-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-EN-26:23.syslogd Errata Notice The FreeBSD Project Topic: syslogd(8) leaks child processes when logging to a pipe Category: core Module: syslogd Announced: 2026-09-29 Affects: FreeBSD 15.1 Corrected: 2026-09-09 08:35:26 UTC (stable/15, 15.1-STABLE) 2026-09-29 15:59:59 UTC (releng/15.1, 15.1-RELEASE-p4) For general information regarding FreeBSD Errata Notices and Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit . I. Background syslogd(8) is the system log daemon. It reads log messages from the kernel and from processes, and distributes them to destinations defined in syslog.conf(5). One supported destination is an external program, specified with a leading '|' character, to which syslogd(8) pipes log messages on its standard input. II. Problem Description When syslogd(8) reloaded its configuration on receipt of SIGHUP, as typically happens during log rotation, it could leak the process descriptor for the program at the other end of a pipe destination. III. Impact Each configuration reload may leave behind zombie processes that are never reaped. syslogd(8) may also crash when one of these processes exits. IV. Workaround No workaround is available. Systems not using pipe destinations in syslog.conf(5) are not affected. V. Solution Upgrade your system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date. Perform one of the following: 1) To update your system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base # service syslogd restart 2) To update your system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install # service syslogd restart 3) To update your system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch https://security.FreeBSD.org/patches/EN-26:23/syslogd.patch # fetch https://security.FreeBSD.org/patches/EN-26:23/syslogd.patch.asc # gpg --verify syslogd.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile the operating system using buildworld and installworld as described in . Restart the applicable daemons, or reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ 74c5995d2e8d stable/15-n285422 releng/15.1/ a64d17f24c43 releng/15.1-n283613 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat Or visit the following URL, replacing NNNNNN with the hash: To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmq8DK0bFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvodEQANWmJm4z1aOCe68emirl 1U213rspn7ni4cyKyXezyuNuePWqG16Frlqwc8yN4kblX+odWOeLk0qPGUtxeI1w psOQbLhUL1rgmddqxcXnMseD0+p4hxDK8Y3jUhnrK1jQlIN8BD/b9GHUtLp+ZgKQ P5X1FL+adNj/wvf3ex3JWisC33F7XB1xIGLuHZlHt5Kcx7Rmmp8aqVDhFjR42fht MRC7AA+gxuGn/+eaVPyLB6ow+gIh8X0ju/PgyH06HF7Z0MbhjUTxsafzLqa9XbQ9 kBVATcd8SlW/5Ltj45/6ASbHzw5VxXYqOpPfvVEuF+UiSldqLSkeLkn/mXrlwt3g 4OyTWocfIrcqH3tKpQpdzsjmCU7jVCBPNN3uIcxSsNy4fOA5de201hlKqty2ex7T Jncn4nMWJLemhNEdwWZ+WkxwblXi8hcJ3+r940T7fzTNf0J8QfIL9V2oXlvB4KZM 06Xbz2gdu7vevy1kqGdZIVjpiYfxN0bWxrk7tITONZldcO8/9kz5se6aOG3Yjkcq UOGGG/M0m6dC0YUxUcan1puaDyDa1r52uv6H/zVNrptTnL8YI/zIjkwvzkA5gC8I o2OY7r3wwyIbC9OCIphntd/b/d7vUEaFqn1Y/zR4L5uiVnsEGQ0MZDWNX7LCWMrQ 04HXfjagZcKPRUixPuSdtQYw =FMsL -----END PGP SIGNATURE-----