Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    pkg audit -F pfSense CE 2.8.1

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 4 Posters 1.1k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y Offline
      yorke
      last edited by

      Re: ARPA DNS ipv6 phishing

      New box 2.8.1 old box was also 2.8.1
      pfblockerNG and Suricata
      pkg audit -F

      Fetching vuln.xml.xz: .......... done
      pkg: warning: database version 37 is newer than libpkg(3) version 36, but still compatible
      libxslt-1.1.37_1 is vulnerable:
      libxslt -- multiple vulnerabilities
      CVE: CVE-2025-24855
      CVE: CVE-2024-55549
      WWW: https://vuxml.FreeBSD.org/freebsd/a96cd659-303e-11f0-94b5-54ee755069b5.html

      libxslt -- multiple vulnerabilities
      CVE: CVE-2025-11731
      CVE: CVE-2025-9714
      CVE: CVE-2025-7425
      CVE: CVE-2025-7424
      WWW: https://vuxml.FreeBSD.org/freebsd/b0a3466f-5efc-11f0-ae84-99047d0a6bcc.html

      libxml2-2.11.9 is vulnerable:
      libxml2 -- multiple vulnerabilities
      CVE: CVE-2025-49795
      CVE: CVE-2025-49795
      CVE: CVE-2025-49794
      CVE: CVE-2025-6170
      CVE: CVE-2025-6021
      WWW: https://vuxml.FreeBSD.org/freebsd/abbc8912-5efa-11f0-ae84-99047d0a6bcc.html

      libxml2 -- Use After Free
      CVE: CVE-2024-56171
      WWW: https://vuxml.FreeBSD.org/freebsd/bd2af307-3e50-11f0-95d4-00a098b42aeb.html

      libxml2 -- Stack-based Buffer Overflow
      CVE: CVE-2025-24928
      WWW: https://vuxml.FreeBSD.org/freebsd/fdd02be0-3e50-11f0-95d4-00a098b42aeb.html

      python311-3.11.11 is vulnerable:
      python -- several security vulnerabilities
      CVE: CVE-2026-0865
      CVE: CVE-2026-1299
      WWW: https://vuxml.FreeBSD.org/freebsd/bfe9adc8-0224-11f1-8790-c5fb948922ad.html

      cpython -- Use-after-free in "unicode_escape" decoder with error handler
      CVE: CVE-2025-4516
      WWW: https://vuxml.FreeBSD.org/freebsd/e587b52d-38ac-11f0-b7b6-dcfe074bd614.html

      python -- several vulnerabilities
      CVE: CVE-2025-13836
      CVE: CVE-2025-12084
      WWW: https://vuxml.FreeBSD.org/freebsd/613d0f9e-d477-11f0-9e85-03ddfea11990.html

      kea-2.6.2 is vulnerable:
      ISC KEA -- Multiple vulnerabilities
      CVE: CVE-2025-32803
      CVE: CVE-2025-32802
      CVE: CVE-2025-32801
      WWW: https://vuxml.FreeBSD.org/freebsd/34744aab-3bf7-11f0-b81c-001b217e4ee5.html

      pkcs11-helper-1.29.0_3 is vulnerable:
      pkcs11-helper -- deserialize buffer overflow
      WWW: https://vuxml.FreeBSD.org/freebsd/1a46e84d-c406-11f0-b513-0da7be77c170.html

      curl-8.11.0_1 is vulnerable:
      curl -- Multiple vulnerabilities
      CVE: CVE-2025-4947
      CVE: CVE-2025-5025
      WWW: https://vuxml.FreeBSD.org/freebsd/533b4470-3f25-11f0-b440-f02f7432cf97.html

      php83-8.3.19 is vulnerable:
      php -- Multiple vulnerabilities
      CVE: CVE-2025-1220
      CVE: CVE-2025-6491
      CVE: CVE-2025-1735
      WWW: https://vuxml.FreeBSD.org/freebsd/d607b12c-5821-11f0-ab92-f02f7497ecda.html

      sqlite3-3.46.1,1 is vulnerable:
      SQLite < 3.50.3 -- CWE-190 Integer Overflow or Wraparound in FTS5 module
      CVE: CVE-2025-7709
      WWW: https://vuxml.FreeBSD.org/freebsd/c5889223-b4e1-11f0-ae9b-b42e991fc52e.html

      sqlite -- integer overflow
      CVE: CVE-2025-3277
      WWW: https://vuxml.FreeBSD.org/freebsd/b945ce3f-6f9b-11f0-bd96-b42e991fc52e.html

      SQLite -- application crash
      CVE: CVE-2025-29088
      WWW: https://vuxml.FreeBSD.org/freebsd/6989312e-8366-11f0-9bc6-b42e991fc52e.html

      SQLite -- Integer Overflow vulnerability
      CVE: CVE-2025-52099
      WWW: https://vuxml.FreeBSD.org/freebsd/2cd61f76-b41b-11f0-bf21-b42e991fc52e.html

      sqlite -- Integer Truncation on SQLite
      CVE: CVE-2025-6965
      WWW: https://vuxml.FreeBSD.org/freebsd/0f5bcba2-67fb-11f0-9ee5-b42e991fc52e.html

      libsodium-1.0.19 is vulnerable:
      security/libsodium -- crypto_core_ed25519_is_valid_point mishandles checks for whether an elliptic curve point is valid
      CVE: CVE-2025-69277
      WWW: https://vuxml.FreeBSD.org/freebsd/583b63f5-ebae-11f0-939f-47e3830276dd.html

      strongswan-5.9.14 is vulnerable:
      strongSwan -- Heap-based buffer overflow in eap-mschapv2 plugin due to improper handling of failure request packets
      CVE: CVE-2025-62291
      WWW: https://vuxml.FreeBSD.org/freebsd/1f1cf967-b35c-11f0-bce7-bc2411002f50.html

      expat-2.7.1 is vulnerable:
      expat -- multiple vulnerabilities
      CVE: CVE-2026-25210
      CVE: CVE-2026-24515
      WWW: https://vuxml.FreeBSD.org/freebsd/027c6c07-065b-11f1-baae-589cfc023192.html

      20 problem(s) in 11 installed package(s) found.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        Most of those don't apply in pfSense.

        Make sure you have the System Patched package installed and have applied the recommended patch list.

        1 Reply Last reply Reply Quote 0
        • E Offline
          elvisimprsntr
          last edited by elvisimprsntr

          Getting this warning message when SSH into pfSense 2.8.1 from macOS 26.4b4

          ** WARNING: connection is not using a post-quantum key exchange algorithm.
          ** This session may be vulnerable to "store now, decrypt later" attacks.
          ** The server may need to be upgraded. See https://openssh.com/pq.html
          

          https://www.openssh.org/pq.html

          patient0P 1 Reply Last reply Reply Quote 0
          • patient0P Online
            patient0 @elvisimprsntr
            last edited by

            @elvisimprsntr it's a point mentioned in 26.03-RC

            https://forum.netgate.com/topic/200319/call-for-testing-pfsense-plus-26.03-rc-now-available

            "SSH Algorithms - Increase security by including post-quantum key exchange algorithms and by removing older and weaker algorithms."

            And @stephenw10 posted a patch/diff one can apply: https://forum.netgate.com/post/1228026.

            Otherwise use the search, luke.

            E 1 Reply Last reply Reply Quote 1
            • E Offline
              elvisimprsntr @patient0
              last edited by

              @patient0 said in pkg audit -F pfSense CE 2.8.1:

              And @stephenw10 posted a patch/diff one can apply: https://forum.netgate.com/post/1228026.

              Thanks. The patch does not work. I'll wait for 2.9.1

              patient0P 1 Reply Last reply Reply Quote 0
              • patient0P Online
                patient0 @elvisimprsntr
                last edited by

                @elvisimprsntr said in pkg audit -F pfSense CE 2.8.1:

                Thanks. The patch does not work. I'll wait for 2.9.1

                Fair enough. Works for me on 2.8.1, copy-pasting the diff and disabling/enabling ssh.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                Privacy Policy · Cookie Policy