Skip to content

Commit f890ec2

Browse files
committed
changelogs
1 parent 9d5c1a4 commit f890ec2

1 file changed

Lines changed: 10 additions & 0 deletions

File tree

source/releases/BE_25.10.rst

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -159,6 +159,16 @@ Here are the full patch notes:
159159
* ports: python security fixes `[16] <https://www.cve.org/cverecord?id=CVE-2025-12084>`__ `[17] <https://www.cve.org/cverecord?id=CVE-2025-13836>`__ `[18] <https://www.cve.org/cverecord?id=CVE-2026-1299>`__ `[19] <https://www.cve.org/cverecord?id=CVE-2026-0865>`__
160160
* ports: suricata 8.0.3 `[20] <https://suricata.io/2026/01/13/suricata-8-0-3-and-7-0-14-released/>`__
161161

162+
A hotfix release was issued as 25.10.2_3:
163+
164+
* captive portal: fix hard-timeout calculation
165+
* firmware: avoid update-hook background cleanups
166+
* mvc: fix CSRF vulnerability in multiple API endpoints by enforcing POST-only requests `[21] <https://www.cve.org/cverecord?id=CVE-2026-30868>`__ (contributed by Oliver Jueguen)
167+
* src: file: qualify pointers to capsicum rights as const
168+
* src: file: add a fd flag with O_RESOLVE_BENEATH semantics
169+
* src: file: Fix the !CAPABILITIES build
170+
* src: unix: Set O_RESOLVE_BENEATH on fds transferred between jails `[22] <https://www.freebsd.org/security/advisories/FreeBSD-SA-26:04.jail.asc>`__
171+
* src: rtsock: Fix stack overflow `[23] <https://www.freebsd.org/security/advisories/FreeBSD-SA-26:05.route.asc>`__
162172

163173

164174
--------------------------------------------------------------------------

0 commit comments

Comments
 (0)