-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
=============================================================================
FreeBSD-EN-26:23.syslogd Errata Notice
The FreeBSD Project
Topic: syslogd(8) leaks child processes when logging to a pipe
Category: core
Module: syslogd
Announced: 2026-09-29
Affects: FreeBSD 15.1
Corrected: 2026-09-09 08:35:26 UTC (stable/15, 15.1-STABLE)
2026-09-29 15:59:59 UTC (releng/15.1, 15.1-RELEASE-p4)
For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
.
I. Background
syslogd(8) is the system log daemon. It reads log messages from the
kernel and from processes, and distributes them to destinations defined
in syslog.conf(5). One supported destination is an external program,
specified with a leading '|' character, to which syslogd(8) pipes log
messages on its standard input.
II. Problem Description
When syslogd(8) reloaded its configuration on receipt of SIGHUP, as
typically happens during log rotation, it could leak the process
descriptor for the program at the other end of a pipe destination.
III. Impact
Each configuration reload may leave behind zombie processes that are never
reaped. syslogd(8) may also crash when one of these processes exits.
IV. Workaround
No workaround is available. Systems not using pipe destinations in
syslog.conf(5) are not affected.
V. Solution
Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.
Perform one of the following:
1) To update your system installed from base system packages:
Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
arm64 platforms, which were installed using base system packages, can be
updated via the pkg(8) utility:
# pkg upgrade -r FreeBSD-base
# service syslogd restart
2) To update your system installed from binary distribution sets:
Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
which were not installed using base system packages can be updated via the
freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
# service syslogd restart
3) To update your system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
# fetch https://security.FreeBSD.org/patches/EN-26:23/syslogd.patch
# fetch https://security.FreeBSD.org/patches/EN-26:23/syslogd.patch.asc
# gpg --verify syslogd.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch -E -p0 < /path/to/patch
c) Recompile the operating system using buildworld and installworld as
described in .
Restart the applicable daemons, or reboot the system.
VI. Correction details
This issue is corrected as of the corresponding Git commit hash in the
following stable and release branches:
Branch/path Hash Revision
- -------------------------------------------------------------------------
stable/15/ 74c5995d2e8d stable/15-n285422
releng/15.1/ a64d17f24c43 releng/15.1-n283613
- -------------------------------------------------------------------------
Run the following command to see which files were modified by a
particular commit:
# git show --stat
Or visit the following URL, replacing NNNNNN with the hash:
To determine the commit count in a working tree (for comparison against
nNNNNNN in the table above), run:
# git rev-list --count --first-parent HEAD
VII. References
The latest revision of this advisory is available at
-----BEGIN PGP SIGNATURE-----
iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmq8DK0bFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvodEQANWmJm4z1aOCe68emirl
1U213rspn7ni4cyKyXezyuNuePWqG16Frlqwc8yN4kblX+odWOeLk0qPGUtxeI1w
psOQbLhUL1rgmddqxcXnMseD0+p4hxDK8Y3jUhnrK1jQlIN8BD/b9GHUtLp+ZgKQ
P5X1FL+adNj/wvf3ex3JWisC33F7XB1xIGLuHZlHt5Kcx7Rmmp8aqVDhFjR42fht
MRC7AA+gxuGn/+eaVPyLB6ow+gIh8X0ju/PgyH06HF7Z0MbhjUTxsafzLqa9XbQ9
kBVATcd8SlW/5Ltj45/6ASbHzw5VxXYqOpPfvVEuF+UiSldqLSkeLkn/mXrlwt3g
4OyTWocfIrcqH3tKpQpdzsjmCU7jVCBPNN3uIcxSsNy4fOA5de201hlKqty2ex7T
Jncn4nMWJLemhNEdwWZ+WkxwblXi8hcJ3+r940T7fzTNf0J8QfIL9V2oXlvB4KZM
06Xbz2gdu7vevy1kqGdZIVjpiYfxN0bWxrk7tITONZldcO8/9kz5se6aOG3Yjkcq
UOGGG/M0m6dC0YUxUcan1puaDyDa1r52uv6H/zVNrptTnL8YI/zIjkwvzkA5gC8I
o2OY7r3wwyIbC9OCIphntd/b/d7vUEaFqn1Y/zR4L5uiVnsEGQ0MZDWNX7LCWMrQ
04HXfjagZcKPRUixPuSdtQYw
=FMsL
-----END PGP SIGNATURE-----