NetBSD 10.2 Security Update: Critical Vulnerability in ipfilter Closed

www.news4hackers.com-netbsd-10-2-security-update-critical-vulnerability-in-ipfilter-closed-netbsd-10-2-security-update-critical-vulnerability-in-ipfilter-closed

A critical flaw in the ipfilter component of NetBSD has been resolved in version 10.2, which allows an external attacker to trigger a null pointer dereference in the kernel.

Critical Kernel Vulnerability in ipfilter

NetBSD 10.2 security updates address a remotely exploitable kernel vulnerability in ipfilter A critical flaw in the ipfilter component of NetBSD has been resolved in version 10.2, which allows an external attacker to trigger a null pointer dereference in the kernel. This vulnerability exists in systems using ipfilter as a network traffic filtering mechanism, enabling unauthorized users to cause a system crash by accessing invalid memory addresses.

Patch Release and TCP Timestamp Leak

The NetBSD Project released the patch on September 15 as part of the 10.2 point update for the stable 10 branch. The update also mitigates a separate issue involving a 4-byte leakage of kernel stack data via TCP timestamps, which could expose memory addresses critical for bypassing security mitigations.

Additional Security Fixes and Third-Party Updates

While the affected code in NFS and telnet received fixes, no specific details or CVE identifiers were provided for these changes, underscoring the importance of timely patching for users relying on these services. Additional security improvements include updated third-party software components such as OpenSSL 3.0.21, Xorg 21.1.24, and xkbcomp 1.5.0, along with patches for known vulnerabilities like CVE-2026-4367 in libXpm and CVE-2025-11411 in the unbound DNS resolver.

Kernel Access Controls and Upgrade Instructions

The kernel now enforces stricter access controls for the /dev/hdaudio device. Users are advised to follow a specific upgrade sequence: booting an installation image and selecting the Upgrade option, or updating the kernel and modules first before addressing userspace components. Repository URLs must be adjusted, and all third-party packages refreshed. A new gpufw set may require separate installation through sysinst.

Verification and Security Measures

All distribution files are signed with the NetBSD Security Officer’s PGP key, and verification is mandatory before deploying updates to production environments.



About Author

en_USEnglish