专注于分布式系统架构AI辅助开发工具(Claude
Code中文周刊)

FreeBSD Remote Code Execution Vulnerability Discovered in IPv6 Router Advertisement Handling

智谱 GLM,支持多语言、多任务推理。从写作到代码生成,从搜索到知识问答,AI 生产力的中国解法。

The FreeBSD project has released an important security advisory, numbered FreeBSD-SA-25:12, disclosing a critical remote code execution vulnerability (CVE-2025-14558) in the rtsold and rtsol programs. These programs handle router advertisement packets for IPv6 Stateless Address Autoconfiguration (SLAAC). The vulnerability stems from the programs’ failure to validate the domain search list option in router advertisement messages, directly passing the option content to the resolvconf(8) script, which lacks input validation and could lead to malicious command injection. Attackers can execute arbitrary code on FreeBSD systems running the affected programs by sending specially crafted router advertisement messages. The attack scope is limited to the same network segment because router advertisements are not routable. This vulnerability affects all supported FreeBSD versions and was patched through an update on December 16, 2025. The advisory emphasizes that this vulnerability highlights the importance of network security protection, and users should apply security patches immediately. No temporary workaround is currently available.

Original link:Hacker News

赞(0)
未经允许不得转载:Toy Tech Blog » FreeBSD Remote Code Execution Vulnerability Discovered in IPv6 Router Advertisement Handling
免费、开放、可编程的智能路由方案,让你的服务随时随地在线。

评论 抢沙发

十年稳如初 — LocVPS,用时间证明实力

10+ 年老牌云主机服务商,全球机房覆盖,性能稳定、价格厚道。

老品牌,更懂稳定的价值你的第一台云服务器,从 LocVPS 开始