¡¾·ì϶¹«¸æ¡¿FreeBSD setcred ±¾µØÈ¨ÏÞÌáÉý·ì϶(CVE-2026-45250)

°ä²¼¹¦·ò 2026-05-22

Ò»¡¢·ì϶¸ÅÊö


FreeBSDÊÇÒ»¿î¿ªÔ´Àà Unix ²Ù×÷ϵͳ£¬¿í·ºÀûÓÃÓÚ·þÎñÆ÷¡¢´æ´¢¡¢ÍøÂçÉ豸¼°¸ß»úÄÜÍÆË㳡¾°¡£ÆäÄÚºËÌṩÆëÈ«µÄ¹ý³ÌÖÎÀí¡¢Îļþϵͳ¡¢ÍøÂçºÍ̸ջ¼°È¨ÏÞ½ÚÔì»úÔ죬ÔÚ»¥ÁªÍø»ù´¡ÉèÊ©ÓëÆóÒµ¼¶ÏµÍ³ÖÐÓµÓнϸßÀûÓÃÂÊ¡£2026Äê5ÔÂ22ÈÕ£¬±¦ÔËÀ³¹Ù·½ÍøÕ¾°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½FreeBSD setcred ±¾µØÈ¨ÏÞÌáÉý·ì϶¡£¸Ã·ì϶ԴÓÚÄÚºËÔÚУÑéŲÓÃÕßȨÏÞ֮ǰ£¬½«Óû§¿É¿ØµÄ²¹³ä×éÁÐ±í¸´Ôìµ½¹Ì¶¨´óÓ×µÄÕ»»º³åÇøÊ±£¬ÃýÎóʹÓÃÁËÖ¸Õë´óÓ×½øÐ㤶ÈÍÆË㣬µ¼ÖÂÕ»ÄÚ´æÔ½½çдÈ롣δ¾­ÊÚȨµÄ±¾µØÓû§¿ÉÀûÓø÷ì϶´¥·¢Äں˱ÀÀ££¨DoS£©£¬ÔÚÌØ¶¨Ç°ÌáÏ»¹¿ÉʵÏÖ±¾µØÈ¨ÏÞÌáÉý£¨LPE£©£¬»ñÈ¡ root ȨÏÞ¡£


¶þ¡¢Ó°ÏìÁìÓò


FreeBSD 14.3.X < 14.3-RELEASE-p14

FreeBSD 14.4.X < 14.4-RELEASE-p5

FreeBSD 15.0.X < 15.0-RELEASE-p9

FreeBSD stable/14 ·ÖÖ§ÔÚ 2026-05-20 ½¨¸´Ç°µÄ°æ±¾

FreeBSD stable/15 ·ÖÖ§ÔÚ 2026-01-06 ½¨¸´Ç°µÄ°æ±¾


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬ÒÔ½¨¸´¸Ã·ì϶¡£

FreeBSD >= 14.3-RELEASE-p14

FreeBSD >= 14.4-RELEASE-p5F

reeBSD >= 15.0-RELEASE-p9


ÏÂÔØÁ´½Ó£º

https://www.freebsd.org/security/advisories/FreeBSD-SA-26:18.setcred.asc/

https://www.freebsd.org/security/advisories/FreeBSD-SA-26:18.setcred.asc

Éý¼¶ÊµÏÖºóÐè³ÁÆôϵͳʹ½¨¸´»îЧ¡£

ʹÓà base system packages ×°ÖõÄϵͳ

¶ÔÓÚͨ¹ý base system packages ×°ÖÃµÄ FreeBSD 15.0-RELEASE£¨amd64 »ò arm64£©ÏµÍ³£¬¿ÉÖ´ÐÐÒÔϺÅÁî¸üУº

pkg upgrade -r FreeBSD-base

shutdown -r +10min Rebooting for a security update

ʹÓà binary distribution sets ×°ÖõÄϵͳ

¶ÔÓÚͨ¹ý binary distribution sets ×°ÖÃµÄ RELEASE °æ±¾ÏµÍ³£¬¿ÉÖ´ÐÐÒÔϺÅÁî¸üУº

freebsd-update fetchfreebsd-update

 installshutdown -r +10min Rebooting for a security update

ʹÓÃÔ´Âë²¹¶¡½¨¸´

¹Ù·½ÌṩÁ˶ÔÓ¦°²È«²¹¶¡£¬Óû§¿Éƾ¾Ýϵͳ°æ±¾ÏÂÔØ²¢ÀûÓá£

FreeBSD 15.x

fetch https://security.FreeBSD.org/patches/SA-26:18/setcred-15.patch

fetch https://security.FreeBSD.org/patches/SA-26:18/setcred-15.patch.asc

gpg verify setcred-15.patch.asc

FreeBSD 14.x

fetch https://security.FreeBSD.org/patches/SA-26:18/setcred-14.patch

fetch https://security.FreeBSD.org/patches/SA-26:18/setcred-14.patch.asc

gpg verify setcred-14.patch.asc


ÀûÓò¹¶¡£º

cd /usr/src

patch < /path/to/patch

²¹¶¡ÀûÓÃʵÏÖºó£¬ÒÀÕÕ FreeBSD ¹Ù·½Äں˱àÒëÎĵµ³ÁбàÒë²¢×°ÖÃÄںˣ¬Ëæºó³ÁÆôϵͳ¡£


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£Ê¹ÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://www.freebsd.org/security/advisories/FreeBSD-SA-26:18.setcred.asc/

https://www.freebsd.org/security/advisories/FreeBSD-SA-26:18.setcred.asc

https://fatgid.io/http://www.openwall.com/lists/oss-security/2026/05/21/3

http://www.openwall.com/lists/oss-security/2026/05/21/18