories]]
name = "FreeBSD-SA-00:52.tcp-iss"
date = "2000-10-06"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/561"
[[advisories]]
name = "FreeBSD-SA-00:53.catopen"
date = "2000-09-27"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/562"
[[advisories]]
name = "FreeBSD-SA-00:51.mailman"
date = "2000-09-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/550"
[[advisories]]
name = "FreeBSD-SA-00:50.listmanager"
date = "2000-09-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/549"
[[advisories]]
name = "FreeBSD-SA-00:49.eject"
date = "2000-09-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/548"
[[advisories]]
name = "FreeBSD-SA-00:48.xchat"
date = "2000-09-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/547"
[[advisories]]
name = "FreeBSD-SA-00:47.pine"
date = "2000-09-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/546"
[[advisories]]
name = "FreeBSD-SA-00:46.screen"
date = "2000-09-13"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/545"
[[advisories]]
name = "FreeBSD-SA-00:45.esound"
date = "2000-08-31"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/526"
[[advisories]]
name = "FreeBSD-SA-00:44.xlock"
date = "2000-08-28"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/523"
[[advisories]]
name = "FreeBSD-SA-00:43.brouted"
date = "2000-08-28"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/520"
[[advisories]]
name = "FreeBSD-SA-00:42.linux"
date = "2000-08-28"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/530"
[[advisories]]
name = "FreeBSD-SA-00:41.elf"
date = "2000-08-28"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/527"
[[advisories]]
name = "FreeBSD-SA-00:40.mopd"
date = "2000-08-28"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/521"
[[advisories]]
name = "FreeBSD-SA-00:39.netscape"
date = "2000-08-28"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/528"
[[advisories]]
name = "FreeBSD-SA-00:38.zope"
date = "2000-08-14"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/525"
[[advisories]]
name = "FreeBSD-SA-00:37.cvsweb"
date = "2000-08-14"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/524"
[[advisories]]
name = "FreeBSD-SA-00:36.ntop"
date = "2000-08-14"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/531"
[[advisories]]
name = "FreeBSD-SA-00:35.proftpd"
date = "2000-08-14"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/522"
[[advisories]]
name = "FreeBSD-SA-00:34.dhclient"
date = "2000-08-14"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/529"
[[advisories]]
name = "FreeBSD-SA-00:33.kerberosIV"
date = "2000-07-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/488"
[[advisories]]
name = "FreeBSD-SA-00:32.bitchx"
date = "2000-07-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/487"
[[advisories]]
name = "FreeBSD-SA-00:31.canna"
date = "2000-07-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/486"
[[advisories]]
name = "FreeBSD-SA-00:30.openssh"
date = "2000-07-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/485"
[[advisories]]
name = "FreeBSD-SA-00:29.wu-ftpd"
date = "2000-07-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/489"
[[advisories]]
name = "FreeBSD-SA-00:28.majordomo"
date = "2000-07-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/484"
[[advisories]]
name = "FreeBSD-SA-00:27.XFree86-4"
date = "2000-07-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/483"
[[advisories]]
name = "FreeBSD-SA-00:26.popper"
date = "2000-07-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/482"
[[advisories]]
name = "FreeBSD-SA-00:24.libedit"
date = "2000-07-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/481"
[[advisories]]
name = "FreeBSD-SA-00:23.ip-options"
date = "2000-06-19"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/480"
[[advisories]]
name = "FreeBSD-SA-00:25.alpha-random"
date = "2000-06-12"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/473"
[[advisories]]
name = "FreeBSD-SA-00:22.apsfilter"
date = "2000-06-07"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/461"
[[advisories]]
name = "FreeBSD-SA-00:21.ssh"
date = "2000-06-07"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/459"
[[advisories]]
name = "FreeBSD-SA-00:20.krb5"
date = "2000-05-26"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/452"
[[advisories]]
name = "FreeBSD-SA-00:19.semconfig"
date = "2000-05-23"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/451"
[[advisories]]
name = "FreeBSD-SA-00:18.gnapster.knapster"
date = "2000-05-09"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/429"
[[advisories]]
name = "FreeBSD-SA-00:17.libmytinfo"
date = "2000-05-09"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/442"
[[advisories]]
name = "FreeBSD-SA-00:16.golddig"
date = "2000-05-09"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/439"
[[advisories]]
name = "FreeBSD-SA-00:15.imap-uw"
date = "2000-04-24"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/438"
[[advisories]]
name = "FreeBSD-SA-00:14.imap-uw"
date = "2000-04-24"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/441"
[[advisories]]
name = "FreeBSD-SA-00:13.generic-nqs"
date = "2000-04-19"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/437"
[[advisories]]
name = "FreeBSD-SA-00:12.healthd"
date = "2000-04-10"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/436"
[[advisories]]
name = "FreeBSD-SA-00:11.ircii"
date = "2000-04-10"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/440"
[[advisories]]
name = "FreeBSD-SA-00:10.orville-write"
date = "2000-03-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/408"
[[advisories]]
name = "FreeBSD-SA-00:09.mtr"
date = "2000-03-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/408"
[[advisories]]
name = "FreeBSD-SA-00:08.lynx"
date = "2000-03-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/407"
[[advisories]]
name = "FreeBSD-SA-00:07.mh"
date = "2000-03-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/411"
[[advisories]]
name = "FreeBSD-SA-00:06.htdig"
date = "2000-03-01"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/403"
[[advisories]]
name = "FreeBSD-SA-00:05.mysql"
date = "2000-02-28"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/402"
[[advisories]]
name = "FreeBSD-SA-00:04.delegate"
date = "2000-02-19"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/392"
[[advisories]]
name = "FreeBSD-SA-00:03.asmon"
date = "2000-02-19"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/391"
[[advisories]]
name = "FreeBSD-SA-00:02.procfs"
date = "2000-01-24"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/380"
[[advisories]]
name = "FreeBSD-SA-00:01.make"
date = "2000-01-19"
[[advisories]]
name = "FreeBSD-SA-99:06.amd"
date = "1999-09-16"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/318"
[[advisories]]
name = "FreeBSD-SA-99:05.fts"
date = "1999-09-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/313"
[[advisories]]
name = "FreeBSD-SA-99:04.core"
date = "1999-09-15"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/312"
[[advisories]]
name = "FreeBSD-SA-99:03.ftpd"
date = "1999-09-05"
link = "http://home.jp.freebsd.org/cgi-bin/showmail/announce-jp/311"
[[advisories]]
name = "FreeBSD-SA-99:02.profil"
date = "1999-09-04"
[[advisories]]
name = "FreeBSD-SA-99:01.chflags"
date = "1999-09-04"
[[advisories]]
name = "FreeBSD-SA-98:08.fragment"
date = "1998-11-04"
[[advisories]]
name = "FreeBSD-SA-98:07.rst"
date = "1998-10-13"
[[advisories]]
name = "FreeBSD-SA-98:06.icmp"
date = "1998-06-10"
[[advisories]]
name = "FreeBSD-SA-98:05.nfs"
date = "1998-06-04"
[[advisories]]
name = "FreeBSD-SA-98:04.mmap"
date = "1998-06-02"
[[advisories]]
name = "FreeBSD-SA-98:03.ttcp"
date = "1998-05-14"
[[advisories]]
name = "FreeBSD-SA-98:02.mmap"
date = "1998-03-12"
[[advisories]]
name = "FreeBSD-SA-97:06.f00f"
date = "1997-12-09"
[[advisories]]
name = "FreeBSD-SA-98:01.land"
date = "1997-12-01"
[[advisories]]
name = "FreeBSD-SA-97:05.open"
date = "1997-10-29"
[[advisories]]
name = "FreeBSD-SA-97:04.procfs"
date = "1997-08-19"
[[advisories]]
name = "FreeBSD-SA-97:03.sysinstall"
date = "1997-04-07"
[[advisories]]
name = "FreeBSD-SA-97:02.lpd"
date = "1997-03-26"
[[advisories]]
name = "FreeBSD-SA-97:01.setlocale"
date = "1997-02-05"
[[advisories]]
name = "FreeBSD-SA-96:21.talkd"
date = "1997-01-18"
[[advisories]]
name = "FreeBSD-SA-96:20.stack-overflow"
date = "1996-12-16"
[[advisories]]
name = "FreeBSD-SA-96:19.modstat"
date = "1996-12-10"
[[advisories]]
name = "FreeBSD-SA-96:18.lpr"
date = "1996-11-25"
[[advisories]]
name = "FreeBSD-SA-96:17.rzsz"
date = "1996-07-16"
[[advisories]]
name = "FreeBSD-SA-96:16.rdist"
date = "1996-07-12"
[[advisories]]
name = "FreeBSD-SA-96:15.ppp"
date = "1996-07-04"
[[advisories]]
name = "FreeBSD-SA-96:12.perl"
date = "1996-06-28"
[[advisories]]
name = "FreeBSD-SA-96:14.ipfw"
date = "1996-06-24"
[[advisories]]
name = "FreeBSD-SA-96:13.comsat"
date = "1996-06-05"
[[advisories]]
name = "FreeBSD-SA-96:11.man"
date = "1996-05-21"
[[advisories]]
name = "FreeBSD-SA-96:10.mount_union"
date = "1996-05-17"
[[advisories]]
name = "FreeBSD-SA-96:09.vfsload"
date = "1996-05-17"
[[advisories]]
name = "FreeBSD-SA-96:02.apache"
date = "1996-04-22"
[[advisories]]
name = "FreeBSD-SA-96:08.syslog"
date = "1996-04-21"
[[advisories]]
name = "FreeBSD-SA-96:01.sliplogin"
date = "1996-04-21"
[[advisories]]
name = "FreeBSD-SA-96:03.sendmail-suggestion"
date = "1996-04-20"
diff --git a/website/data/security/errata.toml b/website/data/security/errata.toml
index e6cb101d6d..92aafdccb4 100644
--- a/website/data/security/errata.toml
+++ b/website/data/security/errata.toml
@@ -1,1135 +1,1143 @@
# Sort errata notices by year, month and day
# $FreeBSD$
+[[notices]]
+name = "FreeBSD-EN-26:19.zfs"
+date = "2026-07-29"
+
+[[notices]]
+name = "FreeBSD-EN-26:18.tzdata"
+date = "2026-07-29"
+
[[notices]]
name = "FreeBSD-EN-26:17.rpcsec_tls"
date = "2026-06-30"
[[notices]]
name = "FreeBSD-EN-26:16.arm64"
date = "2026-06-30"
[[notices]]
name = "FreeBSD-EN-26:15.openssl"
date = "2026-06-09"
[[notices]]
name = "FreeBSD-EN-26:14.syslogd"
date = "2026-06-09"
[[notices]]
name = "FreeBSD-EN-26:13.freebsd-update"
date = "2026-05-20"
[[notices]]
name = "FreeBSD-EN-26:12.freebsd-update"
date = "2026-05-01"
[[notices]]
name = "FreeBSD-EN-26:11.dhclient"
date = "2026-05-01"
[[notices]]
name = "FreeBSD-EN-26:10.amd64"
date = "2026-04-29"
[[notices]]
name = "FreeBSD-EN-26:09.tzdata"
date = "2026-04-29"
[[notices]]
name = "FreeBSD-EN-26:08.pf"
date = "2026-04-29"
[[notices]]
name = "FreeBSD-EN-26:07.pkgbase"
date = "2026-04-21"
[[notices]]
name = "FreeBSD-EN-26:06.timerfd"
date = "2026-04-21"
[[notices]]
name = "FreeBSD-EN-26:05.vm"
date = "2026-04-21"
[[notices]]
name = "FreeBSD-EN-26:04.arm64"
date = "2026-02-10"
[[notices]]
name = "FreeBSD-EN-26:03.vm"
date = "2026-01-27"
[[notices]]
name = "FreeBSD-EN-26:02.arm64"
date = "2026-01-27"
[[notices]]
name = "FreeBSD-EN-26:01.devinfo"
date = "2026-01-27"
[[notices]]
name = "FreeBSD-EN-25:20.vmm"
date = "2025-12-16"
[[notices]]
name = "FreeBSD-EN-25:19.zfs"
date = "2025-12-16"
[[notices]]
name = "FreeBSD-EN-25:18.freebsd-update"
date = "2025-09-30"
[[notices]]
name = "FreeBSD-EN-25:17.bnxt"
date = "2025-09-16"
[[notices]]
name = "FreeBSD-EN-25:16.vfs"
date = "2025-09-16"
[[notices]]
name = "FreeBSD-EN-25:15.arm64"
date = "2025-09-16"
[[notices]]
name = "FreeBSD-EN-25:14.route"
date = "2025-08-08"
[[notices]]
name = "FreeBSD-EN-25:13.wlan_tkip"
date = "2025-08-08"
[[notices]]
name = "FreeBSD-EN-25:12.efi"
date = "2025-08-08"
[[notices]]
name = "FreeBSD-EN-25:11.ena"
date = "2025-07-02"
[[notices]]
name = "FreeBSD-EN-25:10.zfs"
date = "2025-07-02"
[[notices]]
name = "FreeBSD-EN-25:09.libc"
date = "2025-07-02"
[[notices]]
name = "FreeBSD-EN-25:08.caroot"
date = "2025-04-10"
[[notices]]
name = "FreeBSD-EN-25:07.openssl"
date = "2025-04-10"
[[notices]]
name = "FreeBSD-EN-25:06.daemon"
date = "2025-04-10"
[[notices]]
name = "FreeBSD-EN-25:05.expat"
date = "2025-04-10"
[[notices]]
name = "FreeBSD-EN-25:04.tzdata"
date = "2025-04-10"
[[notices]]
name = "FreeBSD-EN-25:03.tzdata"
date = "2025-01-29"
[[notices]]
name = "FreeBSD-EN-25:02.audit"
date = "2025-01-29"
[[notices]]
name = "FreeBSD-EN-25:01.rpc"
date = "2025-01-29"
[[notices]]
name = "FreeBSD-EN-24:17.pam_xdg"
date = "2024-10-29"
[[notices]]
name = "FreeBSD-EN-24:16.pf"
date = "2024-09-19"
[[notices]]
name = "FreeBSD-EN-24:15.calendar"
date = "2024-09-04"
[[notices]]
name = "FreeBSD-EN-24:14.ifconfig"
date = "2024-08-07"
[[notices]]
name = "FreeBSD-EN-24:13.libc++"
date = "2024-06-19"
[[notices]]
name = "FreeBSD-EN-24:12.killpg"
date = "2024-06-19"
[[notices]]
name = "FreeBSD-EN-24:11.ldns"
date = "2024-06-19"
[[notices]]
name = "FreeBSD-EN-24:10.zfs"
date = "2024-06-19"
[[notices]]
name = "FreeBSD-EN-24:09.zfs"
date = "2024-04-24"
[[notices]]
name = "FreeBSD-EN-24:08.kerberos"
date = "2024-03-28"
[[notices]]
name = "FreeBSD-EN-24:07.clang"
date = "2024-03-28"
[[notices]]
name = "FreeBSD-EN-24:06.wireguard"
date = "2024-03-28"
[[notices]]
name = "FreeBSD-EN-24:05.tty"
date = "2024-03-28"
[[notices]]
name = "FreeBSD-EN-24:04.ip"
date = "2024-02-14"
[[notices]]
name = "FreeBSD-EN-24:03.kqueue"
date = "2024-02-14"
[[notices]]
name = "FreeBSD-EN-24:02.libutil"
date = "2024-02-14"
[[notices]]
name = "FreeBSD-EN-24:01.tzdata"
date = "2024-02-14"
[[notices]]
name = "FreeBSD-EN-23:22.vfs"
date = "2023-12-05"
[[notices]]
name = "FreeBSD-EN-23:21.tty"
date = "2023-12-05"
[[notices]]
name = "FreeBSD-EN-23:20.vm"
date = "2023-12-05"
[[notices]]
name = "FreeBSD-EN-23:19.pkgbase"
date = "2023-12-05"
[[notices]]
name = "FreeBSD-EN-23:18.openzfs"
date = "2023-12-05"
[[notices]]
name = "FreeBSD-EN-23:17.ossl"
date = "2023-12-05"
[[notices]]
name = "FreeBSD-EN-23:16.openzfs"
date = "2023-12-01"
[[notices]]
name = "FreeBSD-EN-23:15.sanitizer"
date = "2023-12-01"
[[notices]]
name = "FreeBSD-EN-23:14.regcomp"
date = "2023-11-08"
[[notices]]
name = "FreeBSD-EN-23:13.freebsd-update"
date = "2023-11-08"
[[notices]]
name = "FreeBSD-EN-23:12.freebsd-update"
date = "2023-10-03"
[[notices]]
name = "FreeBSD-EN-23:11.caroot"
date = "2023-09-06"
[[notices]]
name = "FreeBSD-EN-23:10.pci"
date = "2023-09-06"
[[notices]]
name = "FreeBSD-EN-23:09.freebsd-update"
date = "2023-09-06"
[[notices]]
name = "FreeBSD-EN-23:08.vnet"
date = "2023-08-01"
[[notices]]
name = "FreeBSD-EN-23:07.mpr"
date = "2023-06-21"
[[notices]]
name = "FreeBSD-EN-23:06.loader"
date = "2023-06-21"
[[notices]]
name = "FreeBSD-EN-23:05.tzdata"
date = "2023-06-21"
[[notices]]
name = "FreeBSD-EN-23:04.ixgbe"
date = "2023-02-08"
[[notices]]
name = "FreeBSD-EN-23:03.ena"
date = "2023-02-08"
[[notices]]
name = "FreeBSD-EN-23:02.sdhci"
date = "2023-02-08"
[[notices]]
name = "FreeBSD-EN-23:01.tzdata"
date = "2023-02-08"
[[notices]]
name = "FreeBSD-EN-22:28.heimdal"
date = "2022-11-29"
[[notices]]
name = "FreeBSD-EN-22:27.loader"
date = "2022-11-01"
[[notices]]
name = "FreeBSD-EN-22:26.cam"
date = "2022-11-01"
[[notices]]
name = "FreeBSD-EN-22:25.tcp"
date = "2022-11-01"
[[notices]]
name = "FreeBSD-EN-22:24.zfs"
date = "2022-11-01"
[[notices]]
name = "FreeBSD-EN-22:23.vm"
date = "2022-11-01"
[[notices]]
name = "FreeBSD-EN-22:22.tzdata"
date = "2022-11-01"
[[notices]]
name = "FreeBSD-EN-22:21.zfs"
date = "2022-11-01"
[[notices]]
name = "FreeBSD-EN-22:20.tzdata"
date = "2022-08-30"
[[notices]]
name = "FreeBSD-EN-22:19.pam_exec"
date = "2022-08-09"
[[notices]]
name = "FreeBSD-EN-22:18.wifi"
date = "2022-08-09"
[[notices]]
name = "FreeBSD-EN-22:17.cam"
date = "2022-08-09"
[[notices]]
name = "FreeBSD-EN-22:16.kqueue"
date = "2022-08-09"
[[notices]]
name = "FreeBSD-EN-22:15.pf"
date = "2022-04-06"
[[notices]]
name = "FreeBSD-EN-22:14.tzdata"
date = "2022-03-22"
[[notices]]
name = "FreeBSD-EN-22:13.zfs"
date = "2022-03-21"
[[notices]]
name = "FreeBSD-EN-22:12.zfs"
date = "2022-03-15"
[[notices]]
name = "FreeBSD-EN-22:11.zfs"
date = "2022-03-15"
[[notices]]
name = "FreeBSD-EN-22:10.zfs"
date = "2022-03-15"
[[notices]]
name = "FreeBSD-EN-22:09.freebsd-update"
date = "2022-03-15"
[[notices]]
name = "FreeBSD-EN-22:08.i386"
date = "2022-02-01"
[[notices]]
name = "FreeBSD-EN-22:07.la57"
date = "2022-02-01"
[[notices]]
name = "FreeBSD-EN-22:06.libalias"
date = "2022-01-11"
[[notices]]
name = "FreeBSD-EN-22:05.tail"
date = "2022-01-11"
[[notices]]
name = "FreeBSD-EN-22:04.pcid"
date = "2022-01-11"
[[notices]]
name = "FreeBSD-EN-22:03.hyperv"
date = "2022-01-11"
[[notices]]
name = "FreeBSD-EN-22:02.xsave"
date = "2022-01-11"
[[notices]]
name = "FreeBSD-EN-22:01.fsck_ffs"
date = "2022-01-11"
[[notices]]
name = "FreeBSD-EN-21:29.tzdata"
date = "2021-11-03"
[[notices]]
name = "FreeBSD-EN-21:28.vmci"
date = "2021-11-03"
[[notices]]
name = "FreeBSD-EN-21:27.caroot"
date = "2021-11-03"
[[notices]]
name = "FreeBSD-EN-21:26.libevent"
date = "2021-11-03"
[[notices]]
name = "FreeBSD-EN-21:25.bhyve"
date = "2021-08-24"
[[notices]]
name = "FreeBSD-EN-21:24.libcrypto"
date = "2021-08-24"
[[notices]]
name = "FreeBSD-EN-21:23.virtio_blk"
date = "2021-08-24"
[[notices]]
name = "FreeBSD-EN-21:22.linux_futex"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:21.ipfw"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:20.vlan"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:19.libcasper"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:18.libc++"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:17.libradius"
date = "2021-06-01"
[[notices]]
name = "FreeBSD-EN-21:16.bc"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:15.virtio"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:14.pms"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:13.mpt"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:12.divert"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:11.aesni"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:10.lldb"
date = "2021-04-06"
[[notices]]
name = "FreeBSD-EN-21:09.pf"
date = "2021-04-06"
[[notices]]
name = "FreeBSD-EN-21:08.freebsd-update"
date = "2021-02-24"
[[notices]]
name = "FreeBSD-EN-21:07.caroot"
date = "2021-02-24"
[[notices]]
name = "FreeBSD-EN-21:06.microcode"
date = "2021-02-24"
[[notices]]
name = "FreeBSD-EN-21:05.libatomic"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-21:04.zfs"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-21:03.vnet"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-21:02.extattr"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-21:01.tzdata"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-20:22.callout"
date = "2020-12-01"
[[notices]]
name = "FreeBSD-EN-20:21.ipfw"
date = "2020-12-01"
[[notices]]
name = "FreeBSD-EN-20:20.tzdata"
date = "2020-12-01"
[[notices]]
name = "FreeBSD-EN-20:19.audit"
date = "2020-12-01"
[[notices]]
name = "FreeBSD-EN-20:18.getfsstat"
date = "2020-09-02"
[[notices]]
name = "FreeBSD-EN-20:17.linuxthread"
date = "2020-09-02"
[[notices]]
name = "FreeBSD-EN-20:16.vmx"
date = "2020-08-05"
[[notices]]
name = "FreeBSD-EN-20:15.mps"
date = "2020-07-08"
[[notices]]
name = "FreeBSD-EN-20:14.linuxkpi"
date = "2020-07-08"
[[notices]]
name = "FreeBSD-EN-20:13.bhyve"
date = "2020-07-08"
[[notices]]
name = "FreeBSD-EN-20:12.iflib"
date = "2020-06-09"
[[notices]]
name = "FreeBSD-EN-20:11.ena"
date = "2020-06-09"
[[notices]]
name = "FreeBSD-EN-20:10.build"
date = "2020-05-12"
[[notices]]
name = "FreeBSD-EN-20:09.igb"
date = "2020-05-12"
[[notices]]
name = "FreeBSD-EN-20:08.tzdata"
date = "2020-05-12"
[[notices]]
name = "FreeBSD-EN-20:07.quotad"
date = "2020-04-21"
[[notices]]
name = "FreeBSD-EN-20:06.ipv6"
date = "2020-03-19"
[[notices]]
name = "FreeBSD-EN-20:05.mlx5en"
date = "2020-03-19"
[[notices]]
name = "FreeBSD-EN-20:04.pfctl"
date = "2020-03-19"
[[notices]]
name = "FreeBSD-EN-20:03.sshd"
date = "2020-03-19"
[[notices]]
name = "FreeBSD-EN-20:02.nmount"
date = "2020-01-28"
[[notices]]
name = "FreeBSD-EN-20:01.ssp"
date = "2020-01-28"
[[notices]]
name = "FreeBSD-EN-19:19.loader"
date = "2019-11-12"
[[notices]]
name = "FreeBSD-EN-19:18.tzdata"
date = "2019-10-23"
[[notices]]
name = "FreeBSD-EN-19:17.ipfw"
date = "2019-08-20"
[[notices]]
name = "FreeBSD-EN-19:16.bhyve"
date = "2019-08-20"
[[notices]]
name = "FreeBSD-EN-19:15.libunwind"
date = "2019-08-06"
[[notices]]
name = "FreeBSD-EN-19:14.epoch"
date = "2019-08-06"
[[notices]]
name = "FreeBSD-EN-19:13.mds"
date = "2019-07-24"
[[notices]]
name = "FreeBSD-EN-19:12.tzdata"
date = "2019-07-02"
[[notices]]
name = "FreeBSD-EN-19:11.net"
date = "2019-06-19"
[[notices]]
name = "FreeBSD-EN-19:10.scp"
date = "2019-05-14"
[[notices]]
name = "FreeBSD-EN-19:09.xinstall"
date = "2019-05-14"
[[notices]]
name = "FreeBSD-EN-19:08.tzdata"
date = "2019-05-14"
[[notices]]
name = "FreeBSD-EN-19:07.lle"
date = "2019-02-05"
[[notices]]
name = "FreeBSD-EN-19:06.dtrace"
date = "2019-02-05"
[[notices]]
name = "FreeBSD-EN-19:05.kqueue"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-19:04.tzdata"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-19:03.sqlite"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-19:02.tcp"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-19:01.cc_cubic"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-18:18.zfs"
date = "2018-12-19"
[[notices]]
name = "FreeBSD-EN-18:17.vm"
date = "2018-12-19"
[[notices]]
name = "FreeBSD-EN-18:16.ptrace"
date = "2018-12-19"
[[notices]]
name = "FreeBSD-EN-18:15.loader"
date = "2018-11-27"
[[notices]]
name = "FreeBSD-EN-18:14.tzdata"
date = "2018-11-27"
[[notices]]
name = "FreeBSD-EN-18:13.icmp"
date = "2018-11-27"
[[notices]]
name = "FreeBSD-EN-18:12.mem"
date = "2018-09-27"
[[notices]]
name = "FreeBSD-EN-18:11.listen"
date = "2018-09-27"
[[notices]]
name = "FreeBSD-EN-18:10.syscall"
date = "2018-09-27"
[[notices]]
name = "FreeBSD-EN-18:09.ip"
date = "2018-09-27"
[[notices]]
name = "FreeBSD-EN-18:08.lazyfpu"
date = "2018-09-12"
[[notices]]
name = "FreeBSD-EN-18:07.pmap"
date = "2018-06-21"
[[notices]]
name = "FreeBSD-EN-18:06.tzdata"
date = "2018-05-08"
[[notices]]
name = "FreeBSD-EN-18:05.mem"
date = "2018-05-08"
[[notices]]
name = "FreeBSD-EN-18:04.mem"
date = "2018-04-04"
[[notices]]
name = "FreeBSD-EN-18:03.tzdata"
date = "2018-04-04"
[[notices]]
name = "FreeBSD-EN-18:02.file"
date = "2018-03-07"
[[notices]]
name = "FreeBSD-EN-18:01.tzdata"
date = "2018-03-07"
[[notices]]
name = "FreeBSD-EN-17:09.tzdata"
date = "2017-11-02"
[[notices]]
name = "FreeBSD-EN-17:08.pf"
date = "2017-08-10"
[[notices]]
name = "FreeBSD-EN-17:07.vnet"
date = "2017-08-10"
[[notices]]
name = "FreeBSD-EN-17:06.hyperv"
date = "2017-07-12"
[[notices]]
name = "FreeBSD-EN-17:05.xen"
date = "2017-04-12"
[[notices]]
name = "FreeBSD-EN-17:04.mandoc"
date = "2017-02-23"
[[notices]]
name = "FreeBSD-EN-17:03.hyperv"
date = "2017-02-23"
[[notices]]
name = "FreeBSD-EN-17:02.yp"
date = "2017-02-23"
[[notices]]
name = "FreeBSD-EN-17:01.pcie"
date = "2017-02-23"
[[notices]]
name = "FreeBSD-EN-16:21.localedef"
date = "2016-12-06"
[[notices]]
name = "FreeBSD-EN-16:20.tzdata"
date = "2016-12-06"
[[notices]]
name = "FreeBSD-EN-16:19.tzcode"
date = "2016-12-06"
[[notices]]
name = "FreeBSD-EN-16:18.loader"
date = "2016-10-25"
[[notices]]
name = "FreeBSD-EN-16:17.vm"
date = "2016-10-25"
[[notices]]
name = "FreeBSD-EN-16:16.hv_storvsc"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:15.vmbus"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:14.hv_storvsc"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:13.vmbus"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:12.hv_storvsc"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:11.vmbus"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:10.dhclient"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:09.freebsd-update"
date = "2016-07-25"
[[notices]]
name = "FreeBSD-EN-16:08.zfs"
date = "2016-05-04"
[[notices]]
name = "FreeBSD-EN-16:07.ipi"
date = "2016-05-04"
[[notices]]
name = "FreeBSD-EN-16:06.libc"
date = "2016-05-04"
[[notices]]
name = "FreeBSD-EN-16:05.hv_netvsc"
date = "2016-03-16"
[[notices]]
name = "FreeBSD-EN-16:04.hyperv"
date = "2016-03-16"
[[notices]]
name = "FreeBSD-EN-16:03.yplib"
date = "2016-01-14"
[[notices]]
name = "FreeBSD-EN-16:02.pf"
date = "2016-01-14"
[[notices]]
name = "FreeBSD-EN-16:01.filemon"
date = "2016-01-14"
[[notices]]
name = "FreeBSD-EN-15:20.vm"
date = "2015-11-04"
[[notices]]
name = "FreeBSD-EN-15:19.kqueue"
date = "2015-11-04"
[[notices]]
name = "FreeBSD-EN-15:18.pkg"
date = "2015-09-16"
[[notices]]
name = "FreeBSD-EN-15:17.libc"
date = "2015-09-16"
[[notices]]
name = "FreeBSD-EN-15:16.pw"
date = "2015-09-16"
[[notices]]
name = "FreeBSD-EN-15:15.pkg"
date = "2015-08-25"
[[notices]]
name = "FreeBSD-EN-15:14.ixgbe"
date = "2015-08-25"
[[notices]]
name = "FreeBSD-EN-15:13.vidcontrol"
date = "2015-08-18"
[[notices]]
name = "FreeBSD-EN-15:12.netstat"
date = "2015-08-18"
[[notices]]
name = "FreeBSD-EN-15:11.toolchain"
date = "2015-08-18"
[[notices]]
name = "FreeBSD-EN-15:10.iconv"
date = "2015-06-30"
[[notices]]
name = "FreeBSD-EN-15:09.xlocale"
date = "2015-06-30"
[[notices]]
name = "FreeBSD-EN-15:08.sendmail"
date = "2015-06-18"
[[notices]]
name = "FreeBSD-EN-15:07.zfs"
date = "2015-06-09"
[[notices]]
name = "FreeBSD-EN-15:06.file"
date = "2015-06-09"
[[notices]]
name = "FreeBSD-EN-15:05.ufs"
date = "2015-05-13"
[[notices]]
name = "FreeBSD-EN-15:04.freebsd-update"
date = "2015-05-13"
[[notices]]
name = "FreeBSD-EN-15:03.freebsd-update"
date = "2015-02-25"
[[notices]]
name = "FreeBSD-EN-15:02.openssl"
date = "2015-02-25"
[[notices]]
name = "FreeBSD-EN-15:01.vt"
date = "2015-02-25"
[[notices]]
name = "FreeBSD-EN-14:13.freebsd-update"
date = "2014-12-23"
[[notices]]
name = "FreeBSD-EN-14:12.zfs"
date = "2014-11-04"
[[notices]]
name = "FreeBSD-EN-14:11.crypt"
date = "2014-10-22"
[[notices]]
name = "FreeBSD-EN-14:10.tzdata"
date = "2014-10-22"
[[notices]]
name = "FreeBSD-EN-14:09.jail"
date = "2014-07-08"
[[notices]]
name = "FreeBSD-EN-14:08.heimdal"
date = "2014-06-24"
[[notices]]
name = "FreeBSD-EN-14:07.pmap"
date = "2014-06-24"
[[notices]]
name = "FreeBSD-EN-14:06.exec"
date = "2014-06-03"
[[notices]]
name = "FreeBSD-EN-14:05.ciss"
date = "2014-05-13"
[[notices]]
name = "FreeBSD-EN-14:04.kldxref"
date = "2014-05-13"
[[notices]]
name = "FreeBSD-EN-14:03.pkg"
date = "2014-05-13"
[[notices]]
name = "FreeBSD-EN-14:02.mmap"
date = "2014-01-14"
[[notices]]
name = "FreeBSD-EN-14:01.random"
date = "2014-01-14"
[[notices]]
name = "FreeBSD-EN-13:05.freebsd-update"
date = "2013-11-28"
[[notices]]
name = "FreeBSD-EN-13:04.freebsd-update"
date = "2013-10-26"
[[notices]]
name = "FreeBSD-EN-13:03.mfi"
date = "2013-08-22"
[[notices]]
name = "FreeBSD-EN-13:01.fxp"
date = "2013-06-28"
[[notices]]
name = "FreeBSD-EN-13:02.vtnet"
date = "2013-06-28"
[[notices]]
name = "FreeBSD-EN-12:02.ipv6refcount"
date = "2012-06-12"
[[notices]]
name = "FreeBSD-EN-12:01.freebsd-update"
date = "2012-01-04"
[[notices]]
name = "FreeBSD-EN-10:02.sched_ule"
date = "2010-02-27"
[[notices]]
name = "FreeBSD-EN-10:01.freebsd"
date = "2010-01-06"
[[notices]]
name = "FreeBSD-EN-09:05.null"
date = "2009-10-02"
[[notices]]
name = "FreeBSD-EN-09:04.fork"
date = "2009-06-24"
[[notices]]
name = "FreeBSD-EN-09:03.fxp"
date = "2009-06-24"
[[notices]]
name = "FreeBSD-EN-09:02.bce"
date = "2009-06-24"
[[notices]]
name = "FreeBSD-EN-09:01.kenv"
date = "2009-03-23"
[[notices]]
name = "FreeBSD-EN-08:02.tcp"
date = "2008-06-19"
[[notices]]
name = "FreeBSD-EN-08:01.libpthread"
date = "2008-04-17"
[[notices]]
name = "FreeBSD-EN-07:05.freebsd-update"
date = "2007-03-15"
[[notices]]
name = "FreeBSD-EN-07:04.zoneinfo"
date = "2007-02-28"
[[notices]]
name = "FreeBSD-EN-07:03.rc.d_jail"
date = "2007-02-28"
[[notices]]
name = "FreeBSD-EN-07:02.net"
date = "2007-02-28"
[[notices]]
name = "FreeBSD-EN-07:01.nfs"
date = "2007-02-14"
[[notices]]
name = "FreeBSD-EN-06:02.net"
date = "2006-08-28"
[[notices]]
name = "FreeBSD-EN-06:01.jail"
date = "2006-07-07"
[[notices]]
name = "FreeBSD-EN-05:04.nfs"
date = "2005-12-19"
[[notices]]
name = "FreeBSD-EN-05:03.ipi"
date = "2005-01-16"
[[notices]]
name = "FreeBSD-EN-05:02.sk"
date = "2005-01-06"
[[notices]]
name = "FreeBSD-EN-05:01.nfs"
date = "2005-01-05"
[[notices]]
name = "FreeBSD-EN-04:01.twe"
date = "2004-06-28"
diff --git a/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc b/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc
new file mode 100644
index 0000000000..97be7e2a66
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-EN-26:18.tzdata.asc
@@ -0,0 +1,167 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-EN-26:18.tzdata Errata Notice
+ The FreeBSD Project
+
+Topic: Timezone database information update
+
+Category: contrib
+Module: zoneinfo
+Announced: 2026-07-29
+Affects: All supported versions of FreeBSD.
+Corrected: 2026-07-11 09:48:44 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:24 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:00 UTC (releng/15.0, 15.0-RELEASE-p12)
+ 2026-07-11 09:52:47 UTC (stable/14, 14.4-STABLE)
+ 2026-07-29 17:49:33 UTC (releng/14.4, 14.4-RELEASE-p8)
+
+For general information regarding FreeBSD Errata Notices and Security
+Advisories, including descriptions of the fields above, security branches,
+and the following sections, please visit .
+
+I. Background
+
+The IANA Time Zone Database (often called tz or zoneinfo) contains code and
+data that represent the history of local time for many representative
+locations around the globe. It is updated periodically to reflect changes
+made by political bodies to time zone boundaries, UTC offsets, and
+daylight-saving rules.
+
+FreeBSD releases install the IANA Time Zone Database in /usr/share/zoneinfo.
+The tzsetup(8) utility allows the user to specify the default local time
+zone. Based on the selected time zone, tzsetup(8) copies one of the files
+from /usr/share/zoneinfo to /etc/localtime. A time zone may also be selected
+for an individual process by setting its TZ environment variable to a desired
+time zone name.
+
+II. Problem Description
+
+Several changes to future and past timestamps have been recorded in the IANA
+Time Zone Database after previous FreeBSD releases were released. This
+affects many users in different parts of the world. Because of these
+changes, the data in the zoneinfo files need to be updated. If the local
+timezone on the running system is affected, tzsetup(8) needs to be run to
+update /etc/localtime.
+
+III. Impact
+
+An incorrect time will be displayed on a system configured to use one of the
+affected time zones if the /usr/share/zoneinfo and /etc/localtime files are
+not updated, and all applications on the system that rely on the system time,
+such as cron(8) and syslog(8), will be affected.
+
+IV. Workaround
+
+The system administrator can install an updated version of the IANA Time Zone
+Database from the misc/zoneinfo port and run tzsetup(8).
+
+Applications that store and display times in Coordinated Universal Time (UTC)
+are not affected.
+
+V. Solution
+
+Upgrade your system to a supported FreeBSD stable or release / security
+branch (releng) dated after the correction date.
+
+Please note that some third party software, for instance PHP, Ruby, Java,
+Perl and Python, may be using different zoneinfo data sources, in such cases
+this software must be updated separately. Software packages that are
+installed via binary packages can be upgraded by executing 'pkg upgrade'.
+
+Following the instructions in this Errata Notice will only update the IANA
+Time Zone Database installed in /usr/share/zoneinfo.
+
+Perform one of the following:
+
+1) To update your system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+
+2) To update your system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+
+3) To update your system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/EN-26:18/tzdata-2026c.patch
+# fetch https://security.FreeBSD.org/patches/EN-26:18/tzdata-2026c.patch.asc
+# gpg --verify tzdata-2026c.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile the operating system using buildworld and installworld as
+described in .
+
+Restart all the affected applications and daemons, or reboot the system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ 6470095eaa17 stable/15-n284437
+releng/15.1/ 3be83b93661d releng/15.1-n283583
+releng/15.0/ 8dd31fbcc50f releng/15.0-n281087
+stable/14/ 819af80de8e8 stable/14-n274491
+releng/14.4/ 7a227adc1ac6 releng/14.4-n273748
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbjsbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvWjEP/3AD86hhb4UDbCjoPCWg
+X/lkCToUk9WXaEQqORQIFOxsUu2e4CHDWlFkUvAezEV4zzoLjh/KmUzxXpgjj4Ij
+VF1pKgRBPMFQwtdrC9o106yoLAXJFGLlb1EG3jXUOHpOgMTtqCnYejp2NI0uXdDS
+BL19NOZUq8uyW1bbQF1XRQHo9nvUA0fhNbRHLmvXvAQFHsWDbz1h/PvwiSNNZlHs
+vOe9rqSqfOleTsj20V27kRC1/8C/0Ws29hVFWH1Zqb1x63f0nErfYAs/g9tJMdIl
+n4zuxQyJueX+GJaolBHEKvNkGBf/nSRtJNSJydD5MWbzBHs+mt3oiKfqbfUCUiR/
+leyvYhYTczfiORT+GSuBzMEn2fnrP+i/7VyqmETgnEymkyDu6UyxWJIA/d57ajGv
+M0GF62DYWtzjVHDvCChTPAAs4XNN26E/h8eATCNMNoLn39sQQFBjTo+36e4j7RnN
+bQZc7wAwPONOyxjs8GPC7ix8Ytja5VbwIqpUw7P8NpG4RIE3mIOIHAkympT0U7rn
+2xaU102yF3FlS3mUVO9KQyP0RrMhrY06av+MdkZqBcRLbX5CYw+AFcx4A2gU53vH
+a5FPKgyJxcL9/TjrjfvXvRfPJ8xb2E2apqtL/Ih1Dx22XDqv0hQj8Rhrqj2ViY+w
+BAQi1nCtevTlSbKBKMaCx/R0
+=5Yms
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc b/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc
new file mode 100644
index 0000000000..545c8c9af3
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-EN-26:19.zfs.asc
@@ -0,0 +1,141 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-EN-26:19.zfs Errata Notice
+ The FreeBSD Project
+
+Topic: Race conditions in zvol device management
+
+Category: contrib
+Module: openzfs
+Announced: 2026-07-29
+Affects: FreeBSD 15.1 and 15.0
+Corrected: 2026-07-27 17:33:34 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:28 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:04 UTC (releng/15.0, 15.0-RELEASE-p12)
+
+For general information regarding FreeBSD Errata Notices and Security
+Advisories, including descriptions of the fields above, security branches,
+and the following sections, please visit .
+
+I. Background
+
+ZFS is an advanced and scalable file system originally developed by Sun
+Microsystems for its Solaris operating system. ZFS was integrated as part of
+FreeBSD starting with FreeBSD 7.0.
+
+ZFS volumes (zvols) are ZFS datasets that appear as block devices. The
+kernel creates and removes device nodes as zvols are created, destroyed, or
+have their properties changed.
+
+II. Problem Description
+
+Several race conditions existed in interactions between the zvol device
+management code and FreeBSD's GEOM subsystem.
+
+III. Impact
+
+Operations on zvols such as renaming, changing properties, or destroying a
+zvol while it is being opened can cause a kernel panic.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your system to a supported FreeBSD stable or release / security
+branch (releng) dated after the correction date, and reboot the system.
+
+Perform one of the following:
+
+1) To update your system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r now
+
+2) To update your system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r now
+
+3) To update your system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/EN-26:19/zfs.patch
+# fetch https://security.FreeBSD.org/patches/EN-26:19/zfs.patch.asc
+# gpg --verify zfs.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+ and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ 698e0c419895 stable/15-n284603
+releng/15.1/ 596030c13dce releng/15.1-n283587
+releng/15.0/ 4316500c27c6 releng/15.0-n281091
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkIbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvQBYP/1NHmJWw6qysoaKt/ixx
+rKgRIK9hTj0+/JWPIn0M9HOD4bQevTPq0ZsX4rFhd7Ky+mzLh3UWCd1iCYpk+upr
+5awrfKgA+E/UXG0Wax/9zutUYNnPrI8bwayMRAQ1JCodSsYu54NBtQFAwvkEogJw
+yPQUE3bc/6kAaY+5hqGzfoZ2Vl0/Uhp0RTTWdKlSSMEv1RvdQz2gCF9akyJzN7IA
+KFM24jGkMoFV6TojJCuVXgtpqF9MaofqDZu27HY0HVIEEeL/rFzel7UsPNyQ5OTX
+I0tt97VjhPHEpbYbhDUfObFEnxgv8qsw3RWnb0RFttULJ+xcPoN1ASjn1N7g1pK/
+/SnOie9MJA2o9BVdPugRnj2nRmJ8IwOv235/rZwN9ChBeQXQTVxk0vgi49lzGLGB
+yVb4Pc1d5gDGr+S+KBmCq51N1OxSHanQwfrvTmIUjwWalBUqxLWe9rr1Lb7PnoIn
+b8M7NYR4XuX7uzeFKx0VHHFNjYhS9zwDLEVtsfBfcElApgURq/JOytJOXtJuznpw
+qNwiz0hgn9Hnx8WHlWKybQ3tWwX4UTvr+fTfsGzwbJksuVZuvn7y+gnpPTSlA+Rp
+g04H6N7Lcj+x15TQ452JcdzObfrshJXdXPbWLUxLSCmh4SP+3xpsEDlqsJUtX+WS
+/5y3DQbqNNnvHz1ofJfEsP6k
+=j9Br
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc b/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc
new file mode 100644
index 0000000000..885faf681c
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:50.kqueue.asc
@@ -0,0 +1,142 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:50.kqueue Security Advisory
+ The FreeBSD Project
+
+Topic: Use-after-free in kqueue copy-on-fork
+
+Category: core
+Module: kqueue
+Announced: 2026-07-29
+Credits: Hazley Samsudin of GovTech CSG
+Affects: FreeBSD 15.1
+Corrected: 2026-07-29 17:48:38 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:29 UTC (releng/15.1, 15.1-RELEASE-p2)
+CVE Name: CVE-2026-58083
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit .
+
+I. Background
+
+The kqueue(2) event notification facility supports a copy-on-fork mode
+(KQUEUE_CPONFORK) in which registered event filters (knotes) are duplicated
+into the child process during fork(2).
+
+II. Problem Description
+
+While the kernel was copying knotes during fork, a knote with a timer-based
+filter could fire and be enqueued on the kqueue's active list before the copy
+was complete. The copy routine did not account for this and could enqueue
+the new knote a second time, corrupting the active list. In addition, the
+copy routine did not hold the appropriate locks while reading knote state,
+allowing further races.
+
+III. Impact
+
+An unprivileged local user can trigger a use-after-free in the kernel,
+potentially leading to privilege escalation.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/SA-26:50/kqueue.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:50/kqueue.patch.asc
+# gpg --verify kqueue.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+ and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ cb7cb40ae47b stable/15-n284642
+releng/15.1/ 5a4222a1b225 releng/15.1-n283588
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkQbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv0LsP/jNvCmjgjFj/yoF6f2VC
+bHKymftfRZXrMj7xhO95IISFEwth5KwmrwS9e6nNwHBygRiH9AvAbrMREAhju8LK
+jtPkh0kAyMuAVIIDCcpMtFrMHoCS2FyuHLifA0LWhD8ouxPleJ/AkrjBDo9QRx3U
+REdng9J3nvq5N8rzon9yTqosv0qoPQD7y/QJPduzhFA6aPVK6MCHEmOtCjyUMUTS
+8Lze1WFzlqMt1tRl+iVsLsZa9uameOb4D/GQMkT3OagYQQ8rDLtw0r3hyzmWEw9x
+ckx3DgKNQygLY5nOvw7iHUbFdl3ovSAIjDbxRY0TV+UNVfcGhROL7GLkfg4YMVIf
+o5+61XFUaavzYH03xgAVaSKhdNAEv/ybatA/F4HDGeqNVY1V9lqUMX9E+z/n7rfs
+Y4theutEgwhO0ZJ3kB4WtkREEIovKOWDlPX+wbwxc2KUiEg6opkm0Ehjqt0p26+t
+ReWevNgO2qXIFr7ch0JiHJpmI8/yoKwS4VJTizaT5FgYO0fLlOBhJX/YXSGqeOPG
+V+Lb3MnLCGTSkRF4RckDq2ITWbRdQn0IEwYi2v1D6w5NYBd3weJdUioJUuUnXur/
+XweEflFDkNvcA4tOhn8ivMgKkT0xE4FEhBTa7ARlbsaE3/CTiu6Q4688lnKhxIzi
+IXAWlS8Xup6fxlIakdBALCr0
+=BGt9
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc b/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc
new file mode 100644
index 0000000000..60113db4c4
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:51.ktimer.asc
@@ -0,0 +1,145 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:51.ktimer Security Advisory
+ The FreeBSD Project
+
+Topic: Kernel stack disclosure via timer_settime(2)
+
+Category: core
+Module: ktimer
+Announced: 2026-07-29
+Credits: Hazley Samsudin of GovTech CSG
+Affects: FreeBSD 15.1 and 15.0
+Corrected: 2026-07-27 19:15:01 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:30 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:05 UTC (releng/15.0, 15.0-RELEASE-p12)
+CVE Name: CVE-2026-58084
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit .
+
+I. Background
+
+POSIX interval timers, managed by timer_create(2) and timer_settime(2), allow
+a process to schedule periodic or one-shot notifications based on a specified
+clock source. When timer_settime(2) is called with a non-NULL old_value
+argument, the kernel returns the timer's previous setting.
+
+II. Problem Description
+
+To retrieve the previous timer value, the kernel calls realtimer_gettime(),
+which obtains the current time for the timer's clock. For a timer using
+CLOCK_TAI this can fail when no TAI offset has been configured, but the error
+return was not checked, so the uninitialized output buffer was copied to
+userspace.
+
+III. Impact
+
+An unprivileged local user can obtain uninitialized kernel stack memory by
+creating a POSIX timer with CLOCK_TAI and calling timer_settime(2),
+potentially disclosing sensitive kernel data.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/SA-26:51/ktimer.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:51/ktimer.patch.asc
+# gpg --verify ktimer.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+ and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ a4b5ff57ef85 stable/15-n284618
+releng/15.1/ e1c9b0b13a29 releng/15.1-n283589
+releng/15.0/ 3254ef000750 releng/15.0-n281092
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkcbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv4p8P/3J3oX0usjnb08Xq+wBh
+u5GYBpPUUeTrJQkPqqmZon5UVRYoXobemhZ3k/sB1xX+VqxLZBbN9SO+7p5PYCAu
+cOfeirWH+sLj6vCK24ZHJ02mA3KASsHCKoaKxtxj77eKE+3dl3TT8ss9dzC7HgRy
+RqLDELyQnkOgeoXwm7jTxC1OhqP7rjZQiFdiOffy75C4wxWxJEqqpQazVBeqPefo
+gNnFdH5/6F8uJVrKysw+TJtGrVzoQnxVhJ3pho3YXJyPFBviA4FcTg3HJNjp0DrO
+Eg0/8W1R8s2ohyiBjFgoaTZGZyNaQ82F19eYp1XP/ZzeS0biZvYQZ6bTXjM4Pf92
+NOGKM65/ZZguHZMce3Yqf/czUkn9yG0aK+eeD5oQnC3HutQdfrQw+vzL9w51DJ0f
+VyCTH1Gj/x4BcyuBSCLiiWjaL5VVKpPLx3BhNgkQv5KAKiJayLd+kqp42lqPAGwr
+cBNdhL1awbmQtGkicl2suoongpVS6Doth92LjeB3pLT5DKZy5g4T0a/bvSdb+ghi
+HS8wjhvJFMl9PiXJC7h03XdTS1EUD8nbwvq4g1ho0qeS7xVpcWcb/DWkhcVts2eI
+rXe0TQwWdiQvKP7dUWpp8zdpNgpRDp1mGLiH9ojx/xChnMH1Rsu2pStlhY6F1ZjS
+Q7CDj///8ewA1AcGomzzTei0
+=A9FX
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc b/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc
new file mode 100644
index 0000000000..0b1d60109d
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:52.if_wg.asc
@@ -0,0 +1,164 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:52.if_wg Security Advisory
+ The FreeBSD Project
+
+Topic: Missing MAC validation in wg(4) packet decryption
+
+Category: core
+Module: if_wg
+Announced: 2026-07-29
+Credits: Reo Shiseki
+Affects: All supported versions of FreeBSD.
+Corrected: 2026-07-29 17:48:41 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:34 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:08 UTC (releng/15.0, 15.0-RELEASE-p12)
+ 2026-07-29 17:49:02 UTC (stable/14, 14.4-STABLE)
+ 2026-07-29 17:49:36 UTC (releng/14.4, 14.4-RELEASE-p8)
+CVE Name: CVE-2026-58085
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit .
+
+I. Background
+
+wg(4) is a kernel driver implementing the WireGuard VPN protocol. WireGuard
+uses ChaCha20-Poly1305, an authenticated encryption scheme, to protect tunnel
+traffic. The Poly1305 message authentication code (MAC) embedded in each
+data packet allows the receiver to verify that the packet has not been
+tampered with while in transit.
+
+The OpenCrypto framework (OCF) provides a generic interface to the kernel's
+implementation of various cryptographic transforms. Consumers submit a
+request via crypto_dispatch(), and OCF routes the request to a specific
+implementation of the requested transform.
+
+II. Problem Description
+
+After dispatching a decrypt operation to OCF and receiving the result, the
+wg(4) driver failed to check whether the MAC verification step succeeded.
+The driver thus silently accepted packets with an invalid Poly1305
+authentication tag.
+
+III. Impact
+
+A remote attacker who can send UDP packets to a WireGuard endpoint, and who
+can guess the bounds of the receiver's replay window, can inject forged or
+modified transport data packets into the tunnel.
+
+A remote attacker who can intercept WireGuard packets bound for a FreeBSD
+host can modify the ciphertext and authenticated data without detection by
+the receiver.
+
+IV. Workaround
+
+No workaround is available. Systems that do not use wg(4) are not affected.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+[FreeBSD 15.x]
+# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-15.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-15.patch.asc
+# gpg --verify if_wg-15.patch.asc
+
+[FreeBSD 14.x]
+# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-14.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:52/if_wg-14.patch.asc
+# gpg --verify if_wg-14.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+ and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ 4c40cb62935f stable/15-n284645
+releng/15.1/ b0254d23f508 releng/15.1-n283592
+releng/15.0/ 13be8d6d86f3 releng/15.0-n281095
+stable/14/ 825c6f45b147 stable/14-n274644
+releng/14.4/ b20841b47153 releng/14.4-n273751
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkkbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvYT4P/1sjyQxTye1SElCc9UT5
+DRVf9QXItIvjnWcsLAyNPd4EPLzhkiCUcnrYHirsSQoz3CiU1/DUev8WjWYJULoP
+1zx8U/6xxz3x9aTFb9MEKRBt5jQ62PUGXCLf8SsYiFDFoKuIAYljl5q2J1QkfINc
+hwCaYZbqYLunCztREtyfI4NKx5PzqS9paAlY0h85u09hvXOGgz0NeZsaztSjNpTl
+i0VUbpP3KAtZyRRYgt1EpHxPkUEpvE9k2KU8cz7B5WZG3x7iwJQAk0kEq66MBx2L
+dxyPpTPOM0xkkgdffZ3rGFC0tCBF1uqij0Z07ltiOmJDRJBN2imHhHv1QH/8CtwA
+UpK3ukTq5ZRkh7dRy87v/ClirQCgMAHTy4L/sTI9imEp7m/6Hzv6Kse4UIhUo+wI
+sisC+Hmeb/tw716QNrZeF6CT7D3V82F3VYEBNc7+e6OACEYilmKyyKp6+3sczbv0
+6IBgUjW8wQAWif2tbifQEUnxwpGhvVIAurZKnmKKN3y5OsHjaj48Lc36woVpxXPX
+jvuQflUEPPXsR6du4jPVceMAA+tN5fHnGmjWba5E1RtjSqIU6Q74L2hpfTA58Y2q
+yi/vSnOWk84jqXrUuL5JSGsSEQYGshOxHcWyeHndXxGMOjFmgmaoFDtVPvBQwuCo
+0FQ8Cxd/bOL+VieyaGH14wtk
+=xml5
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc b/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc
new file mode 100644
index 0000000000..945ab4c1bc
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:53.ktrace.asc
@@ -0,0 +1,146 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:53.ktrace Security Advisory
+ The FreeBSD Project
+
+Topic: ktrace(2) privilege incorrectly validated in jails
+
+Category: core
+Module: ktrace
+Announced: 2026-07-29
+Credits: Alexander Leidinger
+Affects: FreeBSD 15.1 and 15.0
+Corrected: 2026-07-29 17:48:42 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:35 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:09 UTC (releng/15.0, 15.0-RELEASE-p12)
+CVE Name: CVE-2026-58086
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit .
+
+I. Background
+
+The ktrace(2) facility allows tracing of kernel operations performed by a
+process. When ktrace(2) tracing is configured on a target process by a user
+that has the PRIV_KTRACE privilege (typically just the root user), the
+process is flagged such that an unprivileged user cannot modify the tracing
+flags, even if that user would otherwise be able to invoke ktrace(2) on the
+process.
+
+II. Problem Description
+
+As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was
+always denied to a jailed root user. Tracing configured by a jailed root
+user was therefore not flagged as privileged.
+
+III. Impact
+
+An unprivileged user in a jail that has permission to debug the target
+process can modify the jailed root user's ktrace(2) flags, or disable tracing
+outright. A jailed root user therefore cannot reliably trace unprivileged
+processes.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/SA-26:53/ktrace.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:53/ktrace.patch.asc
+# gpg --verify ktrace.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+ and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ fb432f55a7b8 stable/15-n284646
+releng/15.1/ 00effd2ab0bf releng/15.1-n283593
+releng/15.0/ 8250729075f1 releng/15.0-n281096
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbk0bFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvw3cQAM5ev1bKBd6741KJdhDx
+FliNSgWTmJkGF6Ys0JcYURSpSM+pSDLt96kskISUsSeifo1g4F9tJD619SddSPzt
+cSXzhlRAe74gtNA0P3N56Z1rqkRZxRMgPEAjOPZ3bhQ6o+bXtBUVWbDzVwbw+efs
+astReBuhQSPj7793YEPlOewwEIdQlauVkinfAPeUrHtcecL4ucjiKbkrxici1iWW
+nV9+O6wy6jGamTiLf7fGghLcZy71XkQE9Dy5U7hTmhiBftI9FsZdCJSTuc46jtDP
+NQ5D4DGtJE4RTquVW7OUpiPgDLgLX+RjKU5n6ElMW2/ZmwScG0V4+kj1EzpLVEXA
+7q58DvXfjZP8RAyQ3Ugrh6EQojdOAxYHYNHq+0iqLkk+gnsI7ePATL5u+QLU6nsX
+eYaj+wuNS7hfmI0+AZN3FqYp3+ccnqx/zlKS/aCqQA6cYOptspGvPUKa2pZF6VyO
+iLcscLRO6BfRgDCkU9vQB4dndHnhlRXBLeIrYtCwL5GIrYWEpXfTfPLFXOTZczyX
+utGg4J0F6rGzeoCefcZDXhBMRf+R8/8NtkeAH9UdjhupLiUVQAGTiDiFnPqIiRIz
+HuJDE1ncLEcb0Ey2gjxIG5RUyrtLxCr4jOcUHXyJ8pM9TKfFfnhVBAKVkp+iewQ3
+xD+U3+UO7cpUcFDeRLhGGtya
+=55wC
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:54.sysvsem.asc b/website/static/security/advisories/FreeBSD-SA-26:54.sysvsem.asc
new file mode 100644
index 0000000000..0809cd4541
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:54.sysvsem.asc
@@ -0,0 +1,154 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:54.sysvsem Security Advisory
+ The FreeBSD Project
+
+Topic: Heap out-of-bounds access in semctl(2)
+
+Category: core
+Module: sysvsem
+Announced: 2026-07-29
+Credits: Maik Muench of Secfault Security
+Affects: All supported versions of FreeBSD.
+Corrected: 2026-07-29 17:48:44 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:36 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:10 UTC (releng/15.0, 15.0-RELEASE-p12)
+ 2026-07-29 17:49:03 UTC (stable/14, 14.4-STABLE)
+ 2026-07-29 17:49:37 UTC (releng/14.4, 14.4-RELEASE-p8)
+CVE Name: CVE-2026-58087
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit .
+
+I. Background
+
+System V semaphores provide a set-based inter-process communication (IPC)
+semaphore facility.
+
+The semctl(2) system call performs control operations on semaphore sets,
+including the GETALL and SETALL commands which read or write the values of
+every semaphore in a set.
+
+II. Problem Description
+
+The GETALL and SETALL commands in semctl(2) recorded the number of semaphores
+in the target set, dropped the lock protecting the set, allocated a buffer
+sized for that count, and reacquired the lock. A sequence-number check was
+used to verify that the set had not been replaced in the interim, but the
+sequence number wraps after 0x8000 create/destroy cycles. By rapidly
+destroying and recreating semaphore sets at the same index, another process
+can cause the sequence number to wrap, allowing a set with a different number
+of semaphores to pass validation. The subsequent copy then reads or writes
+past the end of the allocated buffer.
+
+III. Impact
+
+An unprivileged local user can trigger out-of-bounds reads and writes on
+kernel heap memory, potentially leading to privilege escalation.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/SA-26:54/sysvsem.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:54/sysvsem.patch.asc
+# gpg --verify sysvsem.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+ and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ e2585687890e stable/15-n284647
+releng/15.1/ 5eb50510c6b3 releng/15.1-n283594
+releng/15.0/ 20c738692c61 releng/15.0-n281097
+stable/14/ 8b08ee989506 stable/14-n274645
+releng/14.4/ b5eaa00cdba3 releng/14.4-n273752
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbk8bFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvC94QAOGg2UTNCPHJ1g0HzrGa
+jdwvde86pwyP4upVWvCWTTCLMZ7dSoQ31VppY3EnPqMqW7UkZKBURD2MdG9KRsp/
++5U7t3bVr0t0JAUdTqG68c0HsLUjTwz+pLQ/WGcylzY9HEMg8QQfGjTQ9GR5DbuQ
+e/ZCYKOHpD7FttWHKltBC8hNZAHhO0FZftg09+Io2u4oew4Jalg2lGt8n2F9hYXl
+QaAGTF4jnyl0wN3fmUbbyWfBl/iOMO7FVKN97L41nzMiB2y+QUT9r8T1iq/Y5oMh
+AKeXwT4q94mJTczgRIcf8cWLBx3aTx+X3w4mX2R4EwOrcC8FU5Jlvi5k/+Uj6zUY
+Z+jjzr1umJX+cSOdT4VGV5Nhv2i63NsWI0RC5Sd7JU3cXjhLxsAVZcFDTDTYWRqk
+mcxN2rrjtxr6vN03LxLyY8owKLfqAV1eoppXL3ee+a6hFAsQcH8PvvAr9Qqh2oEw
+XZA5H8WLxYl2rejFHlgdVjnnvKGgkoaY1/3vSoJ6NUhEtQbk1OTk/pJs/F7Pnvao
+gDa/giYXFsbk/UIzRCuk8IOdnuGpWbfeVAbvUmYEC8Kw1VHZtTLc+lM0ZWLAKbW9
+B+F+DNj/4WYhbFaKBWnHWIWwtC3TssB280kdyburUpcGTcvBbAhHcu3BM3sYKyJ8
+GXawkEVDDJVDtuquoWyvdZ6+
+=hMF9
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-SA-26:55.elf.asc b/website/static/security/advisories/FreeBSD-SA-26:55.elf.asc
new file mode 100644
index 0000000000..d29b71b231
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-SA-26:55.elf.asc
@@ -0,0 +1,155 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-SA-26:55.elf Security Advisory
+ The FreeBSD Project
+
+Topic: Race condition in ELF core dump segment counting
+
+Category: core
+Module: elf
+Announced: 2026-07-29
+Credits: Maik Muench of Secfault Security
+Affects: All supported versions of FreeBSD.
+Corrected: 2026-07-29 17:48:45 UTC (stable/15, 15.1-STABLE)
+ 2026-07-29 17:50:37 UTC (releng/15.1, 15.1-RELEASE-p2)
+ 2026-07-29 17:50:11 UTC (releng/15.0, 15.0-RELEASE-p12)
+ 2026-07-29 17:49:04 UTC (stable/14, 14.4-STABLE)
+ 2026-07-29 17:49:38 UTC (releng/14.4, 14.4-RELEASE-p8)
+CVE Name: CVE-2026-58088
+
+For general information regarding FreeBSD Security Advisories, including
+descriptions of the fields above, security branches, and the following
+sections, please visit .
+
+I. Background
+
+When a process dumps core, the kernel writes an ELF file containing the
+process's register state and memory contents. Each dumpable region of the
+process's virtual memory map is represented by an ELF segment in the core
+file.
+
+II. Problem Description
+
+The ELF core dump code counted the number of dumpable VM map entries,
+allocated a buffer for the corresponding program headers, then iterated over
+the map a second time to populate them. A process sharing the address space
+via rfork(2) can mutate the map between the two passes, causing the second
+pass to write program headers past the end of the buffer.
+
+III. Impact
+
+An unprivileged local user sharing an address space with a process that dumps
+core can trigger an out-of-bounds write on the kernel heap, potentially
+leading to privilege escalation.
+
+IV. Workaround
+
+Set sysctl kern.coredump=0 to disable core dumps entirely.
+
+V. Solution
+
+Upgrade your vulnerable system to a supported FreeBSD stable or
+release / security branch (releng) dated after the correction date,
+and reboot the system.
+
+Perform one of the following:
+
+1) To update your vulnerable system installed from base system packages:
+
+Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
+arm64 platforms, which were installed using base system packages, can be
+updated via the pkg(8) utility:
+
+# pkg upgrade -r FreeBSD-base
+# shutdown -r +10min "Rebooting for a security update"
+
+2) To update your vulnerable system installed from binary distribution sets:
+
+Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
+which were not installed using base system packages can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r +10min "Rebooting for a security update"
+
+3) To update your vulnerable system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+[FreeBSD 15.x]
+# fetch https://security.FreeBSD.org/patches/SA-26:55/elf-15.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:55/elf-15.patch.asc
+# gpg --verify elf-15.patch.asc
+
+[FreeBSD 14.x]
+# fetch https://security.FreeBSD.org/patches/SA-26:55/elf-14.patch
+# fetch https://security.FreeBSD.org/patches/SA-26:55/elf-14.patch.asc
+# gpg --verify elf-14.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch -E -p0 < /path/to/patch
+
+c) Recompile your kernel as described in
+ and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected as of the corresponding Git commit hash in the
+following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/15/ 008d3bafa124 stable/15-n284648
+releng/15.1/ 8592efddadf6 releng/15.1-n283595
+releng/15.0/ 475a72f75478 releng/15.0-n281098
+stable/14/ 89a88e4f2ddc stable/14-n274646
+releng/14.4/ d46ec216104e releng/14.4-n273753
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqblIbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvlBMQANG+Id+ZqIheEim9bCQc
++Rxfqu3VgaAz8JET1VtOWew6C7xGPe3ii2g+Q/MIN28Lss9ndn1NoyEojKxJhWpb
+4e7yUgA1p24pKcrV23uuMtbn/nWH/BnkIqZXhK1yPxRZ59uv7D1CCr1Qhh6HjADZ
+T6fG5anrUivmTDxDLJZb7OpIuMeVahH9TUvxAvH3MQDEVkv8S0ig8Lghdmf8Ytua
+zZa1gGMiA/LnTGcd13dysGtKSXECRYutD2ak2GV416vPVThCgd1yzdFp4axdopBg
+gMAJK9F3+0C7Mn53ATUGsRXYyAfb6PNNsF5vAc5aojHBluf5hEQTNDK0QumOpYfQ
+Gt6ZvS0lBJ1Lj3nNSKVF2fgBAQeHY80FFeRYABNwPPRWz1X41GMs0ngK6laJVP41
+/m0P6Ad+7KbEWJ5mhfRMx0igApHqpprFMHMMr5HZAd3H8pgclkb7k09PuDBjBFsk
+Y/UsxJ6T5P0IZ5PnExGB5D1K6cql86n8PRDI5mu9aU3wEPQJFsykIeSQU41SWOoc
+GQyAmvUCU4qRjRVaIrULiCowUwhM6TQbuOgrQcJVp/n8MMh92bvpb+sCRniKZDSV
+IvD/6gLXoNBmPEOMR7Bgq1Lz/wUCLPBAQgNmEcFb+HLEMURj+QDXX6heSkZV/6GI
+brmHeN390GhTuutDmJTGgQCK
+=CL/m
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-26:18/tzdata-2026c.patch b/website/static/security/patches/EN-26:18/tzdata-2026c.patch
new file mode 100644
index 0000000000..c89060f3cb
--- /dev/null
+++ b/website/static/security/patches/EN-26:18/tzdata-2026c.patch
@@ -0,0 +1,960 @@
+--- contrib/tzdata/Makefile.orig
++++ contrib/tzdata/Makefile
+@@ -114,7 +114,7 @@
+ # The "zic" command goes in:
+ ZICDIR = $(TOPDIR)/$(USRDIR)/sbin
+
+-# Manual pages go in subdirectories of. . .
++# Manual pages go in subdirectories of:
+ MANDIR = $(TOPDIR)/$(USRSHAREDIR)/man
+
+ # Library functions are put in an archive in LIBDIR.
+@@ -145,7 +145,7 @@
+ # nonnegative TZ_CHANGE_INTERVAL also assumes this, so to be compatible with
+ # these, use "posix_only" or "posix_right". Use POSIX time on systems with
+ # leap smearing; this can work better than unsmeared "right" time with
+-# applications that are not leap second aware, and is closer to unsmeared
++# applications that are not aware of leap seconds, and is closer to unsmeared
+ # "right" time than unsmeared POSIX time is (e.g., 0.5 vs 1.0 s max error).
+
+ REDO= posix_only
+@@ -295,10 +295,10 @@
+ # -DTHREAD_SAFE to make localtime.c thread-safe, as POSIX requires;
+ # not needed by the main-program tz code, which is single-threaded.
+ # Append other compiler flags as needed, e.g., -pthread on GNU/Linux.
+-# The following options can also be used:
++# With -DTHREAD_SAFE the following options can also be used:
+ # -DTHREAD_PREFER_SINGLE to prefer speed in single-threaded apps,
+ # at some cost in CPU time and energy in multi-threaded apps.
+-# The following options can also be used:
++# With -DTHREAD_PREFER_SINGLE the following options can also be used:
+ # -DHAVE___ISTHREADED=1 if there is an extern int __isthreaded
+ # variable, 0 otherwise (default is guessed)
+ # -DHAVE_SYS_SINGLE_THREADED_H=0 if works,
+@@ -377,12 +377,13 @@
+ -Wdeclaration-after-statement -Wdouble-promotion \
+ -Wduplicated-branches -Wduplicated-cond -Wflex-array-member-not-at-end \
+ -Wformat=2 -Wformat-overflow=2 -Wformat-signedness -Wformat-truncation \
+- -Wimplicit-fallthrough=5 -Winit-self -Wlogical-op \
++ -Wfree-labels -Wimplicit-fallthrough=5 -Winit-self \
++ -Wkeyword-macro -Wlogical-op \
+ -Wmissing-declarations -Wmissing-prototypes \
+ -Wmissing-variable-declarations -Wnested-externs \
+ -Wnull-dereference \
+ -Wold-style-definition -Woverlength-strings -Wpointer-arith \
+- -Wshadow -Wshift-overflow=2 -Wstrict-overflow \
++ -Wshadow -Wshift-overflow=2 \
+ -Wstrict-prototypes -Wstringop-overflow=4 \
+ -Wsuggest-attribute=cold \
+ -Wsuggest-attribute=const -Wsuggest-attribute=format \
+@@ -533,7 +534,7 @@
+ # mawk 1.3.3 and Solaris 10 /usr/bin/awk do not work.
+ # Also, it is better (though not essential) if 'awk' supports UTF-8,
+ # and unfortunately mawk and busybox awk do not support UTF-8.
+-# Try AWK=gawk or AWK=nawk if your awk has the abovementioned problems.
++# Try AWK=gawk or AWK=nawk if your awk has the problems mentioned above.
+ AWK= awk
+
+ # The full path name of a POSIX-compliant shell, preferably one that supports
+@@ -913,7 +914,7 @@
+ check: check_mild back.ck now.ck
+ check_mild: check_web check_zishrink \
+ character-set.ck white-space.ck links.ck mainguard.ck \
+- name-lengths.ck slashed-abbrs.ck sorted.ck \
++ name-lengths.ck news.ck slashed-abbrs.ck sorted.ck \
+ tables.ck ziguard.ck tzs.ck
+
+ # True if UTF8_LOCALE does not work;
+@@ -1083,6 +1084,12 @@
+ rm -fr $@d t-$@d shrunk-$@d
+ touch $@
+
++# Check that NEWS has data release versions and dates in reverse order.
++news.ck: NEWS
++ grep '^Release [0-9][0-9][0-9][0-9]' NEWS | LC_ALL=C sort -cru
++ sed -n '/ -0000$$/!s/^Release [^ ]*//p' NEWS|LC_ALL=C sort -cru
++ touch $@
++
+ clean_misc:
+ rm -fr *.ckd *.dir
+ rm -f *.ck *.core *.o *.out *.t core core.* \
+@@ -1139,7 +1146,8 @@
+ # If DEST depends on A B C ... in this Makefile, callers should use
+ # $(SET_TIMESTAMP_DEP) DEST A B C ..., for the benefit of any
+ # downstream 'make' that considers equal timestamps to be out of date.
+-# POSIX allows this 'make' behavior, and HP-UX 'make' does it.
++# POSIX allows this 'make' behavior, although only HP-UX 'make'
++# (which is no longer supported) did things that way.
+ # If all that matters is that the timestamp be reproducible
+ # and plausible, use $(SET_TIMESTAMP).
+ SET_TIMESTAMP = $(SET_TIMESTAMP_N) 0
+@@ -1399,24 +1407,6 @@
+ $(SET_TIMESTAMP) $(@:.t=) $(?:.t=)
+ touch $@
+
+-TYPECHECK_CFLAGS = $(CFLAGS) -DTYPECHECK -D__time_t_defined -D_TIME_T
+-typecheck: long-long.ck unsigned.ck
+-long-long.ck unsigned.ck: $(VERSION_DEPS)
+- rm -fr $@d
+- mkdir $@d
+- ln $(VERSION_DEPS) $@d
+- cd $@d && \
+- case $@ in \
+- long-long.*) i="long long";; \
+- unsigned.* ) i="unsigned" ;; \
+- esac && \
+- $(MAKE) \
+- CFLAGS="$(TYPECHECK_CFLAGS) \"-Dtime_t=$$i\"" \
+- TOPDIR="$$PWD" \
+- install
+- $@d/zdump -i -c 1970,1971 Europe/Rome
+- touch $@
+-
+ zonenames: tzdata.zi
+ @$(AWK) '/^Z/ { print $$2 } /^L/ { print $$3 }' tzdata.zi
+
+@@ -1442,6 +1432,5 @@
+ .PHONY: traditional_signatures traditional_signatures_version
+ .PHONY: traditional_tarballs traditional_tarballs_version
+ .PHONY: tailored_tarballs tailored_tarballs_version
+-.PHONY: typecheck
+ .PHONY: zonenames zones
+ .PHONY: $(ZDS)
+--- contrib/tzdata/NEWS.orig
++++ contrib/tzdata/NEWS
+@@ -1,6 +1,69 @@
+ News for the tz database
+
+-Release 2026a - 2026-04-22 23:06:43 -0700
++Release 2026c - 2026-07-08 10:23:58 -0700
++
++ Briefly:
++ Alberta moved to permanent -06 on 2026-06-18.
++ Morocco moves to permanent +00 on 2026-09-20.
++ More integer overflow bugs have been fixed in zic.
++
++ Changes to future timestamps
++
++ Alberta’s 2026-03-08 spring forward was its last foreseeable clock
++ change, as it moved to permanent -06 thereafter. (Thanks to Roozbeh
++ Pournader and others.) Model this with its traditional abbreviation
++ CST. Although the change to permanent -06 legally took place on
++ 2026-06-18, temporarily model the change to occur on 2026-11-01 at
++ 02:00 instead, for the same reason we introduced a similarly
++ temporary hack for British Columbia in 2026b.
++
++ Although another TZDB release will likely be needed soon because
++ Northwest Territories will likely follow Alberta, the legal
++ formalities have not yet taken place.
++
++ Morocco plans to move back to permanent UTC, without daylight
++ saving time transitions, on 2026-09-20 at 02:00. This also
++ affects Western Sahara.
++
++ Changes to code
++
++ zic no longer overflows integers when processing outlandish input
++ like ‘Zone Ouch 0 - LMT 9223372036854775807’, ‘Zone Ouch 0
++ 2562047788015215 LMT’, ‘Zone Ouch -2562047788015215:30:08 - LMT’,
++ and ‘Zone Ouch -2562047788015215:30:08 - %%z’. This avoids
++ undefined behavior in C. (Problems reported by Naveed Khan.)
++
++ On platforms that have EFTYPE, tzalloc now fails with errno set to
++ EFTYPE, not EINVAL, if it detects that the TZif file has an
++ invalid format or is not a regular file. Formerly it did this
++ only on NetBSD, and only when the file was not a regular file.
++
++ Unprivileged programs no longer require TZif files to be regular
++ files or reject relative names containing ".." components. This
++ reverts to the more-permissive 2025b behavior, as the stricter
++ behavior did not catch on in FreeBSD.
++
++ zic now reports any failure to remove a temporary file when
++ cleaning up after a previous failure. (Problem reported by Tom
++ Lane.)
++
++ Changes to commentary
++
++ Northwest Territories is expected to move to permanent -06 prior to
++ 2026-11-01 02:00, when clocks would otherwise fall back. (Thanks to
++ Tim Parenti and James Bellaire.) Model this with its traditional
++ abbreviation CST. Unfortunately the change is not yet official, so
++ it is currently present only as comments that can be uncommented as
++ needed.
++
++ Changes to build procedure
++
++ The undocumented ‘typecheck’ Makefile check rule has been removed.
++ It stopped working in 2025a and evidently nobody noticed.
++ The rule was superseded by ‘check_time_t_alternatives’ in 2013d.
++
++
++Release 2026b - 2026-04-22 23:06:43 -0700
+
+ Briefly:
+ British Columbia moved to permanent -07 on 2026-03-09.
+@@ -13,7 +76,7 @@
+ (Thanks to Arthur David Olson.) Although the change to permanent
+ -07 legally took place on 2026-03-09, temporarily model the change
+ to occur on 2026-11-01 at 02:00 instead. This works around a
+- limitation in CLDR v48.2 (2026-03-17). This temporary hack is
++ limitation in CLDR 48.1 (2026-01-08). This temporary hack is
+ planned to be removed after CLDR is fixed.
+
+ Changes to code
+@@ -99,7 +162,7 @@
+ than attempting to override this fallback with the contents of the
+ posixrules file. This removes library support that was declared
+ obsolete in release 2019b, and fixes some undefined behavior.
+- (Undefined behavior reported by GitHub user Naveed8951.)
++ (Undefined behavior reported by Naveed Khan.)
+
+ The posix2time, posix2time_z, time2posix, and time2posix_z
+ functions now set errno=EOVERFLOW and return ((time_t) -1) if the
+@@ -111,7 +174,7 @@
+
+ Some other undefined behavior, triggered by TZif files containing
+ outlandish but conforming UT offsets or leap second corrections,
+- has also been fixed. (Some of these bugs reported by Naveed8951.)
++ has also been fixed. (Some of these bugs reported by Naveed Khan.)
+
+ localtime.c no longer rejects TZif files that exactly fit in its
+ internal structures, fixing off-by-one typos introduced in 2014g.
+@@ -221,7 +284,7 @@
+ rarely changing and many threads call tzcode simultaneously.
+ It costs more CPU time and energy.
+
+- The new CFLAGS option -TTHREAD_TM_MULTI causes localtime to return
++ The new CFLAGS option -DTHREAD_TM_MULTI causes localtime to return
+ a pointer to thread-specific memory, as FreeBSD does, instead of
+ to the same memory in all threads. This supports nonportable
+ programs that incorrectly use localtime instead of localtime_r.
+@@ -551,7 +614,7 @@
+ The leap-seconds.list file is now copied from the IERS instead of
+ from its downstream counterpart at NIST, as the IERS version is
+ now in the public domain too and tends to be more up-to-date.
+- (Thanks to Martin Burnicki for liaisoning with the IERS.)
++ (Thanks to Martin Burnicki for liaising with the IERS.)
+
+ Changes to documentation
+
+@@ -1709,7 +1772,7 @@
+ zic -L now supports an Expires line in the leapseconds file, and
+ truncates the TZif output accordingly. This propagates leap
+ second expiration information into the TZif file, and avoids the
+- abovementioned localtime.c bug as well as similar bugs present in
++ localtime.c bug mentioned above, as well as similar bugs present in
+ many client implementations. If no Expires line is present, zic
+ -L instead truncates the TZif output based on the #expires comment
+ present in leapseconds files distributed by tzdb 2018f and later;
+@@ -6666,7 +6729,7 @@
+ numbers. Recent releases also come in an experimental format
+ consisting of a single tarball tzdb-R.tar.lz with extra data.
+
+-Release timestamps are taken from the release's commit (for newer,
++A release’s timestamp is taken from the release’s commit (for newer,
+ Git-based releases), from the newest file in the tarball (for older
+ releases, where this info is available) or from the email announcing
+ the release (if all else fails; these are marked with a time zone
+--- contrib/tzdata/africa.orig
++++ contrib/tzdata/africa
+@@ -597,6 +597,24 @@
+ # Morocco
+ # See Africa/Ceuta for Spanish Morocco.
+
++# From Paul Eggert (2026-06-26):
++# In “Morocco’s GMT+1, a century of shifting time and a debate far from over”
++# https://en.yabiladi.com/articles/details/191310/morocco-s-gmt1-century-shifting-time
++# (2026-03-30), Yabiladi’s Latifa Babas reports the following:
++# * A 1913-10-26 royal dahir established GMT as legal time in Morocco.
++# * A 1918-05-10 dahir instituted DST on 1918-05-16 at 00:00.
++# * A September 1939 dahir restarted DST on 1939-09-12.
++# * A February 1940 dahir restarted DST as early as 1940-02-25.
++# * Standard time resumed in September 1946.
++# * A June 1950 decree restarted DST, which ran until as late as October.
++# * Royal decree 455-67 (1967-06-02) restarted DST on June 3 at noon.
++# * After 1967 Morocco used DST “during several summers, particularly
++# throughout the 1970s and 1980s.”
++# Babas consulted official records that disagree with and are surely
++# more correct than our pre-2008 timestamp data, which came from the
++# unreliable Shanks & Pottenger. Unfortunately, Babas did not provide
++# enough detail to correct our data.
++
+ # From Alex Krivenyshev (2008-05-09):
+ # Here is an article that Morocco plan to introduce Daylight Saving Time between
+ # 1 June, 2008 and 27 September, 2008.
+@@ -850,33 +868,16 @@
+ # The return to legal GMT time will take place this Sunday, March 19 at 3 a.m.
+ # ... the return to GMT+1 will be made on Sunday April 23, 2023 at 2 a.m.
+ # https://www.mmsp.gov.ma/fr/actualites/passage-à-l%E2%80%99heure-gmt-à-partir-du-dimanche-19-mars-2023
+-#
+-# From Paul Eggert (2023-03-14):
+-# For now, guess that in the future Morocco will fall back at 03:00
+-# the last Sunday before Ramadan, and spring forward at 02:00 the
+-# first Sunday after one day after Ramadan. To implement this,
+-# transition dates and times for 2019 through 2087 were determined by
+-# running the following program under GNU Emacs 28.2. (This algorithm
+-# also produces the correct transition dates for 2016 through 2018,
+-# though the times differ due to Morocco's time zone change in 2018.)
+-# (let ((islamic-year 1440))
+-# (require 'cal-islam)
+-# (while (< islamic-year 1511)
+-# (let ((a (calendar-islamic-to-absolute (list 9 1 islamic-year)))
+-# (b (+ 1 (calendar-islamic-to-absolute (list 10 1 islamic-year))))
+-# (sunday 0))
+-# (while (/= sunday (mod (setq a (1- a)) 7)))
+-# (while (/= sunday (mod b 7))
+-# (setq b (1+ b)))
+-# (setq a (calendar-gregorian-from-absolute a))
+-# (setq b (calendar-gregorian-from-absolute b))
+-# (insert
+-# (format
+-# (concat "Rule\tMorocco\t%d\tonly\t-\t%s\t%2d\t 3:00\t-1:00\t-\n"
+-# "Rule\tMorocco\t%d\tonly\t-\t%s\t%2d\t 2:00\t0\t-\n")
+-# (car (cdr (cdr a))) (calendar-month-name (car a) t) (car (cdr a))
+-# (car (cdr (cdr b))) (calendar-month-name (car b) t) (car (cdr b)))))
+-# (setq islamic-year (+ 1 islamic-year))))
++
++# From Paul Eggert (2026-06-25):
++# https://www.moroccoworldnews.com/2026/06/325034/confirmed-morocco-to-restore-gmt-on-september-20-ending-eight-year-gmt1-saga/
++# Today the Moroccan government adopted Decree No. 2.26.530, which abrogates
++# the 2018 decree that put it at +01 with daylight saving during Ramadan.
++# The plan is to go back to +00 without DST on 2026-09-20 at 02:00.
++# From Anass Taghjichte (2026-07-03):
++# https://www.sgg.gov.ma/BO/AR/3111/2026/BO_7521_Ar.pdf
++# From Afaf EL MAAYATI (2026-07-06):
++# https://www.mapexpress.ma/actualite/activite-gouvernementale/conseil-gouvernement-approuve-projet-decret-relatif-au-retour-lheure-legale/
+
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule Morocco 1939 only - Sep 12 0:00 1:00 -
+@@ -936,143 +937,14 @@
+ Rule Morocco 2025 only - Apr 6 2:00 0 -
+ Rule Morocco 2026 only - Feb 15 3:00 -1:00 -
+ Rule Morocco 2026 only - Mar 22 2:00 0 -
+-Rule Morocco 2027 only - Feb 7 3:00 -1:00 -
+-Rule Morocco 2027 only - Mar 14 2:00 0 -
+-Rule Morocco 2028 only - Jan 23 3:00 -1:00 -
+-Rule Morocco 2028 only - Mar 5 2:00 0 -
+-Rule Morocco 2029 only - Jan 14 3:00 -1:00 -
+-Rule Morocco 2029 only - Feb 18 2:00 0 -
+-Rule Morocco 2029 only - Dec 30 3:00 -1:00 -
+-Rule Morocco 2030 only - Feb 10 2:00 0 -
+-Rule Morocco 2030 only - Dec 22 3:00 -1:00 -
+-Rule Morocco 2031 only - Jan 26 2:00 0 -
+-Rule Morocco 2031 only - Dec 14 3:00 -1:00 -
+-Rule Morocco 2032 only - Jan 18 2:00 0 -
+-Rule Morocco 2032 only - Nov 28 3:00 -1:00 -
+-Rule Morocco 2033 only - Jan 9 2:00 0 -
+-Rule Morocco 2033 only - Nov 20 3:00 -1:00 -
+-Rule Morocco 2033 only - Dec 25 2:00 0 -
+-Rule Morocco 2034 only - Nov 5 3:00 -1:00 -
+-Rule Morocco 2034 only - Dec 17 2:00 0 -
+-Rule Morocco 2035 only - Oct 28 3:00 -1:00 -
+-Rule Morocco 2035 only - Dec 9 2:00 0 -
+-Rule Morocco 2036 only - Oct 19 3:00 -1:00 -
+-Rule Morocco 2036 only - Nov 23 2:00 0 -
+-Rule Morocco 2037 only - Oct 4 3:00 -1:00 -
+-Rule Morocco 2037 only - Nov 15 2:00 0 -
+-Rule Morocco 2038 only - Sep 26 3:00 -1:00 -
+-Rule Morocco 2038 only - Oct 31 2:00 0 -
+-Rule Morocco 2039 only - Sep 18 3:00 -1:00 -
+-Rule Morocco 2039 only - Oct 23 2:00 0 -
+-Rule Morocco 2040 only - Sep 2 3:00 -1:00 -
+-Rule Morocco 2040 only - Oct 14 2:00 0 -
+-Rule Morocco 2041 only - Aug 25 3:00 -1:00 -
+-Rule Morocco 2041 only - Sep 29 2:00 0 -
+-Rule Morocco 2042 only - Aug 10 3:00 -1:00 -
+-Rule Morocco 2042 only - Sep 21 2:00 0 -
+-Rule Morocco 2043 only - Aug 2 3:00 -1:00 -
+-Rule Morocco 2043 only - Sep 13 2:00 0 -
+-Rule Morocco 2044 only - Jul 24 3:00 -1:00 -
+-Rule Morocco 2044 only - Aug 28 2:00 0 -
+-Rule Morocco 2045 only - Jul 9 3:00 -1:00 -
+-Rule Morocco 2045 only - Aug 20 2:00 0 -
+-Rule Morocco 2046 only - Jul 1 3:00 -1:00 -
+-Rule Morocco 2046 only - Aug 5 2:00 0 -
+-Rule Morocco 2047 only - Jun 23 3:00 -1:00 -
+-Rule Morocco 2047 only - Jul 28 2:00 0 -
+-Rule Morocco 2048 only - Jun 7 3:00 -1:00 -
+-Rule Morocco 2048 only - Jul 19 2:00 0 -
+-Rule Morocco 2049 only - May 30 3:00 -1:00 -
+-Rule Morocco 2049 only - Jul 4 2:00 0 -
+-Rule Morocco 2050 only - May 15 3:00 -1:00 -
+-Rule Morocco 2050 only - Jun 26 2:00 0 -
+-Rule Morocco 2051 only - May 7 3:00 -1:00 -
+-Rule Morocco 2051 only - Jun 18 2:00 0 -
+-Rule Morocco 2052 only - Apr 28 3:00 -1:00 -
+-Rule Morocco 2052 only - Jun 2 2:00 0 -
+-Rule Morocco 2053 only - Apr 13 3:00 -1:00 -
+-Rule Morocco 2053 only - May 25 2:00 0 -
+-Rule Morocco 2054 only - Apr 5 3:00 -1:00 -
+-Rule Morocco 2054 only - May 10 2:00 0 -
+-Rule Morocco 2055 only - Mar 28 3:00 -1:00 -
+-Rule Morocco 2055 only - May 2 2:00 0 -
+-Rule Morocco 2056 only - Mar 12 3:00 -1:00 -
+-Rule Morocco 2056 only - Apr 23 2:00 0 -
+-Rule Morocco 2057 only - Mar 4 3:00 -1:00 -
+-Rule Morocco 2057 only - Apr 8 2:00 0 -
+-Rule Morocco 2058 only - Feb 17 3:00 -1:00 -
+-Rule Morocco 2058 only - Mar 31 2:00 0 -
+-Rule Morocco 2059 only - Feb 9 3:00 -1:00 -
+-Rule Morocco 2059 only - Mar 23 2:00 0 -
+-Rule Morocco 2060 only - Feb 1 3:00 -1:00 -
+-Rule Morocco 2060 only - Mar 7 2:00 0 -
+-Rule Morocco 2061 only - Jan 16 3:00 -1:00 -
+-Rule Morocco 2061 only - Feb 27 2:00 0 -
+-Rule Morocco 2062 only - Jan 8 3:00 -1:00 -
+-Rule Morocco 2062 only - Feb 12 2:00 0 -
+-Rule Morocco 2062 only - Dec 31 3:00 -1:00 -
+-Rule Morocco 2063 only - Feb 4 2:00 0 -
+-Rule Morocco 2063 only - Dec 16 3:00 -1:00 -
+-Rule Morocco 2064 only - Jan 27 2:00 0 -
+-Rule Morocco 2064 only - Dec 7 3:00 -1:00 -
+-Rule Morocco 2065 only - Jan 11 2:00 0 -
+-Rule Morocco 2065 only - Nov 22 3:00 -1:00 -
+-Rule Morocco 2066 only - Jan 3 2:00 0 -
+-Rule Morocco 2066 only - Nov 14 3:00 -1:00 -
+-Rule Morocco 2066 only - Dec 26 2:00 0 -
+-Rule Morocco 2067 only - Nov 6 3:00 -1:00 -
+-Rule Morocco 2067 only - Dec 11 2:00 0 -
+-Rule Morocco 2068 only - Oct 21 3:00 -1:00 -
+-Rule Morocco 2068 only - Dec 2 2:00 0 -
+-Rule Morocco 2069 only - Oct 13 3:00 -1:00 -
+-Rule Morocco 2069 only - Nov 17 2:00 0 -
+-Rule Morocco 2070 only - Oct 5 3:00 -1:00 -
+-Rule Morocco 2070 only - Nov 9 2:00 0 -
+-Rule Morocco 2071 only - Sep 20 3:00 -1:00 -
+-Rule Morocco 2071 only - Nov 1 2:00 0 -
+-Rule Morocco 2072 only - Sep 11 3:00 -1:00 -
+-Rule Morocco 2072 only - Oct 16 2:00 0 -
+-Rule Morocco 2073 only - Aug 27 3:00 -1:00 -
+-Rule Morocco 2073 only - Oct 8 2:00 0 -
+-Rule Morocco 2074 only - Aug 19 3:00 -1:00 -
+-Rule Morocco 2074 only - Sep 30 2:00 0 -
+-Rule Morocco 2075 only - Aug 11 3:00 -1:00 -
+-Rule Morocco 2075 only - Sep 15 2:00 0 -
+-Rule Morocco 2076 only - Jul 26 3:00 -1:00 -
+-Rule Morocco 2076 only - Sep 6 2:00 0 -
+-Rule Morocco 2077 only - Jul 18 3:00 -1:00 -
+-Rule Morocco 2077 only - Aug 22 2:00 0 -
+-Rule Morocco 2078 only - Jul 10 3:00 -1:00 -
+-Rule Morocco 2078 only - Aug 14 2:00 0 -
+-Rule Morocco 2079 only - Jun 25 3:00 -1:00 -
+-Rule Morocco 2079 only - Aug 6 2:00 0 -
+-Rule Morocco 2080 only - Jun 16 3:00 -1:00 -
+-Rule Morocco 2080 only - Jul 21 2:00 0 -
+-Rule Morocco 2081 only - Jun 1 3:00 -1:00 -
+-Rule Morocco 2081 only - Jul 13 2:00 0 -
+-Rule Morocco 2082 only - May 24 3:00 -1:00 -
+-Rule Morocco 2082 only - Jun 28 2:00 0 -
+-Rule Morocco 2083 only - May 16 3:00 -1:00 -
+-Rule Morocco 2083 only - Jun 20 2:00 0 -
+-Rule Morocco 2084 only - Apr 30 3:00 -1:00 -
+-Rule Morocco 2084 only - Jun 11 2:00 0 -
+-Rule Morocco 2085 only - Apr 22 3:00 -1:00 -
+-Rule Morocco 2085 only - May 27 2:00 0 -
+-Rule Morocco 2086 only - Apr 14 3:00 -1:00 -
+-Rule Morocco 2086 only - May 19 2:00 0 -
+-Rule Morocco 2087 only - Mar 30 3:00 -1:00 -
+-Rule Morocco 2087 only - May 11 2:00 0 -
+-# For dates after the somewhat-arbitrary cutoff of 2087, assume that
+-# Morocco will no longer observe DST. At some point this table will
+-# need to be extended, though quite possibly Morocco will change the
+-# rules first.
+
+ # Zone NAME STDOFF RULES FORMAT [UNTIL]
+ Zone Africa/Casablanca -0:30:20 - LMT 1913 Oct 26
+ 0:00 Morocco %z 1984 Mar 16
+ 1:00 - %z 1986
+ 0:00 Morocco %z 2018 Oct 28 3:00
+- 1:00 Morocco %z
++ 1:00 Morocco %z 2026 Sep 20 2:00
++ 0:00 - %z
+
+ # Western Sahara
+ #
+@@ -1088,7 +960,8 @@
+ Zone Africa/El_Aaiun -0:52:48 - LMT 1934 Jan # El Aaiún
+ -1:00 - %z 1976 Apr 14
+ 0:00 Morocco %z 2018 Oct 28 3:00
+- 1:00 Morocco %z
++ 1:00 Morocco %z 2026 Sep 20 2:00
++ 0:00 - %z
+
+ # Botswana
+ # Burundi
+--- contrib/tzdata/australasia.orig
++++ contrib/tzdata/australasia
+@@ -1721,7 +1721,7 @@
+ # to Japanese rule was right before 1970, ... per the current tz database
+ # rule, the information doesn't warrant creation of a new timezone for Bonin
+ # Islands itself and is thus as an anecdotal note for interest purpose only.
+-# ... [The abovementioned link] described some special timekeeping phenomenon
++# ... [The link mentioned above] described some special timekeeping phenomenon
+ # regarding Marcus island, another remote island currently owned by Japanese
+ # in the same administrative unit as Bonin Islands. Many reports claim that
+ # the American coastal guard on the American quarter of the island use its own
+--- contrib/tzdata/europe.orig
++++ contrib/tzdata/europe
+@@ -230,7 +230,7 @@
+ # https://www.polyomino.org.uk/british-time/bbc-19410418.png
+ # https://www.polyomino.org.uk/british-time/ho-19410421.png
+
+-# From Sir Alexander Maxwell in the above-mentioned letter (1941-04-21):
++# From Sir Alexander Maxwell (1941-04-21) in the letter mentioned above:
+ # [N]o official designation has as far as I know been adopted for the time
+ # which is to be introduced in May....
+ # I cannot think of anything better than "Double British Summer Time"
+@@ -2015,7 +2015,7 @@
+ # From Roman Tudos (2015-07-02):
+ # http://lex.justice.md/index.php?action=view&view=doc&lang=1&id=355077
+ # From Paul Eggert (2015-07-01):
+-# The abovementioned official link to IGO1445-868/2014 states that
++# The above-mentioned official link to IGO1445-868/2014 states that
+ # 2014-10-26's fallback transition occurred at 03:00 local time. Also,
+ # https://www.trm.md/en/social/la-30-martie-vom-trece-la-ora-de-vara
+ # says the 2014-03-30 spring-forward transition was at 02:00 local time.
+@@ -2380,10 +2380,17 @@
+ # https://oal.ul.pt/hora-legal/legislacao/
+ # working backward through references of revocation and abrogation to
+ # Decreto-Lei 47233 of 1966-10-01, the last time DST was abolished across the
+-# mainland and its adjacent islands. Because of that reference, it is
+-# therefore assumed that DST rules in the islands prior to 1966 were like that
+-# of the mainland, though most legislation of the time didn't explicitly
+-# specify DST practices for the islands.
++# mainland and its adjacent islands.
++#
++# From Tim Parenti (2026-05-26):
++# Observance of DST on the Azores and Madeira was explicitly covered by
++# mainland legislation in:
++# - Portaria 11767 of 1947-03-28 for 1947,
++# - Portaria 12286 of 1948-02-19 for 1948, and
++# - Decreto-Lei 37048 of 1948-09-07 through its revocation in 1966.
++# (See mainland commentary, above.) However, most legislation prior to 1947
++# didn't explicitly call out these "adjacent islands", so we assume that DST
++# rules on the islands prior to 1947 were also like that of the mainland.
+ Zone Atlantic/Azores -1:42:40 - LMT 1884 # Ponta Delgada
+ -1:54:32 - HMT 1912 Jan 1 2:00u # Horta MT
+ # Vanguard section, for zic and other parsers that support %z.
+@@ -2616,7 +2623,7 @@
+ # http://astro.uni-altai.ru/~orion/blog/2011/11/novyie-granitsyi-chasovyih-poyasov-v-sssr/
+ #
+ # From Paul Eggert (2018-07-16):
+-# Perhaps someone could translate the above-mentioned link and use it
++# Perhaps someone could translate the link mentioned above, and use it
+ # to correct our data for the ex-Soviet Union. It cites the following:
+ # «Поясное время и новые границы часовых поясов» / сост. П.Н. Долгов,
+ # отв. ред. Г.Д. Бурдун - М: Комитет стандартов, мер и измерительных
+--- contrib/tzdata/leap-seconds.list.orig
++++ contrib/tzdata/leap-seconds.list
+@@ -60,15 +60,15 @@
+ #
+ # The following line shows the last update of this file in NTP timestamp:
+ #
+-#$ 3976686858
++#$ 3992312697
+ #
+ # 2) Expiration date of the file given on a semi-annual basis: last June or last December
+ #
+-# File expires on 28 December 2026
++# File expires on 28 June 2027
+ #
+ # Expire date in NTP timestamp:
+ #
+-#@ 4007404800
++#@ 4023129600
+ #
+ #
+ # LIST OF LEAP SECONDS
+@@ -117,4 +117,4 @@
+ # please see the readme file in the 'source' directory :
+ # https://hpiers.obspm.fr/iers/bul/bulc/ntp/sources/README
+ #
+-#h 2e101270 4e6749f8 2f1792b7 14a0c188 36bb19d6
++#h a9bad145 84c31c70 758402aa b37bfd54 5923836a
+--- contrib/tzdata/leapseconds.orig
++++ contrib/tzdata/leapseconds
+@@ -70,7 +70,7 @@
+ # Any additional leap seconds will come after this.
+ # This Expires line is commented out for now,
+ # so that pre-2020a zic implementations do not reject this file.
+-#Expires 2026 Dec 28 00:00:00
++#Expires 2027 Jun 28 00:00:00
+
+ # Here are POSIX timestamps for the data in this file.
+ # "#updated" gives the last time the leap seconds data changed
+@@ -79,8 +79,8 @@
+ # "#expires" gives the first time this file might be wrong;
+ # if this file was derived from the IERS leap-seconds.list,
+ # this is typically a bit less than one year after "updated".
+-#updated 1767698058 (2026-01-06 11:14:18 UTC)
+-#expires 1798416000 (2026-12-28 00:00:00 UTC)
++#updated 1783323897 (2026-07-06 07:44:57 UTC)
++#expires 1814140800 (2027-06-28 00:00:00 UTC)
+
+ # Updated through IERS Bulletin C (https://hpiers.obspm.fr/iers/bul/bulc/bulletinc.dat)
+-# File expires on 28 December 2026
++# File expires on 28 June 2027
+--- contrib/tzdata/northamerica.orig
++++ contrib/tzdata/northamerica
+@@ -1742,6 +1742,22 @@
+
+ # Manitoba
+
++# From Paul Eggert (2026-05-08):
++# For 1916 timestamps America/Winnipeg covers only a small region. See:
++# Cassidy C. Winnipeg’s 110-year history with daylight time.
++# Winnipeg Free Press. 2026-05-06.
++# https://www.winnipegfreepress.com/our-communities/correspondents/2026/05/06/winnipegs-110-year-history-with-daylight-time
++# Of the 1916 experiment, Cassidy writes: “As rural areas and nearby
++# urban centres such as Selkirk and Brandon did not adopt DST, the
++# City of Winnipeg essentially had its own time zone.” Cassidy also
++# writes that province-wide DST came into effect on 1963-05-12.
++#
++# Shanks & Pottenger write that Winnipeg did not observe DST in 1964 and 1965.
++# Although dubious in the light of Cassidy’s article, we lack a better source.
++# Perhaps S&P’s data are for the train stations, not for the city?
++# Also, S&P say Manitoba switched at 02:00 (not 02:00s) starting in 1966.
++# Since 02:00s is clearly correct for 1967 on, assume 02:00s in 1966 too.
++
+ # From Rob Douglas (2006-04-06):
+ # the old Manitoba Time Act - as amended by Bill 2, assented to
+ # March 27, 1987 ... said ...
+@@ -1756,11 +1772,6 @@
+ # the 1987 version would apply - the changeover was at 2:00 Central
+ # Standard Time (i.e. not until 3:00 Central Daylight Time).
+
+-# From Paul Eggert (2006-04-10):
+-# Shanks & Pottenger say Manitoba switched at 02:00 (not 02:00s)
+-# starting 1966. Since 02:00s is clearly correct for 1967 on, assume
+-# it was also 02:00s in 1966.
+-
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule Winn 1916 only - Apr 23 0:00 1:00 D
+ Rule Winn 1916 only - Sep 17 0:00 0 S
+@@ -1852,6 +1863,22 @@
+ # long and rather painful to read.
+ # http://www.qp.gov.sk.ca/documents/English/Statutes/Statutes/T14.pdf
+
++# From Heitor David Pinto (2026-05-14):
++# In Saskatchewan, a bill was passed to replace the Time Act. It sets UTC-6 all
++# year in the whole province, including Lloydminster, but allows the government
++# to issue regulations specifying a different time in localities that request
++# so:
++# https://docs.legassembly.sk.ca/legdocs/Bills/30L2S/Bill30-58.pdf
++# The bill ... received royal assent today.
++# From Tim Parenti (2026-05-14):
++# In light of Alberta joining Saskatchewan on year-round -06, this simplifies
++# the prior Act's framework for the many local exceptions to year-round -06 in
++# border areas, by extending province-wide the notion of "time option areas"
++# which can be prescribed by regulation "if it is in the provincial interest"
++# for those areas to observe either "UTC-5, UTC-6 or UTC-7 for all or part of
++# the year" on at least 30 days' notice.
++# The new Act comes into force by order of the Lieutenant Governor in Council.
++
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule Regina 1918 only - Apr 14 2:00 1:00 D
+ Rule Regina 1918 only - Oct 27 2:00 0 S
+@@ -1902,6 +1929,45 @@
+ # Boyer JP. Forcing Choice: The Risky Reward of Referendums. Dundum. 2017.
+ # ISBN 978-1459739123.
+
++# From Roozbeh Pournader (2026-04-20):
++# https://calgaryherald.com/opinion/columnists/bell-alberta-daylight-time-year-round-premier-danielle-smith
++#
++# From Tim Parenti (2026-04-23):
++# Section 3 of Bill 31, the Red Tape Reduction Statutes Amendment Act, 2026
++# https://docs.assembly.ab.ca/LADDAR_files/docs/bills/bill/legislature_31/session_2/20251023_bill-031.pdf
++# would repeal the Daylight Saving Time Act in the Revised Statutes of Alberta
++# 2000 Chapter D-5:
++# https://kings-printer.alberta.ca/documents/Acts/D05.pdf
++# ...and substitutes a new chapter with language that closely parallels the
++# original. The new title is the Official Time Act and will be numbered
++# Chapter O-5.7. The Act establishes a standard time of UTC−6 without
++# replacing the language previously used to effectuate DST.
++#
++# From Tim Parenti (2026-06-19):
++# After receiving Royal Assent on 2026-05-14, Order in Council 204/2026 was
++# issued on 2026-06-18 proclaiming the relevant section of the bill in force on
++# the same date. Order in Council 206/2026, issued the same day, uses the
++# regulatory authority within the Act to prescribe the official term "Alberta
++# Time"; we use the traditional abbreviation CST for consistency.
++# https://kings-printer.alberta.ca/Documents/Orders/Orders_in_Council/2026/2026_204.pdf
++# https://kings-printer.alberta.ca/Documents/Orders/Orders_in_Council/2026/2026_206.pdf
++#
++# Since wall clock times do not diverge from past practice until 2026-11-01,
++# use that transition date for now to work around potential CLDR limitations in
++# the meantime; see British Columbia, below.
++#
++# From Paul Eggert (2026-07-02):
++# The temporary hack for Alberta is needed for CLDR 48.2 (2026-03-17)
++# and earlier, not the CLDR 48.1-and-earlier which drives BC’s temporary hack.
++# Only a few platforms track minor CLDR releases, though, so the two
++# temporary hacks have roughly the same effect in practice.
++#
++# The term “Alberta Time” is legally prescribed from yesterday until
++# 2031-06-30, when the regulation in OiC 206/2026 expires to ensure that the
++# term is reviewed by then for relevancy and need. This plan for possible
++# obsolescence affects neither timekeeping nor TZDB’s data, which do
++# not contain the string “Alberta Time”.
++
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule Edm 1918 1919 - Apr Sun>=8 2:00 1:00 D
+ Rule Edm 1918 only - Oct 27 2:00 0 S
+@@ -1919,7 +1985,11 @@
+ # Zone NAME STDOFF RULES FORMAT [UNTIL]
+ Zone America/Edmonton -7:33:52 - LMT 1906 Sep
+ -7:00 Edm M%sT 1987
+- -7:00 Canada M%sT
++ -7:00 Canada M%sT 2026 Jun 18
++ # Temporary hack; see above.
++ -7:00 1:00 MDT 2026 Nov 1 2:00
++ # End of temporary hack.
++ -6:00 - CST
+
+
+ # British Columbia
+@@ -1962,7 +2032,7 @@
+ # on March 8 will be the last time change, ending twice-yearly clock changes.”
+ # https://news.gov.bc.ca/releases/2026AG0013-000209
+ #
+-# From Paul Eggert (2026-03-07):
++# From Paul Eggert (2026-07-02):
+ # The law says that 21 hours after the usual 2026-03-08 02:00 switch from
+ # PST to PDT, the next day inaugurates the new standard time Pacific Time,
+ # i.e., just one clock change but two name changes separated by 21 hours.
+@@ -1971,13 +2041,14 @@
+ # I asked the BC government for advice, with no response. For now, do this:
+ # 1. As a temporary hack, pretend that the BC law takes effect
+ # not on 2026-03-09 at 00:00, but on 2026-11-01 at 02:00.
+-# This pretense works around a limitation in CLDR v48.2 (2026-03-17),
++# This pretense works around a limitation in CLDR 48.1 (2026-01-08),
+ # which would otherwise say the interval uses “Pacific Standard Time”.
+ # (Below, this temporary hack is marked “Temporary hack; see above.”)
+ # Strictly speaking this hack is incorrect since the interval uses
+ # standard time, but it does have the right UT offset and it
+ # works around the CLDR limitation. We should be able to remove
+-# the temporary hack after CLDR is fixed.
++# the temporary hack by November when there would be little point
++# to keeping it anyway.
+ # 2. After the BC law takes effect, model the time as MST sans DST.
+ # We can change this later if another conforming non-numeric abbreviation
+ # for Pacific Time becomes more popular. Possibilities include:
+@@ -1988,10 +2059,7 @@
+ # PST - straightforward but even more confusing,
+ # and will likely break much software that assumes PST is -08
+ # -07 - accurate and clear in itself, but makes BC look odd vs neighbors
+-# CPT, CPST - for Canadian Pacific (Standard) Time,
+-# by analogy with AEST in Australia
+-# P-T - conforming approximation to “PT”
+-# PT+ - like P-T but suggesting one-hour advance over PST
++# PacT - straightforward but novel abbreviation for Pacific Time
+
+ # From Chris Walton (2026-03-15):
+ # The Regional District of East Kootenay is planning to move to year-round
+@@ -2006,6 +2074,10 @@
+ # saying, “Pardon the pun, but this is not a time-sensitive issue.”
+ # For now, merely mention the potential change in these comments.
+ # If it happens it would likely affect clocks starting 2027-03-14 at 02:00.
++# From Tim Parenti (2026-05-14):
++# RDEK has historically been aligned with neighboring Alberta. With the latter
++# now opting to stay on -06 year-round, if RDEK does not follow, it would
++# require a new zone for the Cranbrook area.
+
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule Vanc 1918 only - Apr 14 2:00 1:00 D
+@@ -2022,7 +2094,7 @@
+ -8:00 Vanc P%sT 1987
+ -8:00 Canada P%sT 2026 Mar 9
+ # Temporary hack; see above.
+- -8:00 1:00 PDT 2026 Nov 1 02:00
++ -8:00 1:00 PDT 2026 Nov 1 2:00
+ # End of temporary hack.
+ -7:00 - MST
+ Zone America/Dawson_Creek -8:00:56 - LMT 1884
+@@ -2350,6 +2422,23 @@
+ # about 1970, and uses PST for standard time in Yukon since then. Consistent
+ # with that, use MST for -07, the new standard time in Yukon effective Nov. 1.
+
++# From Tim Parenti (2026-04-21):
++# "[Northwest Territories] Premier R.J. Simpson announced Monday that the
++# territory will move to end seasonal time changes and will adopt a year-round
++# time standard instead. ... Simpson has previously said the territory wouldn't
++# end seasonal time changes until Alberta does."
++# https://www.cbc.ca/news/canada/north/nwt-ends-daylight-saving-9.7170964
++#
++# From Tim Parenti (2026-06-19), per James Bellaire (2026-06-02):
++# Much of NWT has, to date, been represented by America/Edmonton, which alias
++# America/Yellowknife links to. While Bill 13 (assented to 2021-03-31) would
++# enable NWT's proposed change mirroring Alberta's, at time of writing it has
++# not yet been formally enacted; if it doesn't move forward as expected,
++# America/Yellowknife would need to become its own zone as Alberta has stopped
++# changing its clocks.
++# If it does go ahead, draft changes to America/Inuvik, which represents the
++# remainder of NWT, are commented below.
++
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule NT_YK 1918 only - Apr 14 2:00 1:00 D
+ Rule NT_YK 1918 only - Oct 27 2:00 0 S
+@@ -2392,6 +2481,10 @@
+ -8:00 NT_YK P%sT 1979 Apr lastSun 2:00
+ -7:00 NT_YK M%sT 1980
+ -7:00 Canada M%sT
++# Assuming Northwest Territories follows Alberta in abolishing seasonal time
++# changes, replace the above line with something like:
++# -7:00 Canada M%sT 2026 Nov 1 2:00
++# -6:00 - CST
+ Zone America/Whitehorse -9:00:12 - LMT 1900 Aug 20
+ -9:00 NT_YK Y%sT 1965
+ -9:00 Yukon Y%sT 1966 Feb 27 0:00
+--- contrib/tzdata/theory.html.orig
++++ contrib/tzdata/theory.html
+@@ -592,10 +592,10 @@
+ locations while uninhabited.
+ The leading "-" is a flag that the UT offset is in
+ some sense undefined; this notation is derived
+- from Internet
++ from Internet
+ RFC 3339.
+ (The abbreviation Z that
+- Internet
++ Internet
+ RFC 9557 uses for this concept
+ would violate the POSIX requirement
+ of at least three characters in an abbreviation.)
+@@ -632,7 +632,7 @@
+ timestamps, and current predictions
+ will be incorrect after future governments change the rules.
+ For example, if today someone schedules a meeting for 13:00 next
+- October 1, Casablanca time, and tomorrow Morocco changes its
++ October 1, Dublin time, and tomorrow Ireland changes its
+ daylight saving rules, software can mess up after the rule change
+ if it blithely relies on conversions made before the change.
+
+@@ -657,7 +657,7 @@
+ zones at all, often not even a stable landscape of mean times,
+ prior to the middle decades of the twentieth century”.
+ See: Timothy Shenk, Booked:
++href="https://dissentmagazine.org/online_articles/booked-a-global-history-of-time-vanessa-ogle/">Booked:
+ A Global History of Time. Dissent 2015-12-17.
+
+
+@@ -938,7 +938,7 @@
+ has a format that is hard to describe and is error-prone in practice.
+ Also, proleptic TZ strings cannot deal with daylight
+ saving time rules not based on the Gregorian calendar (as in
+- Morocco), or with situations where more than two time zone
++ Palestine), or with situations where more than two time zone
+ abbreviations or UT offsets are used in an area.
+
+
+@@ -1128,7 +1128,7 @@
+ the name of a file from which time-related information is read.
+ The file’s format is TZif,
+ a timezone information format that contains binary data; see
+- Internet
++ Internet
+ RFC 9636.
+ The daylight saving time rules to be used for a
+ particular timezone are encoded in the
+@@ -1212,8 +1212,8 @@
+
+
+ The tm_isdst member is almost never needed and most of
+- its uses should be discouraged in favor of the abovementioned
+- APIs.
++ its uses should be discouraged in favor of the
++ APIs mentioned above.
+ It was intended as an index into the tzname variable,
+ but as mentioned previously that usage is obsolete.
+ Although it can still be used in arguments to
+@@ -1558,7 +1558,7 @@
+ Michael Allison and Robert Schmunk,
+ “Technical
+ Notes on Mars Solar Time as Adopted by the Mars24 Sunclock”
+- (2020-03-08).
++ (2023-05-15).
+
+
+ Zara Mirmalek,
+--- contrib/tzdata/version.orig
++++ contrib/tzdata/version
+@@ -1 +1 @@
+-2026b
++2026c
+--- contrib/tzdata/ziguard.awk.orig
++++ contrib/tzdata/ziguard.awk
+@@ -184,7 +184,7 @@
+ dstoff = get_minutes(rules)
+ } else {
+ # The DST offset is normally an hour, but there are special cases.
+- if (rules == "Morocco" && NF == 3) {
++ if (rules == "Morocco" && $4 == 2026) {
+ dstoff = -60
+ } else if (rules == "NBorneo") {
+ dstoff = 20
+@@ -286,13 +286,13 @@
+ }
+ }
+ }
+- if ($1 ~ /^[+0-9-]/ && NF == 3) {
++ if ($1 ~ /^[+0-9-]/ && $4 == 2026) {
+ if (DATAFORM == "rearguard") {
+ sub(/1:00\tMorocco/, "0:00\tMorocco")
+- sub(/\t\+01\/\+00$/, "\t+00/+01")
++ sub(/\t\+01\/\+00/, "\t+00/+01")
+ } else {
+ sub(/0:00\tMorocco/, "1:00\tMorocco")
+- sub(/\t\+00\/+01$/, "\t+01/+00")
++ sub(/\t\+00\/+01/, "\t+01/+00")
+ }
+ }
+ }
+--- contrib/tzdata/zone.tab.orig
++++ contrib/tzdata/zone.tab
+@@ -121,7 +121,7 @@
+ CA +624900-0920459 America/Rankin_Inlet Central - NU (central)
+ CA +5024-10439 America/Regina CST - SK (most areas)
+ CA +5017-10750 America/Swift_Current CST - SK (midwest)
+-CA +5333-11328 America/Edmonton Mountain - AB, BC(E), NT(E), SK(W)
++CA +5333-11328 America/Edmonton CST - AB, BC(E), NT(E), SK(W)
+ CA +690650-1050310 America/Cambridge_Bay Mountain - NU (west)
+ CA +682059-1334300 America/Inuvik Mountain - NT (west)
+ CA +4916-12307 America/Vancouver MST - BC (most areas)
+--- contrib/tzdata/zone1970.tab.orig
++++ contrib/tzdata/zone1970.tab
+@@ -113,7 +113,7 @@
+ CA +624900-0920459 America/Rankin_Inlet Central - NU (central)
+ CA +5024-10439 America/Regina CST - SK (most areas)
+ CA +5017-10750 America/Swift_Current CST - SK (midwest)
+-CA +5333-11328 America/Edmonton Mountain - AB, BC(E), NT(E), SK(W)
++CA +5333-11328 America/Edmonton CST - AB, BC(E), NT(E), SK(W)
+ CA +690650-1050310 America/Cambridge_Bay Mountain - NU (west)
+ CA +682059-1334300 America/Inuvik Mountain - NT (west)
+ CA +4916-12307 America/Vancouver MST - BC (most areas)
+--- contrib/tzdata/zonenow.tab.orig
++++ contrib/tzdata/zonenow.tab
+@@ -56,16 +56,19 @@
+ XX -2504-13005 Pacific/Pitcairn Pitcairn
+ #
+ # -08/-07 - PST/PDT (North America DST)
+-XX +340308-1181434 America/Los_Angeles Pacific (PST/PDT) - US & Canada; Mexico near US border
++XX +340308-1181434 America/Los_Angeles Pacific (PST/PDT) - US; Mexico near US border
+ #
+ # -08/-07 - PST/PDT (North America DST) until 2026-11-01 02:00; then MST
+-XX +4916-12307 America/Vancouver MST - BC (most areas)
++XX +4916-12307 America/Vancouver Mountain Standard (MST) - British Columbia (most areas)
+ #
+ # -07 - MST
+ XX +332654-1120424 America/Phoenix Mountain Standard (MST) - Arizona; western Mexico; Yukon
+ #
+ # -07/-06 - MST/MDT (North America DST)
+-XX +394421-1045903 America/Denver Mountain (MST/MDT) - US & Canada; Mexico near US border
++XX +394421-1045903 America/Denver Mountain (MST/MDT) - US; Mexico near US border; northern Canada
++#
++# -07/-06 - MST/MDT (North America DST) until 2026-11-01 02:00; then CST
++XX +5333-11328 America/Edmonton Central Standard (CST) - Alberta and some neighbors
+ #
+ # -06
+ XX -0054-08936 Pacific/Galapagos Galápagos
diff --git a/website/static/security/patches/EN-26:18/tzdata-2026c.patch.asc b/website/static/security/patches/EN-26:18/tzdata-2026c.patch.asc
new file mode 100644
index 0000000000..1c67f86b3e
--- /dev/null
+++ b/website/static/security/patches/EN-26:18/tzdata-2026c.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkEbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvjSwP/3IBFvyqlPQUZ0vHp0I3
+/Wk9GeYFYmP3qJ3KWFfRro6IzFV+SXCXsF9mzEjWQjKFdV4A2i7OMKI6kNYE2+G7
+jv89m4iSC+T2NYuq+HhpCvPPomSXMTnnWqckl9cmsCGAzOLFYThZyG/BNqIpEibC
+Uzk1Hm6now+XeiNayjzP9LpkqhrOyvougBlaU+5xmYCxA1Z/Vk+I3wdWyzobilxH
+Sri0gYG29avMYrZiQn8BpiHw8JxtCA4l7U8eN6Tb8gKbomCQrvCBk/TOEq/vPgfA
+V/TzmqK6zeSn9X6f847QvI7tryLnV5nqMInE+LN+KXC7lvoJHJvxnCz+p9LvFQ9s
+6ym7U/eMiE39l0WxfO1gN/mLJxiyjVlYPEYrun9bHDmN/b1UfSBx3ZZMh4Hj53XT
+PrVJJhhoiKP6RgpMtrs1J++gWFuDylfhq4auMj0R0l21PA2Zr4PCdDhN5SIWllyY
+cl49vZkwvL2YZCovzTV3HIBYoTtB/bJMwMZdZjvz7mcRhaW6/XIh9Hfkd4W1RfQn
+gLB8sduO3lr+//u60ZvzAFj1vXO6H20qx4KMAx0tYku9/iQDhuUUHXn2XxubKTNK
+GPlkjWGP8my+voUaNdIkLB8sXiGIiF1qp1NU+LPHeSP95sxR98hbI6nCn0JKlXWQ
+ISafE7Ixg/lTt0cZuwpDc1Vr
+=ooko
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-26:19/zfs.patch b/website/static/security/patches/EN-26:19/zfs.patch
new file mode 100644
index 0000000000..854950c98d
--- /dev/null
+++ b/website/static/security/patches/EN-26:19/zfs.patch
@@ -0,0 +1,380 @@
+--- sys/contrib/openzfs/module/os/freebsd/zfs/zvol_os.c.orig
++++ sys/contrib/openzfs/module/os/freebsd/zfs/zvol_os.c
+@@ -128,7 +128,8 @@
+ struct g_provider *zsg_provider;
+ } _zso_geom;
+ } _zso_state;
+- int zso_dying;
++ boolean_t zso_opening;
++ boolean_t zso_dying;
+ };
+
+ static uint32_t zvol_minors;
+@@ -226,12 +227,13 @@
+ }
+
+ retry:
+- zv = atomic_load_ptr(&pp->private);
++ zv = pp->private;
+ if (zv == NULL)
+ return (SET_ERROR(ENXIO));
+
+ mutex_enter(&zv->zv_state_lock);
+- if (zv->zv_zso->zso_dying || zv->zv_flags & ZVOL_REMOVING) {
++ g_topology_unlock();
++ if (zv->zv_flags & ZVOL_REMOVING || zv->zv_zso->zso_dying) {
+ err = SET_ERROR(ENXIO);
+ goto out_locked;
+ }
+@@ -245,18 +247,16 @@
+ if (zv->zv_open_count == 0) {
+ drop_suspend = B_TRUE;
+ if (!rw_tryenter(&zv->zv_suspend_lock, ZVOL_RW_READER)) {
+- mutex_exit(&zv->zv_state_lock);
+-
+ /*
+- * Removal may happen while the locks are down, so
+- * we can't trust zv any longer; we have to start over.
++ * Set a flag to interlock with zvol_os_remove_minor()
++ * while locks are dropped.
+ */
+- zv = atomic_load_ptr(&pp->private);
+- if (zv == NULL)
+- return (SET_ERROR(ENXIO));
+-
++ zv->zv_zso->zso_opening = B_TRUE;
++ mutex_exit(&zv->zv_state_lock);
+ rw_enter(&zv->zv_suspend_lock, ZVOL_RW_READER);
+ mutex_enter(&zv->zv_state_lock);
++ zv->zv_zso->zso_opening = B_FALSE;
++ cv_broadcast(&zv->zv_removing_cv);
+
+ if (zv->zv_zso->zso_dying ||
+ zv->zv_flags & ZVOL_REMOVING) {
+@@ -289,6 +289,7 @@
+ rw_exit(&zv->zv_suspend_lock);
+ drop_suspend = B_FALSE;
+ kern_yield(PRI_USER);
++ g_topology_lock();
+ goto retry;
+ } else {
+ drop_namespace = B_TRUE;
+@@ -337,6 +338,7 @@
+ mutex_exit(&zv->zv_state_lock);
+ if (drop_suspend)
+ rw_exit(&zv->zv_suspend_lock);
++ g_topology_lock();
+ return (err);
+ }
+
+@@ -348,11 +350,12 @@
+ boolean_t drop_suspend = B_TRUE;
+ int new_open_count;
+
+- zv = atomic_load_ptr(&pp->private);
++ zv = pp->private;
+ if (zv == NULL)
+ return (SET_ERROR(ENXIO));
+
+ mutex_enter(&zv->zv_state_lock);
++ g_topology_unlock();
+ if (zv->zv_flags & ZVOL_EXCL) {
+ ASSERT3U(zv->zv_open_count, ==, 1);
+ zv->zv_flags &= ~ZVOL_EXCL;
+@@ -413,6 +416,7 @@
+
+ if (drop_suspend)
+ rw_exit(&zv->zv_suspend_lock);
++ g_topology_lock();
+ return (0);
+ }
+
+@@ -448,7 +452,7 @@
+ ("Unsupported access request to %s (acr=%d, acw=%d, ace=%d).",
+ pp->name, acr, acw, ace));
+
+- if (atomic_load_ptr(&pp->private) == NULL) {
++ if (pp->private == NULL) {
+ if (acr <= 0 && acw <= 0 && ace <= 0)
+ return (0);
+ return (pp->error);
+@@ -473,24 +477,16 @@
+ if (acw != 0)
+ flags |= FWRITE;
+
+- g_topology_unlock();
+ if (count > 0)
+ error = zvol_geom_open(pp, flags, count);
+ else
+ error = zvol_geom_close(pp, flags, -count);
+- g_topology_lock();
+ return (error);
+ }
+
+ static void
+ zvol_geom_bio_start(struct bio *bp)
+ {
+- zvol_state_t *zv = bp->bio_to->private;
+-
+- if (zv == NULL) {
+- g_io_deliver(bp, ENXIO);
+- return;
+- }
+ if (bp->bio_cmd == BIO_GETATTR) {
+ if (zvol_geom_bio_getattr(bp))
+ g_io_deliver(bp, EOPNOTSUPP);
+@@ -507,7 +503,10 @@
+ zvol_state_t *zv;
+
+ zv = bp->bio_to->private;
+- ASSERT3P(zv, !=, NULL);
++ if (zv == NULL) {
++ g_io_deliver(bp, ENXIO);
++ return (0);
++ }
+
+ spa_t *spa = dmu_objset_spa(zv->zv_objset);
+ uint64_t refd, avail, usedobjs, availobjs;
+@@ -920,7 +919,7 @@
+ return (SET_ERROR(ENXIO));
+
+ mutex_enter(&zv->zv_state_lock);
+- if (zv->zv_zso->zso_dying || zv->zv_flags & ZVOL_REMOVING) {
++ if (zv->zv_flags & ZVOL_REMOVING || zv->zv_zso->zso_dying) {
+ err = SET_ERROR(ENXIO);
+ goto out_locked;
+ }
+@@ -1251,24 +1250,32 @@
+ {
+ int error = 0;
+
+- ASSERT(RW_LOCK_HELD(&zvol_state_lock));
++ ASSERT(RW_WRITE_HELD(&zvol_state_lock));
+ ASSERT(MUTEX_HELD(&zv->zv_state_lock));
+
+ /* Move to a new hashtable entry. */
+ zv->zv_hash = zvol_name_hash(newname);
+ hlist_del(&zv->zv_hlink);
+ hlist_add_head(&zv->zv_hlink, ZVOL_HT_HEAD(zv->zv_hash));
++ strlcpy(zv->zv_name, newname, sizeof (zv->zv_name));
++ dataset_kstats_rename(&zv->zv_kstat, newname);
+
+ if (zv->zv_volmode == ZFS_VOLMODE_GEOM) {
+ struct zvol_state_geom *zsg = &zv->zv_zso->zso_geom;
+- struct g_provider *pp = zsg->zsg_provider;
++ struct g_provider *pp;
+ struct g_geom *gp;
+
++ mutex_exit(&zv->zv_state_lock);
+ g_topology_lock();
++ pp = zsg->zsg_provider;
++ if (pp->private == NULL) {
++ g_topology_unlock();
++ mutex_enter(&zv->zv_state_lock);
++ return (SET_ERROR(ENXIO));
++ }
+ gp = pp->geom;
+ ASSERT3P(gp, !=, NULL);
+
+- zsg->zsg_provider = NULL;
+ g_wither_provider(pp, ENXIO);
+
+ pp = g_new_providerf(gp, "%s/%s", ZVOL_DRIVER, newname);
+@@ -1278,6 +1285,7 @@
+ pp->private = zv;
+ zsg->zsg_provider = pp;
+ g_error_provider(pp, 0);
++ mutex_enter(&zv->zv_state_lock);
+ g_topology_unlock();
+ } else if (zv->zv_volmode == ZFS_VOLMODE_DEV) {
+ struct zvol_state_dev *zsd = &zv->zv_zso->zso_dev;
+@@ -1310,8 +1318,6 @@
+ zsd->zsd_cdev = dev;
+ }
+ }
+- strlcpy(zv->zv_name, newname, sizeof (zv->zv_name));
+- dataset_kstats_rename(&zv->zv_kstat, newname);
+
+ return (error);
+ }
+@@ -1400,27 +1406,32 @@
+ void
+ zvol_os_remove_minor(zvol_state_t *zv)
+ {
++ struct zvol_state_os *zso = zv->zv_zso;
++
+ ASSERT(MUTEX_HELD(&zv->zv_state_lock));
+ ASSERT0(zv->zv_open_count);
+ ASSERT0(atomic_read(&zv->zv_suspend_ref));
+ ASSERT(zv->zv_flags & ZVOL_REMOVING);
+
+- struct zvol_state_os *zso = zv->zv_zso;
+- zv->zv_zso = NULL;
+-
+ if (zv->zv_volmode == ZFS_VOLMODE_GEOM) {
+ struct zvol_state_geom *zsg = &zso->zso_geom;
+- struct g_provider *pp = zsg->zsg_provider;
+- atomic_store_ptr(&pp->private, NULL);
+- mutex_exit(&zv->zv_state_lock);
++ struct g_provider *pp;
+
++ while (zso->zso_opening)
++ cv_wait(&zv->zv_removing_cv, &zv->zv_state_lock);
++ zv->zv_zso = NULL;
++ mutex_exit(&zv->zv_state_lock);
+ g_topology_lock();
++ pp = zsg->zsg_provider;
++ pp->private = NULL;
+ g_wither_geom(pp->geom, ENXIO);
+ g_topology_unlock();
++ g_waitidle(curthread);
+ } else if (zv->zv_volmode == ZFS_VOLMODE_DEV) {
+ struct zvol_state_dev *zsd = &zso->zso_dev;
+ struct cdev *dev = zsd->zsd_cdev;
+
++ zv->zv_zso = NULL;
+ if (dev != NULL)
+ atomic_store_ptr(&dev->si_drv2, NULL);
+ mutex_exit(&zv->zv_state_lock);
+@@ -1545,6 +1556,7 @@
+ g_error_provider(zv->zv_zso->zso_geom.zsg_provider, 0);
+ /* geom was locked inside zvol_alloc() function */
+ g_topology_unlock();
++ g_waitidle(curthread);
+ }
+ out_doi:
+ kmem_free(doi, sizeof (dmu_object_info_t));
+@@ -1565,10 +1577,10 @@
+ zv->zv_volsize = volsize;
+ if (zv->zv_volmode == ZFS_VOLMODE_GEOM) {
+ struct zvol_state_geom *zsg = &zv->zv_zso->zso_geom;
+- struct g_provider *pp = zsg->zsg_provider;
++ struct g_provider *pp;
+
+ g_topology_lock();
+-
++ pp = zsg->zsg_provider;
+ if (pp->private == NULL) {
+ g_topology_unlock();
+ return (SET_ERROR(ENXIO));
+--- sys/contrib/openzfs/module/os/linux/zfs/zvol_os.c.orig
++++ sys/contrib/openzfs/module/os/linux/zfs/zvol_os.c
+@@ -1796,7 +1796,7 @@
+ {
+ int readonly = get_disk_ro(zv->zv_zso->zvo_disk);
+
+- ASSERT(RW_LOCK_HELD(&zvol_state_lock));
++ ASSERT(RW_WRITE_HELD(&zvol_state_lock));
+ ASSERT(MUTEX_HELD(&zv->zv_state_lock));
+
+ strlcpy(zv->zv_name, newname, sizeof (zv->zv_name));
+--- sys/contrib/openzfs/module/zfs/zvol.c.orig
++++ sys/contrib/openzfs/module/zfs/zvol.c
+@@ -1762,9 +1762,10 @@
+ if (zvol_inhibit_dev)
+ return;
+
++ last_error = 0;
+ oldnamelen = strlen(oldname);
+
+- rw_enter(&zvol_state_lock, RW_READER);
++ rw_enter(&zvol_state_lock, RW_WRITER);
+
+ for (zv = list_head(&zvol_state_list); zv != NULL; zv = zv_next) {
+ zv_next = list_next(&zvol_state_list, zv);
+@@ -1781,6 +1782,8 @@
+ zv->zv_name + oldnamelen + 1);
+ error = zvol_os_rename_minor(zv, name);
+ kmem_strfree(name);
++ } else {
++ error = 0;
+ }
+ if (error) {
+ last_error = error;
+@@ -1936,6 +1939,10 @@
+ uint64_t zsda_value;
+ zprop_source_t zsda_source;
+ zfs_prop_t zsda_prop;
++ taskqid_t zsda_taskqid;
++ boolean_t zsda_dispatched;
++ kmutex_t zsda_lock;
++ kcondvar_t zsda_cv;
+ } zvol_set_prop_int_arg_t;
+
+ /*
+@@ -1966,6 +1973,7 @@
+ char dsname[ZFS_MAX_DATASET_NAME_LEN];
+ zvol_task_t *task;
+ uint64_t prop;
++ taskqid_t id;
+
+ const char *prop_name = zfs_prop_to_name(zsda->zsda_prop);
+ dsl_dataset_name(ds, dsname);
+@@ -1984,8 +1992,12 @@
+ }
+ task->zt_value = prop;
+ strlcpy(task->zt_name1, dsname, sizeof (task->zt_name1));
+- (void) taskq_dispatch(dp->dp_spa->spa_zvol_taskq, zvol_task_cb,
+- task, TQ_SLEEP);
++ id = taskq_dispatch(dp->dp_spa->spa_zvol_taskq, zvol_task_cb, task,
++ TQ_SLEEP);
++ mutex_enter(&zsda->zsda_lock);
++ if (id != TASKQID_INVALID && id > zsda->zsda_taskqid)
++ zsda->zsda_taskqid = id;
++ mutex_exit(&zsda->zsda_lock);
+ return (0);
+ }
+
+@@ -2018,6 +2030,11 @@
+ dmu_objset_find_dp(dp, dd->dd_object, zvol_set_common_sync_cb,
+ zsda, DS_FIND_CHILDREN);
+
++ mutex_enter(&zsda->zsda_lock);
++ zsda->zsda_dispatched = TRUE;
++ cv_broadcast(&zsda->zsda_cv);
++ mutex_exit(&zsda->zsda_lock);
++
+ dsl_dir_rele(dd, FTAG);
+ }
+
+@@ -2026,14 +2043,38 @@
+ uint64_t val)
+ {
+ zvol_set_prop_int_arg_t zsda;
++ spa_t *spa;
++ int error;
+
+ zsda.zsda_name = ddname;
+ zsda.zsda_source = source;
+ zsda.zsda_value = val;
+ zsda.zsda_prop = prop;
++ zsda.zsda_taskqid = TASKQID_INVALID;
++ zsda.zsda_dispatched = FALSE;
++ mutex_init(&zsda.zsda_lock, NULL, MUTEX_DEFAULT, NULL);
++ cv_init(&zsda.zsda_cv, NULL, CV_DEFAULT, NULL);
+
+- return (dsl_sync_task(ddname, zvol_set_common_check,
+- zvol_set_common_sync, &zsda, 0, ZFS_SPACE_CHECK_NONE));
++ error = spa_open(ddname, &spa, FTAG);
++ if (error != 0)
++ goto out;
++ error = dsl_sync_task(ddname, zvol_set_common_check,
++ zvol_set_common_sync, &zsda, 0, ZFS_SPACE_CHECK_NONE);
++ if (error == 0) {
++ mutex_enter(&zsda.zsda_lock);
++ while (!zsda.zsda_dispatched)
++ cv_wait(&zsda.zsda_cv, &zsda.zsda_lock);
++ mutex_exit(&zsda.zsda_lock);
++
++ if (zsda.zsda_taskqid != TASKQID_INVALID)
++ taskq_wait_outstanding(spa->spa_zvol_taskq,
++ zsda.zsda_taskqid);
++ }
++ spa_close(spa, FTAG);
++out:
++ cv_destroy(&zsda.zsda_cv);
++ mutex_destroy(&zsda.zsda_lock);
++ return (error);
+ }
+
+ void
diff --git a/website/static/security/patches/EN-26:19/zfs.patch.asc b/website/static/security/patches/EN-26:19/zfs.patch.asc
new file mode 100644
index 0000000000..3dd8be31a9
--- /dev/null
+++ b/website/static/security/patches/EN-26:19/zfs.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkMbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv1uUP/RQ4pxOnk+uep9OPhji7
+w6G9WCx8lQajlVvRfoI4wJQTiO0XC4wJeXVsVUrNMKYxUJOJ4Zoa1tCL2CHjriYd
++DgbGSy2EB1l1x49Y1FjM0OCmGNrTnwK4UOcxpV/XctP+lXVLKjuFBC/h/v0lFbL
+MojSJoKAtJLODPyQWqZfeWs1pqQZYjta4nnrUGgg7RUdtIpexIAjIj0t+YsGWAsd
+tm2kddq7FzeSeLd3omAev/BwGUlrLB+ti6A4crODLOD+ZClVKw429VUy7syPLBFg
+NX4xtJYyTYJ+PRbeMiML/3Y/CGD3zCEoXwI0tsObzdywy7BK+6WmwNCxEUSRpJfa
+NbwJsGXdUOpFyoS5QyM4ESsoSD2dBuX+dsz48LVMi/qmXB+a1XpRL7IjIbet1mwJ
+2mJClhggz3UhJg9Ndn9r+8IS05sk+ZTwiv1rqP3IjvxPVY/QuRotbfPjwdLQggpV
+ckaZfDmL+A1Q5Nh74PO6oUp2MI8xTJrL2KrMAItYD9YvbNobLowz5PtDhp+YmY3R
+fjgZQdDbYivkadb3UkOIT2zmMrQd+0jIWWhSUsaKJYR+rHV84dIhK4Lunky9PQFV
+vEE0VdqfMguSbAN/EC+wUMXtoAbJZUDgDTqB6tgqDG5Gno0Ww+cqybKU1yI1kn/N
+1HiEHTIhxW9mkYD/tqSTnMrh
+=r6VY
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/SA-26:50/kqueue.patch b/website/static/security/patches/SA-26:50/kqueue.patch
new file mode 100644
index 0000000000..ce29d56285
--- /dev/null
+++ b/website/static/security/patches/SA-26:50/kqueue.patch
@@ -0,0 +1,141 @@
+--- sys/kern/kern_event.c.orig
++++ sys/kern/kern_event.c
+@@ -3072,13 +3072,29 @@
+ }
+
+ static void
+-kqueue_fork_copy_knote(struct kqueue *kq1, struct knote *kn, struct proc *p1,
+- struct filedesc *fdp)
++kqueue_fork_copy_knote(struct kqueue *kq, struct kqueue *kq1, struct knote *kn,
++ struct proc *p1, struct filedesc *fdp)
+ {
+ struct knote *kn1;
++ struct knlist *knl;
+ const struct filterops *fop;
+ int error;
++ bool enqueue;
+
++ KASSERT(kn->kn_influx != 0,
++ ("%s: knote %p not in flux", __func__, kn));
++ KASSERT((kn->kn_status & KN_DETACHED) == 0,
++ ("%s: knote %p not detached", __func__, kn));
++
++ if ((kn->kn_status & KN_MARKER) != 0)
++ return;
++ if ((kn->kn_status & KN_KQUEUE) != 0) {
++ /*
++ * We cannot hold references to a kqueue outside of the process
++ * itself, kqueue_close() does not handle this possibility.
++ */
++ return;
++ }
+ fop = kn->kn_fop;
+ if (fop->f_copy == NULL || (fop->f_isfd &&
+ fdp->fd_files->fdt_ofiles[kn->kn_kevent.ident].fde_file == NULL))
+@@ -3088,9 +3104,13 @@
+ return;
+
+ kn1 = knote_alloc(M_WAITOK);
++
++ knl = kn_list_lock(kn);
++ KQ_LOCK(kq);
+ *kn1 = *kn;
+- kn1->kn_status |= KN_DETACHED;
+- kn1->kn_status &= ~KN_QUEUED;
++ KQ_UNLOCK(kq);
++ kn_list_unlock(knl);
++ kn1->kn_status = KN_DETACHED | (kn1->kn_status & KN_CPONFORK);
+ kn1->kn_kq = kq1;
+ kn1->kn_knlist = NULL;
+ error = fop->f_copy(kn1, p1);
+@@ -3105,12 +3125,19 @@
+ knote_free(kn1);
+ return;
+ }
+- if (kn->kn_knlist != NULL)
+- knlist_add(kn->kn_knlist, kn1, 0);
++ if (kn->kn_knlist != NULL) {
++ knl = kn_list_lock(kn);
++ knlist_add(kn->kn_knlist, kn1, 1);
++ } else {
++ knl = NULL;
++ }
++ enqueue = kn->kn_fop->f_event(kn1, 0) != 0;
++ kn_list_unlock(knl);
++
+ KQ_LOCK(kq1);
+ knote_attach(kn1, kq1);
+ kn1->kn_influx = 0;
+- if ((kn->kn_status & KN_QUEUED) != 0)
++ if (enqueue && (kn1->kn_status & KN_QUEUED) == 0)
+ knote_enqueue(kn1);
+ KQ_UNLOCK(kq1);
+ }
+@@ -3134,7 +3161,7 @@
+ kn_enter_flux(kn);
+ SLIST_INSERT_AFTER(kn, marker, kn_link);
+ KQ_UNLOCK(kq);
+- kqueue_fork_copy_knote(kq1, kn, p1, fdp);
++ kqueue_fork_copy_knote(kq, kq1, kn, p1, fdp);
+ KQ_LOCK(kq);
+ kn_leave_flux(kn);
+ kn = SLIST_NEXT(marker, kn_link);
+--- sys/sys/event.h.orig
++++ sys/sys/event.h
+@@ -315,6 +315,7 @@
+ #define KN_MARKER 0x20 /* ignore this knote */
+ #define KN_KQUEUE 0x40 /* this knote belongs to a kq */
+ #define KN_SCAN 0x100 /* flux set in kqueue_scan() */
++#define KN_CPONFORK (KN_ACTIVE | KN_DISABLED) /* state preserved by fork */
+ int kn_influx;
+ unsigned int kn_sfflags; /* saved filter flags */
+ int64_t kn_sdata; /* saved data field */
+--- tests/sys/kqueue/kqueue_fork.c.orig
++++ tests/sys/kqueue/kqueue_fork.c
+@@ -269,10 +269,46 @@
+ cponfork_notes_mask_check(info.si_status, true);
+ }
+
++/*
++ * Exercise a rare race: while the kernel is copying knotes during a fork, try
++ * to set things up so that a new knote is activated while the copy is still in
++ * progress.
++ */
++ATF_TC_WITHOUT_HEAD(cponfork_timer_race);
++ATF_TC_BODY(cponfork_timer_race, tc)
++{
++ struct kevent ev;
++ int error, kq, status;
++ pid_t pid;
++
++ for (int i = 0; i < 100; i++) {
++ kq = kqueuex(KQUEUE_CPONFORK);
++ ATF_REQUIRE(kq >= 0);
++
++ EV_SET(&ev, 0, EVFILT_TIMER, EV_ADD | EV_ENABLE, NOTE_NSECONDS,
++ 1, NULL);
++ error = kevent(kq, &ev, 1, NULL, 0, NULL);
++ ATF_REQUIRE(error == 0);
++
++ pid = fork();
++ ATF_REQUIRE(pid != -1);
++ if (pid == 0)
++ _exit(0);
++
++ error = waitpid(pid, &status, 0);
++ ATF_REQUIRE(error != -1);
++ ATF_REQUIRE(WIFEXITED(status));
++ ATF_REQUIRE_EQ(WEXITSTATUS(status), 0);
++
++ ATF_REQUIRE(close(kq) == 0);
++ }
++}
++
+ ATF_TP_ADD_TCS(tp)
+ {
+ ATF_TP_ADD_TC(tp, shared_table_filt_sig);
+ ATF_TP_ADD_TC(tp, cponfork_notes);
++ ATF_TP_ADD_TC(tp, cponfork_timer_race);
+
+ return (atf_no_error());
+ }
diff --git a/website/static/security/patches/SA-26:50/kqueue.patch.asc b/website/static/security/patches/SA-26:50/kqueue.patch.asc
new file mode 100644
index 0000000000..65c05fcccb
--- /dev/null
+++ b/website/static/security/patches/SA-26:50/kqueue.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkYbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv8nkP/39gXekYncW8hR/7hgLi
+lkueVkS0xODf/yODW5wZAzPK4gyGgkk1/MH+Gmexj2oy1m7zRUDr4lK46HD45an0
+5LKgJqFWYoUI63u/OWPSBND4QxvjfNW/vvcfb1zJi9XScm3gwAZt/V4maeNT9/AG
+81tTqvNx4fhayshY90x1cpWJm1BHpp2k6boFbcoH44Av0BWXcZX3toRC+HqcADUD
+sw5NA23KxssShg4wMwGLa2kql9h2wMe7I5NbiT5BT5WSaba/5ATAjp7tCUFToE1c
+j1Id0NVcRumZLGjpZV+moN5LtS47LJj+YDbAO6MTfEq1XjC0W5mA+JTk6VM2OXdE
+52pLAD/YlY8kPV+cGxB5YcrjhVOd9SCvvvz9sZ9ITS17JBUcphqNHV4aBur3OIPL
+X18FUq25Lyv24VuKszvfc3BpZ78gG95HXjvZ7CN32nMdxhwytEawXyeJ0aphFoR/
+DKmIPeg3Agsh4K00ZRac0Z6V48T/ZhQp0/Nl3d8PBibKsNTJPUDEeMX59YT7b6n1
+Qw8FqCy7mdUuIglCiEgWYvctxssonUWzPva3WWAzl2jf8WJrzRZp81Cz32mQdbgJ
+EfsTYQDg3cDYUHt36w3EDH0MLx7EcNvkWfl40O+xZv0U6rW2ClZpAB3UxGqLDcM+
+eP/Hl8L9125DMD35Ujam9dhv
+=YAZg
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/SA-26:51/ktimer.patch b/website/static/security/patches/SA-26:51/ktimer.patch
new file mode 100644
index 0000000000..5bb35a7191
--- /dev/null
+++ b/website/static/security/patches/SA-26:51/ktimer.patch
@@ -0,0 +1,16 @@
+--- sys/kern/kern_time.c.orig
++++ sys/kern/kern_time.c
+@@ -1631,8 +1631,11 @@
+ timespecclear(&val.it_interval);
+ }
+
+- if (ovalue != NULL)
+- realtimer_gettime(it, ovalue);
++ if (ovalue != NULL) {
++ error = realtimer_gettime(it, ovalue);
++ if (error != 0)
++ return (error);
++ }
+
+ it->it_time = val;
+ if (timespecisset(&val.it_value)) {
diff --git a/website/static/security/patches/SA-26:51/ktimer.patch.asc b/website/static/security/patches/SA-26:51/ktimer.patch.asc
new file mode 100644
index 0000000000..4dc00c4007
--- /dev/null
+++ b/website/static/security/patches/SA-26:51/ktimer.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkgbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrv2U4P/Am+OQc04ZywBnKXZDjV
+hnMI+Y/WpT07eN4C9pnRgWGqWcskpUf8iTut470wYwwqZqOh6KasxrUM5lGaa53K
+rKFsgBRBoJXFfJ44nrHBrtD/9+3g2ti6syZ6QdE8iirsa1j3pEfZUiMiQF6tVkPz
+m4ou5wAKORWmooYan26/HFpnQ6qc6eQ6AbqT7Zu2DZt0f7TLeE6ba4DHbl/vo96S
+jLX4wh881sWFFbpcyythEOdhO3Fwl4jDGqU0AtVE5V4XGKmh0R+DIAInEAtyRoj8
+OKhcdtAZwfwUU1PiilozSCqXgZc8QYcazHlNBHc6fFpVXYhSffUbD60YQsWFf4P6
+BFXtlqdkW8bk84Nr24zHLql/mlVf7OWxdEBJvu19CEB676+6fTNh69ee8B9JRxYz
+/kS4OC9LQDi92rRT9kIn5uE2s2h2nMVkeeyWM7ZwGoYxq145W1xsM5AxF0fXzZYv
+g4xrqJQjRanJYEm34Nza8mgnSOYuB+q2VPyCpzU8BHm7nWq603Drmc2STwp7GYka
+VcLBORx9Cgk5z4bx2rkT0OzOTVaj+YFwAgOXTewAUOoXJGccvOHcRPRVEOT8Kbzk
+wZmf7yEWLRziZb3E2Nez6zkpEm6f8EUTWUy+nzchom5tre/I655EMoZxgdYRduzU
+Q4TZF8x2zVNxvqQqcm0lHo4Z
+=Ok+/
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/SA-26:52/if_wg-14.patch b/website/static/security/patches/SA-26:52/if_wg-14.patch
new file mode 100644
index 0000000000..42356d349a
--- /dev/null
+++ b/website/static/security/patches/SA-26:52/if_wg-14.patch
@@ -0,0 +1,223 @@
+--- etc/mtree/BSD.tests.dist.orig
++++ etc/mtree/BSD.tests.dist
+@@ -848,6 +848,8 @@
+ ..
+ routing
+ ..
++ wg
++ ..
+ ..
+ netgraph
+ ..
+--- sys/dev/wg/wg_crypto.c.orig
++++ sys/dev/wg/wg_crypto.c
+@@ -230,6 +230,8 @@
+ crp.crp_cipher_key = key;
+ crp.crp_callback = crypto_callback;
+ ret = crypto_dispatch(&crp);
++ if (ret == 0)
++ ret = crp.crp_etype;
+ crypto_destroyreq(&crp);
+ return (ret);
+ }
+@@ -253,6 +255,8 @@
+ crp.crp_cipher_key = key;
+ crp.crp_callback = crypto_callback;
+ ret = crypto_dispatch(&crp);
++ if (ret == 0)
++ ret = crp.crp_etype;
+ crypto_destroyreq(&crp);
+ if (ret)
+ return (ret);
+@@ -270,9 +274,14 @@
+ .csp_cipher_klen = CHACHA20POLY1305_KEY_SIZE,
+ .csp_flags = CSP_F_SEPARATE_AAD | CSP_F_SEPARATE_OUTPUT
+ };
+- int ret = crypto_newsession(&chacha20_poly1305_sid, &csp, CRYPTOCAP_F_SOFTWARE);
++ int ret = crypto_newsession(&chacha20_poly1305_sid, &csp,
++ CRYPTOCAP_F_SOFTWARE);
+ if (ret != 0)
+ return (ret);
++ if (!CRYPTO_SESS_SYNC(chacha20_poly1305_sid)) {
++ crypto_freesession(chacha20_poly1305_sid);
++ return (ENXIO);
++ }
+ return (0);
+ }
+
+--- sys/opencrypto/crypto.c.orig
++++ sys/opencrypto/crypto.c
+@@ -61,6 +61,7 @@
+ #include
+ #include
+ #include
++#include
+ #include
+ #include
+ #include
+@@ -145,6 +146,9 @@
+ SYSCTL_NODE(_kern, OID_AUTO, crypto, CTLFLAG_RW, 0,
+ "In-kernel cryptography");
+
++static SYSCTL_NODE(_debug_fail_point, OID_AUTO, crypto, CTLFLAG_RW, 0,
++ "OCF fail points");
++
+ /*
+ * Taskqueue used to dispatch the crypto requests submitted with
+ * crypto_dispatch_async .
+@@ -1679,6 +1683,18 @@
+ KASSERT((crp->crp_flags & CRYPTO_F_DONE) == 0,
+ ("crypto_done: op already done, flags 0x%x", crp->crp_flags));
+ crp->crp_flags |= CRYPTO_F_DONE;
++
++ if (crp->crp_etype == 0) {
++ switch (crp->crp_session->csp.csp_mode) {
++ case CSP_MODE_DIGEST:
++ case CSP_MODE_AEAD:
++ if ((crp->crp_op & CRYPTO_OP_VERIFY_DIGEST) != 0)
++ KFAIL_POINT_CODE(_debug_fail_point_crypto,
++ inject_badmsg, crp->crp_etype = EBADMSG);
++ break;
++ }
++ }
++
+ if (crp->crp_etype != 0)
+ CRYPTOSTAT_INC(cs_errs);
+
+--- tests/sys/net/Makefile.orig
++++ tests/sys/net/Makefile
+@@ -15,6 +15,7 @@
+ ATF_TESTS_SH+= if_wg
+
+ TESTS_SUBDIRS+= if_ovpn
++TESTS_SUBDIRS+= wg
+ TESTS_SUBDIRS+= routing
+
+ # The netmap bridge application is used by if_wg tests.
+--- /dev/null
++++ tests/sys/net/wg/Makefile
+@@ -0,0 +1,10 @@
++PACKAGE= tests
++
++TESTSDIR= ${TESTSBASE}/sys/net/wg
++BINDIR= ${TESTSDIR}
++
++ATF_TESTS_SH+= if_wg_nojail
++
++TEST_METADATA.if_wg_nojail= is_exclusive=true
++
++.include
+--- /dev/null
++++ tests/sys/net/wg/if_wg_nojail.sh
+@@ -0,0 +1,111 @@
++#
++# SPDX-License-Identifier: BSD-2-Clause
++#
++# Copyright (c) 2021 The FreeBSD Foundation
++#
++# This software was developed by Mark Johnston under sponsorship
++# from the FreeBSD Foundation.
++#
++# Redistribution and use in source and binary forms, with or without
++# modification, are permitted provided that the following conditions
++# are met:
++# 1. Redistributions of source code must retain the above copyright
++# notice, this list of conditions and the following disclaimer.
++# 2. Redistributions in binary form must reproduce the above copyright
++# notice, this list of conditions and the following disclaimer in the
++# documentation and/or other materials provided with the distribution.
++#
++# THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
++# ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
++# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
++# ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
++# FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
++# DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
++# OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
++# HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
++# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
++# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
++# SUCH DAMAGE.
++
++. $(atf_get_srcdir)/../../common/vnet.subr
++
++atf_test_case "wg_bad_decrypt" "cleanup"
++wg_bad_decrypt_head()
++{
++ atf_set descr 'Create a wg(4) tunnel over an epair and inject a decryption error'
++ atf_set require.user root
++ atf_set require.kmods if_wg
++}
++
++wg_bad_decrypt_body()
++{
++ local epair pri1 pri2 pub1 pub2 wg1 wg2
++ local endpoint1 endpoint2 tunnel1 tunnel2
++
++ pri1=$(wg genkey)
++ pri2=$(wg genkey)
++
++ endpoint1=192.168.2.1
++ endpoint2=192.168.2.2
++ tunnel1=169.254.0.1
++ tunnel2=169.254.0.2
++
++ epair=$(vnet_mkepair)
++
++ vnet_init
++
++ vnet_mkjail wgtest1 ${epair}a
++ vnet_mkjail wgtest2 ${epair}b
++
++ jexec wgtest1 ifconfig ${epair}a ${endpoint1}/24 up
++ jexec wgtest2 ifconfig ${epair}b ${endpoint2}/24 up
++
++ wg1=$(jexec wgtest1 ifconfig wg create)
++ echo "$pri1" | jexec wgtest1 wg set $wg1 listen-port 12345 \
++ private-key /dev/stdin
++ pub1=$(jexec wgtest1 wg show $wg1 public-key)
++ wg2=$(jexec wgtest2 ifconfig wg create)
++ echo "$pri2" | jexec wgtest2 wg set $wg2 listen-port 12345 \
++ private-key /dev/stdin
++ pub2=$(jexec wgtest2 wg show $wg2 public-key)
++
++ atf_check -s exit:0 -o ignore \
++ jexec wgtest1 wg set $wg1 peer "$pub2" \
++ endpoint ${endpoint2}:12345 allowed-ips ${tunnel2}/32
++ atf_check -s exit:0 \
++ jexec wgtest1 ifconfig $wg1 inet ${tunnel1}/24 up
++
++ atf_check -s exit:0 -o ignore \
++ jexec wgtest2 wg set $wg2 peer "$pub1" \
++ endpoint ${endpoint1}:12345 allowed-ips ${tunnel1}/32
++ atf_check -s exit:0 \
++ jexec wgtest2 ifconfig $wg2 inet ${tunnel2}/24 up
++
++ # Generous timeout since the handshake takes some time.
++ atf_check -s exit:0 -o ignore jexec wgtest1 ping -c 1 -t 5 $tunnel2
++
++ # No receive errors before injection
++ ierrs=$(netstat -j wgtest2 -I $wg2 --libxo json,pretty | \
++ awk '/received-errors/ { print $2 }')
++ atf_check_equal "0," "$ierrs"
++
++ # Trigger a decryption error
++ atf_check -s exit:0 -o ignore \
++ sysctl debug.fail_point.crypto.inject_badmsg="1*return"
++
++ atf_check -s exit:2 -o ignore jexec wgtest1 ping -c 1 -t 5 $tunnel2
++
++ ierrs=$(netstat -j wgtest2 -I $wg2 --libxo json,pretty | \
++ awk '/received-errors/ { print $2 }')
++ atf_check_equal "1," "$ierrs"
++}
++
++wg_bad_decrypt_cleanup()
++{
++ vnet_cleanup
++}
++
++atf_init_test_cases()
++{
++ atf_add_test_case "wg_bad_decrypt"
++}
diff --git a/website/static/security/patches/SA-26:52/if_wg-14.patch.asc b/website/static/security/patches/SA-26:52/if_wg-14.patch.asc
new file mode 100644
index 0000000000..ce04a7e9f4
--- /dev/null
+++ b/website/static/security/patches/SA-26:52/if_wg-14.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbkobFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvrjEQAMY1BC6RFslzOAQnFCC8
+PAr+IrbZ2nKunUVxYnhl/lZSZ9yCbPf1f+KjNjeBZEoQKUUtUrnNTGv/0BlmJqNi
+XPtEplsOsIlKDVUgSMfy8N+N7PC6Nk9IVACol9boU2HIhFSGaBNInxjvClYAWGIP
+rRBFk1T2XJqbVWrcVsPBqP4lPQqKuLUkabU2cwPqBxfSDL6xI306kKcgkaABkAAJ
+x/oREn6HmmlRyYyUxgCEkmhZjF2w0POggq4+g0A/vDNZbA+1LmVZV7a9v390nEwc
+op6Bl490BEjPDGyhv+Ky8gBTxnqc1zlZr47V3iApVhbbouq5u44tCboZ6gKaThyY
+RPgsup8bucr/HaLT+wPkDkRf0iidJNG7MUGWDsEM1wbq8F+D9LSig34Vg/OyTdQM
+Tl7qq2P1bHZicHp2JfbsDtOSXdwV+7lSVzZGbeQLTK2uC7fkj5NhaB32blSbOjQH
++jNFTwCcDvFpbv7PdGV3nbPtlnaa/ciZQ/er3WKwDy63R1D6ErdFRM3Do7a2hpoj
+PvXg7vYFi1BhHCc+N776UkjTKjzVA8UdfGbldkA2tJzgWuUqkm9+erTUZZbExMTe
+DxOPx28oQTq8+RZ5qPFnFi21INUZOQuu/IAL5Z9QDd7ZFHUrh0yZNdatNybJcZO8
+FgXa6xruNrVQa54urajoMPvj
+=MpsO
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/SA-26:52/if_wg-15.patch b/website/static/security/patches/SA-26:52/if_wg-15.patch
new file mode 100644
index 0000000000..bf821555af
--- /dev/null
+++ b/website/static/security/patches/SA-26:52/if_wg-15.patch
@@ -0,0 +1,222 @@
+--- etc/mtree/BSD.tests.dist.orig
++++ etc/mtree/BSD.tests.dist
+@@ -900,6 +900,8 @@
+ ..
+ routing
+ ..
++ wg
++ ..
+ ..
+ netgraph
+ ..
+--- sys/dev/wg/wg_crypto.c.orig
++++ sys/dev/wg/wg_crypto.c
+@@ -230,6 +230,8 @@
+ crp.crp_cipher_key = key;
+ crp.crp_callback = crypto_callback;
+ ret = crypto_dispatch(&crp);
++ if (ret == 0)
++ ret = crp.crp_etype;
+ crypto_destroyreq(&crp);
+ return (ret);
+ }
+@@ -253,6 +255,8 @@
+ crp.crp_cipher_key = key;
+ crp.crp_callback = crypto_callback;
+ ret = crypto_dispatch(&crp);
++ if (ret == 0)
++ ret = crp.crp_etype;
+ crypto_destroyreq(&crp);
+ if (ret)
+ return (ret);
+@@ -270,9 +274,14 @@
+ .csp_cipher_klen = CHACHA20POLY1305_KEY_SIZE,
+ .csp_flags = CSP_F_SEPARATE_AAD | CSP_F_SEPARATE_OUTPUT
+ };
+- int ret = crypto_newsession(&chacha20_poly1305_sid, &csp, CRYPTOCAP_F_SOFTWARE);
++ int ret = crypto_newsession(&chacha20_poly1305_sid, &csp,
++ CRYPTOCAP_F_SOFTWARE);
+ if (ret != 0)
+ return (ret);
++ if (!CRYPTO_SESS_SYNC(chacha20_poly1305_sid)) {
++ crypto_freesession(chacha20_poly1305_sid);
++ return (ENXIO);
++ }
+ return (0);
+ }
+
+--- sys/opencrypto/crypto.c.orig
++++ sys/opencrypto/crypto.c
+@@ -61,6 +61,7 @@
+ #include
+ #include
+ #include
++#include
+ #include
+ #include
+ #include
+@@ -145,6 +146,9 @@
+ SYSCTL_NODE(_kern, OID_AUTO, crypto, CTLFLAG_RW, 0,
+ "In-kernel cryptography");
+
++static SYSCTL_NODE(_debug_fail_point, OID_AUTO, crypto, CTLFLAG_RW, 0,
++ "OCF fail points");
++
+ /*
+ * Taskqueue used to dispatch the crypto requests submitted with
+ * crypto_dispatch_async .
+@@ -1666,6 +1670,17 @@
+ void
+ crypto_done(struct cryptop *crp)
+ {
++ if (crp->crp_etype == 0) {
++ switch (crp->crp_session->csp.csp_mode) {
++ case CSP_MODE_DIGEST:
++ case CSP_MODE_AEAD:
++ if ((crp->crp_op & CRYPTO_OP_VERIFY_DIGEST) != 0)
++ KFAIL_POINT_CODE(_debug_fail_point_crypto,
++ inject_badmsg, crp->crp_etype = EBADMSG);
++ break;
++ }
++ }
++
+ if (crp->crp_etype != 0)
+ CRYPTOSTAT_INC(cs_errs);
+
+--- tests/sys/net/Makefile.orig
++++ tests/sys/net/Makefile
+@@ -18,6 +18,7 @@
+
+ TESTS_SUBDIRS+= bpf
+ TESTS_SUBDIRS+= if_ovpn
++TESTS_SUBDIRS+= wg
+ TESTS_SUBDIRS+= routing
+
+ # The netmap bridge application is used by if_wg tests.
+--- /dev/null
++++ tests/sys/net/wg/Makefile
+@@ -0,0 +1,10 @@
++PACKAGE= tests
++
++TESTSDIR= ${TESTSBASE}/sys/net/wg
++BINDIR= ${TESTSDIR}
++
++ATF_TESTS_SH+= if_wg_nojail
++
++TEST_METADATA.if_wg_nojail= is_exclusive=true
++
++.include
+--- /dev/null
++++ tests/sys/net/wg/if_wg_nojail.sh
+@@ -0,0 +1,111 @@
++#
++# SPDX-License-Identifier: BSD-2-Clause
++#
++# Copyright (c) 2021 The FreeBSD Foundation
++#
++# This software was developed by Mark Johnston under sponsorship
++# from the FreeBSD Foundation.
++#
++# Redistribution and use in source and binary forms, with or without
++# modification, are permitted provided that the following conditions
++# are met:
++# 1. Redistributions of source code must retain the above copyright
++# notice, this list of conditions and the following disclaimer.
++# 2. Redistributions in binary form must reproduce the above copyright
++# notice, this list of conditions and the following disclaimer in the
++# documentation and/or other materials provided with the distribution.
++#
++# THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
++# ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
++# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
++# ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
++# FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
++# DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
++# OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
++# HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
++# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
++# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
++# SUCH DAMAGE.
++
++. $(atf_get_srcdir)/../../common/vnet.subr
++
++atf_test_case "wg_bad_decrypt" "cleanup"
++wg_bad_decrypt_head()
++{
++ atf_set descr 'Create a wg(4) tunnel over an epair and inject a decryption error'
++ atf_set require.user root
++ atf_set require.kmods if_wg
++}
++
++wg_bad_decrypt_body()
++{
++ local epair pri1 pri2 pub1 pub2 wg1 wg2
++ local endpoint1 endpoint2 tunnel1 tunnel2
++
++ pri1=$(wg genkey)
++ pri2=$(wg genkey)
++
++ endpoint1=192.168.2.1
++ endpoint2=192.168.2.2
++ tunnel1=169.254.0.1
++ tunnel2=169.254.0.2
++
++ epair=$(vnet_mkepair)
++
++ vnet_init
++
++ vnet_mkjail wgtest1 ${epair}a
++ vnet_mkjail wgtest2 ${epair}b
++
++ jexec wgtest1 ifconfig ${epair}a ${endpoint1}/24 up
++ jexec wgtest2 ifconfig ${epair}b ${endpoint2}/24 up
++
++ wg1=$(jexec wgtest1 ifconfig wg create)
++ echo "$pri1" | jexec wgtest1 wg set $wg1 listen-port 12345 \
++ private-key /dev/stdin
++ pub1=$(jexec wgtest1 wg show $wg1 public-key)
++ wg2=$(jexec wgtest2 ifconfig wg create)
++ echo "$pri2" | jexec wgtest2 wg set $wg2 listen-port 12345 \
++ private-key /dev/stdin
++ pub2=$(jexec wgtest2 wg show $wg2 public-key)
++
++ atf_check -s exit:0 -o ignore \
++ jexec wgtest1 wg set $wg1 peer "$pub2" \
++ endpoint ${endpoint2}:12345 allowed-ips ${tunnel2}/32
++ atf_check -s exit:0 \
++ jexec wgtest1 ifconfig $wg1 inet ${tunnel1}/24 up
++
++ atf_check -s exit:0 -o ignore \
++ jexec wgtest2 wg set $wg2 peer "$pub1" \
++ endpoint ${endpoint1}:12345 allowed-ips ${tunnel1}/32
++ atf_check -s exit:0 \
++ jexec wgtest2 ifconfig $wg2 inet ${tunnel2}/24 up
++
++ # Generous timeout since the handshake takes some time.
++ atf_check -s exit:0 -o ignore jexec wgtest1 ping -c 1 -t 5 $tunnel2
++
++ # No receive errors before injection
++ ierrs=$(netstat -j wgtest2 -I $wg2 --libxo json,pretty | \
++ awk '/received-errors/ { print $2 }')
++ atf_check_equal "0," "$ierrs"
++
++ # Trigger a decryption error
++ atf_check -s exit:0 -o ignore \
++ sysctl debug.fail_point.crypto.inject_badmsg="1*return"
++
++ atf_check -s exit:2 -o ignore jexec wgtest1 ping -c 1 -t 5 $tunnel2
++
++ ierrs=$(netstat -j wgtest2 -I $wg2 --libxo json,pretty | \
++ awk '/received-errors/ { print $2 }')
++ atf_check_equal "1," "$ierrs"
++}
++
++wg_bad_decrypt_cleanup()
++{
++ vnet_cleanup
++}
++
++atf_init_test_cases()
++{
++ atf_add_test_case "wg_bad_decrypt"
++}
diff --git a/website/static/security/patches/SA-26:52/if_wg-15.patch.asc b/website/static/security/patches/SA-26:52/if_wg-15.patch.asc
new file mode 100644
index 0000000000..ddd3abfd0c
--- /dev/null
+++ b/website/static/security/patches/SA-26:52/if_wg-15.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbksbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvXxQQANEykqvplbVCHoI2bgUc
+Oql9fk9cMwk1AYl9z8brf2VN5qEIxY5Y+2GDZEoZgGI5IGDa9516LI/WannpBsiR
+irnnWeEk99SYd1pyT4Id38exE8sL49ahDv4QgfINjrFuDk3q0du/cYINd5dRMMIZ
+Bwqokgn3fK8OTGpieAO2nyTEcvaYxGPvoswgUV8sHBFvLAhs4vYZBlXQHIqFTdl+
+KCFUm0FO7EgEP/ORnSPegGwheZ+c7UJ1UkqLgxuMsOH4l89BrExE9arVkYeTkwfE
+MmM41l6WTec8h6T479iIppSu6ZWc91m7CsD6hknrzGENpWaUZCYRphiAQL0toZaE
+Mfpm4dFT9mUQIx3K0/DZvToaUjbdLQ5Rqr6OHnTzewOVeb3W+9cIZePjyNOIN8SP
+PTS5i9JVlnEuHiBhmAXJXV7l4nQbrYBpsW/zoVvlALEV7CgzaxTgm9i5WUs59kz7
+JlXKnvsV7dpHUOT3rqHxahy7MycHnfifx/gewp7At967USFwlqNkImdpz7mip1Jj
+Csmo1TckRh5vVjwiCrwEMxr+h9/SBzclC7KXT9BjYsK8RLn/2ltT8iuTIyyYp4FN
+jSr4GSO6XuXBh/RiRAc/frFdSJXCe5K8mia+YiY9yr8KxW/yR1qixFZeF2rx1/Cb
+6Bns2KdgoHO5b8D3Z6T/FH2V
+=dVSU
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/SA-26:53/ktrace.patch b/website/static/security/patches/SA-26:53/ktrace.patch
new file mode 100644
index 0000000000..81b6dea55d
--- /dev/null
+++ b/website/static/security/patches/SA-26:53/ktrace.patch
@@ -0,0 +1,10 @@
+--- sys/kern/kern_jail.c.orig
++++ sys/kern/kern_jail.c
+@@ -4313,6 +4313,7 @@
+ * Allow ktrace privileges for root in jail.
+ */
+ case PRIV_KTRACE:
++ return (0);
+
+ /*
+ * Allow jailed processes to configure audit identity and
diff --git a/website/static/security/patches/SA-26:53/ktrace.patch.asc b/website/static/security/patches/SA-26:53/ktrace.patch.asc
new file mode 100644
index 0000000000..20aafbb37f
--- /dev/null
+++ b/website/static/security/patches/SA-26:53/ktrace.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqbk4bFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvTkMP/RL3obwFjvXhdIxTzeQY
+44WMR1k22A7awkX1R/03mRJ3QiQ0eiYylGYc6ijaRZinsMeab5utPF/gghO/1vJy
+adFd/uBZh4La7VLuHDYzHSAyLECgdFdbr+pE5ClJNGsCvR3mrqvbSbXNelbLklne
+miM4yFznFnG0Wyq5lZyIaWbaemz8aS3OOoQ/8+BjhTHGoyW9n4ByaqKjQ8IfK/GN
+8xm7EnipGgEqqRHGG17xjUmleW/YGPS9u34wpKt9IYkkuC0WphzbbTtb2yv7RnBq
+BZc6cTX/+ImMNwEF/QT0HRzVyXoYDPYlTmrECaR0tv3ZUp5Jq0b/Ze2pesd9eACz
+ADI3J32x1j86WpCu75iAAR6CGxAUB2QHwPhdgrKshFNlny6txQsOpWw1d7nej6Ld
+p72bupDhp8qLM0OTbA5wuPf7aSWJ1ih3J9OyUX4wTIbhnaCjjIGfLoyeSHGV/r9M
+UZGyIn9JWAzcu63Pgh/2LGQn+7Bat1fTLGnK+2dNG/z478Yy8lPLdEcwGn5pw2oQ
+Qeui6CRrAH073VWdqrCDorz8mC9S2JJHU3ljeVDl9I6MgjuARt1bQ64qH1cgN+Ux
+NgHSdvsaYgyyJqqnN+sOdvcmA6Z8bkvKesJJpfAJT+/0erLw6Ny+YbiD/rAjecWM
+lJiydwdAPrCF0/Fb6eblSynI
+=mUb/
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/SA-26:54/sysvsem.patch b/website/static/security/patches/SA-26:54/sysvsem.patch
new file mode 100644
index 0000000000..7d29ef5855
--- /dev/null
+++ b/website/static/security/patches/SA-26:54/sysvsem.patch
@@ -0,0 +1,76 @@
+--- sys/kern/sysv_sem.c.orig
++++ sys/kern/sysv_sem.c
+@@ -848,25 +848,20 @@
+ * won't work for SETALL since we can't copyin() more
+ * data than the user specified as we may return a
+ * spurious EFAULT.
+- *
+- * Note that the number of semaphores in a set is
+- * fixed for the life of that set. The only way that
+- * the 'count' could change while are blocked in
+- * malloc() is if this semaphore set were destroyed
+- * and a new one created with the same index.
+- * However, semvalid() will catch that due to the
+- * sequence number unless exactly 0x8000 (or a
+- * multiple thereof) semaphore sets for the same index
+- * are created and destroyed while we are in malloc!
+- *
+ */
++ if ((error = semvalid(semid, rpr, semakptr)) != 0)
++ goto done2;
+ count = semakptr->u.sem_nsems;
+ mtx_unlock(sema_mtxp);
+ array = malloc(sizeof(*array) * count, M_TEMP, M_WAITOK);
+ mtx_lock(sema_mtxp);
+ if ((error = semvalid(semid, rpr, semakptr)) != 0)
+ goto done2;
+- KASSERT(count == semakptr->u.sem_nsems, ("nsems changed"));
++ if (count != semakptr->u.sem_nsems) {
++ /* Unlikely, but possible. */
++ error = EAGAIN;
++ goto done2;
++ }
+ if ((error = ipcperm(td, &semakptr->u.sem_perm, IPC_R)))
+ goto done2;
+ for (i = 0; i < semakptr->u.sem_nsems; i++)
+@@ -909,10 +904,8 @@
+ break;
+
+ case SETALL:
+- /*
+- * See comment on GETALL for why 'count' shouldn't change
+- * and why we require a userland buffer.
+- */
++ if ((error = semvalid(semid, rpr, semakptr)) != 0)
++ goto done2;
+ count = semakptr->u.sem_nsems;
+ mtx_unlock(sema_mtxp);
+ array = malloc(sizeof(*array) * count, M_TEMP, M_WAITOK);
+@@ -922,7 +915,11 @@
+ break;
+ if ((error = semvalid(semid, rpr, semakptr)) != 0)
+ goto done2;
+- KASSERT(count == semakptr->u.sem_nsems, ("nsems changed"));
++ if (count != semakptr->u.sem_nsems) {
++ /* Unlikely, but possible. */
++ error = EAGAIN;
++ goto done2;
++ }
+ if ((error = ipcperm(td, &semakptr->u.sem_perm, IPC_W)))
+ goto done2;
+ for (i = 0; i < semakptr->u.sem_nsems; i++) {
+@@ -1482,12 +1479,11 @@
+
+ mtx_lock(sema_mtxp);
+ if ((semakptr->u.sem_perm.mode & SEM_ALLOC) == 0 ||
+- (semakptr->u.sem_perm.seq != seq)) {
++ semakptr->u.sem_perm.seq != seq ||
++ semakptr->u.sem_nsems <= semnum) {
+ mtx_unlock(sema_mtxp);
+ continue;
+ }
+- if (semnum >= semakptr->u.sem_nsems)
+- panic("semexit - semnum out of range");
+
+ DPRINTF((
+ "semexit: %p id=%d num=%d(adj=%d) ; sem=%d\n",
diff --git a/website/static/security/patches/SA-26:54/sysvsem.patch.asc b/website/static/security/patches/SA-26:54/sysvsem.patch.asc
new file mode 100644
index 0000000000..b9f7b72e3f
--- /dev/null
+++ b/website/static/security/patches/SA-26:54/sysvsem.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqblAbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvQscQALQ/OccFBNH4xLzdIlmK
+kLLLnrVCEPB8sEQ6YPvwoOid94SgVtE31v0/Zx5Ey04RgmyevvPsYhzPg0OX4a/Y
+LOEMmppl4Fpd7mOHzlyPj2ycbO5wZ++E9zbvbQGo4bnRfS1xX7oXYwQnvI2o6W5D
+Xzs7WtOSN5E0kPjffxL+lxrLAV3JMqT8n1AXVXRMK+yyigxMZFq7nfXfM8ogVeAp
+uO+h6u6BgekABIOV5sPD+9kkiGY1gsOPgZ/TIqKuipUd+dqP9MrBHDAFa9n8oY/z
+8XAoU2AqTQvYCha94e7bwG76A59V3Te7vc2pZHl+gsv9H0M1tqCXcVjmujB0WMqi
+3ecNZWoFCI36ZewUfLLOToqqfdMWOZT+bzg+/F84QOzKu3RettsJsSYckMZfjSPm
+P+CDq3kUKg/Q5GfKTgitwn8wZgSd7gv0pLE2r1VIdqSTlpC6IZureuS/Vphc2elp
+5jbkl4Zh2PTrP8DXJ2KatNM7n0F3Vh11PqSm2EABKicmXTxbWUSsjwBFdkT5328g
+946ygmaKr9OFQFVD4OGa57cKmIKYqCX7o1TRo6QPIrwkKncIAYFTfCViUHZZkl1t
+BfRETOI9dFL3pufkA96Pl/oqZ9NhM1hjITyQ74Eoei9705yMBrPmf3ngUI8DccLP
+86tYCGB6vWUI4aXC+FYpj1Xf
+=4hU7
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/SA-26:55/elf-14.patch b/website/static/security/patches/SA-26:55/elf-14.patch
new file mode 100644
index 0000000000..3e74f749ce
--- /dev/null
+++ b/website/static/security/patches/SA-26:55/elf-14.patch
@@ -0,0 +1,60 @@
+--- sys/kern/imgact_elf.c.orig
++++ sys/kern/imgact_elf.c
+@@ -1533,6 +1533,8 @@
+ struct phdr_closure {
+ Elf_Phdr *phdr; /* Program header to fill in */
+ Elf_Off offset; /* Offset of segment in core file */
++ int numsegs; /* Maximum number of segments */
++ int nextseg; /* Next segment to fill in */
+ };
+
+ struct note_info {
+@@ -1647,10 +1649,15 @@
+ }
+
+ /*
+- * Allocate memory for building the header, fill it up,
+- * and write it out following the notes.
++ * Allocate memory for building the header, fill it up, and write it out
++ * following the notes.
++ *
++ * Note that a process sharing our vmspace might be concurrently
++ * mutating the map, in which case we could populate fewer than
++ * seginfo.count headers. Zero the buffer to ensure that unpopulated
++ * headers are still initialized.
+ */
+- hdr = malloc(hdrsize, M_TEMP, M_WAITOK);
++ hdr = malloc(hdrsize, M_TEMP, M_WAITOK | M_ZERO);
+ error = __elfN(corehdr)(¶ms, seginfo.count, hdr, hdrsize, ¬elst,
+ notesz, flags);
+
+@@ -1703,6 +1710,11 @@
+ struct phdr_closure *phc = (struct phdr_closure *)closure;
+ Elf_Phdr *phdr = phc->phdr;
+
++ if (phc->nextseg >= phc->numsegs) {
++ /* Only write as many headers as we have space for. */
++ return;
++ }
++
+ phc->offset = round_page(phc->offset);
+
+ phdr->p_type = PT_LOAD;
+@@ -1715,6 +1727,8 @@
+
+ phc->offset += phdr->p_filesz;
+ phc->phdr++;
++
++ phc->nextseg++;
+ }
+
+ /*
+@@ -1977,6 +1991,8 @@
+ /* All the writable segments from the program. */
+ phc.phdr = phdr;
+ phc.offset = round_page(hdrsize + notesz);
++ phc.numsegs = numsegs;
++ phc.nextseg = 0;
+ each_dumpable_segment(td, cb_put_phdr, &phc, flags);
+ }
+
diff --git a/website/static/security/patches/SA-26:55/elf-14.patch.asc b/website/static/security/patches/SA-26:55/elf-14.patch.asc
new file mode 100644
index 0000000000..4c290a114d
--- /dev/null
+++ b/website/static/security/patches/SA-26:55/elf-14.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqblMbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvwfgP/iEtrYJCWD2VjE9GS0OJ
+lKjhr5YIrU8//RKVKUglIer7ESyyOsXvXPyBrtsdguiWlsKgDja1RDRoPuCYDqzY
+U095DRn/Neefa53Ymxd5uKAoqPus47RuMkDo0+ivphFEd5dbfDzrhoyxHNHpxsu6
+bFG7oU0mqa5lIyFoUjbCjAh5lZyF4RVWh5WQWrMoVKulbQMldai2tXUFh6iqPHlX
+J6+Q0RHDGs0QvXNIDRI2kyJm6FK+/1PO9YgDaE2oSb2qO5or1I2KMCOXHLAF/qcY
+FHFpNzBG2b2UYO4E3CAlyKhQk2j0iZmT8r+q03k6xof1zOx4Akf1keOX4MiYw04U
+r+fzosCDXYgcwz+q1HsoqHhXSvmNL7Se5k+hckqAM3arNICA7ZGxbk0Ja+8B0eQ1
+HtfdMs6dq7Id5JG9zEGsWEEP5H4CIoZDNos2oBvOnZczVI7l7Vew0m2L+eDZeDIL
+sqIvHmsgHe46vRGHFGrYD8qSXUY99xXdfUt9F0+nnNIH6YYpbcbsEeJzCGVViKQd
+uk8Pa1s7P8c6KmHHBZXZ+OiJlPIIv9TG0ZKEhtCh4oWjvaZGj0pGUNOn28IggXv2
+Yh2WNbJUgD+tm4pPhyITz0RruMwX6OAZXKS+k4xyWpabSOGCz5iANCDRVpyHJq5T
+c7lGlaLHyhKBYbXPNJeAU15I
+=pu6D
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/SA-26:55/elf-15.patch b/website/static/security/patches/SA-26:55/elf-15.patch
new file mode 100644
index 0000000000..81375620fc
--- /dev/null
+++ b/website/static/security/patches/SA-26:55/elf-15.patch
@@ -0,0 +1,60 @@
+--- sys/kern/imgact_elf.c.orig
++++ sys/kern/imgact_elf.c
+@@ -1555,6 +1555,8 @@
+ struct phdr_closure {
+ Elf_Phdr *phdr; /* Program header to fill in */
+ Elf_Off offset; /* Offset of segment in core file */
++ int numsegs; /* Maximum number of segments */
++ int nextseg; /* Next segment to fill in */
+ };
+
+ struct note_info {
+@@ -1671,10 +1673,15 @@
+ }
+
+ /*
+- * Allocate memory for building the header, fill it up,
+- * and write it out following the notes.
++ * Allocate memory for building the header, fill it up, and write it out
++ * following the notes.
++ *
++ * Note that a process sharing our vmspace might be concurrently
++ * mutating the map, in which case we could populate fewer than
++ * seginfo.count headers. Zero the buffer to ensure that unpopulated
++ * headers are still initialized.
+ */
+- hdr = malloc(hdrsize, M_TEMP, M_WAITOK);
++ hdr = malloc(hdrsize, M_TEMP, M_WAITOK | M_ZERO);
+ error = __elfN(corehdr)(¶ms, seginfo.count, hdr, hdrsize, ¬elst,
+ notesz, flags);
+
+@@ -1727,6 +1734,11 @@
+ struct phdr_closure *phc = (struct phdr_closure *)closure;
+ Elf_Phdr *phdr = phc->phdr;
+
++ if (phc->nextseg >= phc->numsegs) {
++ /* Only write as many headers as we have space for. */
++ return;
++ }
++
+ phc->offset = round_page(phc->offset);
+
+ phdr->p_type = PT_LOAD;
+@@ -1739,6 +1751,8 @@
+
+ phc->offset += phdr->p_filesz;
+ phc->phdr++;
++
++ phc->nextseg++;
+ }
+
+ /*
+@@ -2001,6 +2015,8 @@
+ /* All the writable segments from the program. */
+ phc.phdr = phdr;
+ phc.offset = round_page(hdrsize + notesz);
++ phc.numsegs = numsegs;
++ phc.nextseg = 0;
+ each_dumpable_segment(td, cb_put_phdr, &phc, flags);
+ }
+
diff --git a/website/static/security/patches/SA-26:55/elf-15.patch.asc b/website/static/security/patches/SA-26:55/elf-15.patch.asc
new file mode 100644
index 0000000000..13b03615c1
--- /dev/null
+++ b/website/static/security/patches/SA-26:55/elf-15.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmpqblQbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvWagQAJ16Rf1aJfrHUM/BlRIS
+RFADkPbNmsVyAlhMEsyBTzx5jFq8RnECli6Fdar6ojOzViMFKVkhFw+B2hNG1Lpv
+fhQBMLkGnKvh0aAV+h1Pmwp2sBZRrYYe2jpjh9rR5zP3ZcPRnLlgC+Rau/22MEUz
+OWc4y+teleAXCEUf+4Iwsd+czp7J3XY8ZlcWlhiRvvof2DTJMMmcDkgPPH6I9wuZ
+N/5HGG2XbD8FWkwAzvwoeagcrcqxCUD7+sXY99ctL9gNIO0V0K2kg8MqGny889TK
+RDC9DsSrZvV8qOqv+Jp3ZFu9w9kAX/axZVwnEZ1qMeBwjkDcTiSrIN/Dv+CsLt/i
+EPFFQioD9BEuOazNBsaN4fig9b1vuCkULCd13YUnIphv/gRS/aQ+bNF+h8jYA4QJ
+lzrtAxX1TyxL57Jrshyh/PV0xfqQ2FrUayEum/if1r0Ym7dTX0GCiTMlfSzlOPaq
+bG0ejz2spTihmaU8DdWEi39+UC7SE/K9VicHNI+itV+OBUrCYFjNFvdHq+gGNc33
+qZSsC3avabComb0DCVRcNl05liF3vDDl1gT8tXeIzFir4PlZ99WwUhrXxtdm8tfh
+yJT96YYejRuDxoioupYGeK1WKlnSAE6nDsqVh3BqiteKBsCO1lVY2UucgY//zv3Y
+R7XjvvHZuiuwcjRPZwabwMA4
+=exkg
+-----END PGP SIGNATURE-----