pkg audit -F pfSense CE 2.8.1
-
New box 2.8.1 old box was also 2.8.1
pfblockerNG and Suricata
pkg audit -FFetching vuln.xml.xz: .......... done
pkg: warning: database version 37 is newer than libpkg(3) version 36, but still compatible
libxslt-1.1.37_1 is vulnerable:
libxslt -- multiple vulnerabilities
CVE: CVE-2025-24855
CVE: CVE-2024-55549
WWW: https://vuxml.FreeBSD.org/freebsd/a96cd659-303e-11f0-94b5-54ee755069b5.htmllibxslt -- multiple vulnerabilities
CVE: CVE-2025-11731
CVE: CVE-2025-9714
CVE: CVE-2025-7425
CVE: CVE-2025-7424
WWW: https://vuxml.FreeBSD.org/freebsd/b0a3466f-5efc-11f0-ae84-99047d0a6bcc.htmllibxml2-2.11.9 is vulnerable:
libxml2 -- multiple vulnerabilities
CVE: CVE-2025-49795
CVE: CVE-2025-49795
CVE: CVE-2025-49794
CVE: CVE-2025-6170
CVE: CVE-2025-6021
WWW: https://vuxml.FreeBSD.org/freebsd/abbc8912-5efa-11f0-ae84-99047d0a6bcc.htmllibxml2 -- Use After Free
CVE: CVE-2024-56171
WWW: https://vuxml.FreeBSD.org/freebsd/bd2af307-3e50-11f0-95d4-00a098b42aeb.htmllibxml2 -- Stack-based Buffer Overflow
CVE: CVE-2025-24928
WWW: https://vuxml.FreeBSD.org/freebsd/fdd02be0-3e50-11f0-95d4-00a098b42aeb.htmlpython311-3.11.11 is vulnerable:
python -- several security vulnerabilities
CVE: CVE-2026-0865
CVE: CVE-2026-1299
WWW: https://vuxml.FreeBSD.org/freebsd/bfe9adc8-0224-11f1-8790-c5fb948922ad.htmlcpython -- Use-after-free in "unicode_escape" decoder with error handler
CVE: CVE-2025-4516
WWW: https://vuxml.FreeBSD.org/freebsd/e587b52d-38ac-11f0-b7b6-dcfe074bd614.htmlpython -- several vulnerabilities
CVE: CVE-2025-13836
CVE: CVE-2025-12084
WWW: https://vuxml.FreeBSD.org/freebsd/613d0f9e-d477-11f0-9e85-03ddfea11990.htmlkea-2.6.2 is vulnerable:
ISC KEA -- Multiple vulnerabilities
CVE: CVE-2025-32803
CVE: CVE-2025-32802
CVE: CVE-2025-32801
WWW: https://vuxml.FreeBSD.org/freebsd/34744aab-3bf7-11f0-b81c-001b217e4ee5.htmlpkcs11-helper-1.29.0_3 is vulnerable:
pkcs11-helper -- deserialize buffer overflow
WWW: https://vuxml.FreeBSD.org/freebsd/1a46e84d-c406-11f0-b513-0da7be77c170.htmlcurl-8.11.0_1 is vulnerable:
curl -- Multiple vulnerabilities
CVE: CVE-2025-4947
CVE: CVE-2025-5025
WWW: https://vuxml.FreeBSD.org/freebsd/533b4470-3f25-11f0-b440-f02f7432cf97.htmlphp83-8.3.19 is vulnerable:
php -- Multiple vulnerabilities
CVE: CVE-2025-1220
CVE: CVE-2025-6491
CVE: CVE-2025-1735
WWW: https://vuxml.FreeBSD.org/freebsd/d607b12c-5821-11f0-ab92-f02f7497ecda.htmlsqlite3-3.46.1,1 is vulnerable:
SQLite < 3.50.3 -- CWE-190 Integer Overflow or Wraparound in FTS5 module
CVE: CVE-2025-7709
WWW: https://vuxml.FreeBSD.org/freebsd/c5889223-b4e1-11f0-ae9b-b42e991fc52e.htmlsqlite -- integer overflow
CVE: CVE-2025-3277
WWW: https://vuxml.FreeBSD.org/freebsd/b945ce3f-6f9b-11f0-bd96-b42e991fc52e.htmlSQLite -- application crash
CVE: CVE-2025-29088
WWW: https://vuxml.FreeBSD.org/freebsd/6989312e-8366-11f0-9bc6-b42e991fc52e.htmlSQLite -- Integer Overflow vulnerability
CVE: CVE-2025-52099
WWW: https://vuxml.FreeBSD.org/freebsd/2cd61f76-b41b-11f0-bf21-b42e991fc52e.htmlsqlite -- Integer Truncation on SQLite
CVE: CVE-2025-6965
WWW: https://vuxml.FreeBSD.org/freebsd/0f5bcba2-67fb-11f0-9ee5-b42e991fc52e.htmllibsodium-1.0.19 is vulnerable:
security/libsodium -- crypto_core_ed25519_is_valid_point mishandles checks for whether an elliptic curve point is valid
CVE: CVE-2025-69277
WWW: https://vuxml.FreeBSD.org/freebsd/583b63f5-ebae-11f0-939f-47e3830276dd.htmlstrongswan-5.9.14 is vulnerable:
strongSwan -- Heap-based buffer overflow in eap-mschapv2 plugin due to improper handling of failure request packets
CVE: CVE-2025-62291
WWW: https://vuxml.FreeBSD.org/freebsd/1f1cf967-b35c-11f0-bce7-bc2411002f50.htmlexpat-2.7.1 is vulnerable:
expat -- multiple vulnerabilities
CVE: CVE-2026-25210
CVE: CVE-2026-24515
WWW: https://vuxml.FreeBSD.org/freebsd/027c6c07-065b-11f1-baae-589cfc023192.html20 problem(s) in 11 installed package(s) found.
-
Most of those don't apply in pfSense.
Make sure you have the System Patched package installed and have applied the recommended patch list.
-
Getting this warning message when SSH into pfSense 2.8.1 from macOS 26.4b4
** WARNING: connection is not using a post-quantum key exchange algorithm. ** This session may be vulnerable to "store now, decrypt later" attacks. ** The server may need to be upgraded. See https://openssh.com/pq.html -
@elvisimprsntr it's a point mentioned in 26.03-RC
https://forum.netgate.com/topic/200319/call-for-testing-pfsense-plus-26.03-rc-now-available
"SSH Algorithms - Increase security by including post-quantum key exchange algorithms and by removing older and weaker algorithms."
And @stephenw10 posted a patch/diff one can apply: https://forum.netgate.com/post/1228026.
Otherwise use the search, luke.
-
@patient0 said in pkg audit -F pfSense CE 2.8.1:
And @stephenw10 posted a patch/diff one can apply: https://forum.netgate.com/post/1228026.
Thanks. The patch does not work. I'll wait for 2.9.1
-
@elvisimprsntr said in pkg audit -F pfSense CE 2.8.1:
Thanks. The patch does not work. I'll wait for 2.9.1
Fair enough. Works for me on 2.8.1, copy-pasting the diff and disabling/enabling ssh.
Privacy Policy · Cookie Policy