The FreeBSD project has released an important security advisory, numbered FreeBSD-SA-25:12, disclosing a critical remote code execution vulnerability (CVE-2025-14558) in the rtsold and rtsol programs. These programs handle router advertisement packets for IPv6 Stateless Address Autoconfiguration (SLAAC). The vulnerability stems from the programs’ failure to validate the domain search list option in router advertisement messages, directly passing the option content to the resolvconf(8) script, which lacks input validation and could lead to malicious command injection. Attackers can execute arbitrary code on FreeBSD systems running the affected programs by sending specially crafted router advertisement messages. The attack scope is limited to the same network segment because router advertisements are not routable. This vulnerability affects all supported FreeBSD versions and was patched through an update on December 16, 2025. The advisory emphasizes that this vulnerability highlights the importance of network security protection, and users should apply security patches immediately. No temporary workaround is currently available.
FreeBSD Remote Code Execution Vulnerability Discovered in IPv6 Router Advertisement Handling
未经允许不得转载:80aj » FreeBSD Remote Code Execution Vulnerability Discovered in IPv6 Router Advertisement Handling
相关推荐
我与AWS的二十年纠葛:从早期漏洞挖掘到推动FreeBSD上云
2024年FreeBSD笔记本兼容性榜单:Framework与ThinkPad领跑,AMD/Intel新芯片表现优异
拒绝盲目追逐热点:为何 FreeBSD 仍是服务器端最可靠的“基石”操作系统
拒绝被ISP绑定:如何在个人实验室搭建属于自己的互联网AS和BGP?
FreeBSD家庭NAS入门:配置ZFS镜像
突破FreeBSD监狱:安全漏洞分析与演示
月省5000刀!20+个Claude Code公益站横评:注册就送钱,签到更疯狂
Get AI Code Review in 10 Seconds: A Simple GitHub PR Hack