> For the complete documentation index, see [llms.txt](https://book.bsdcn.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://book.bsdcn.org/release/freebsd-10.0-release/10.0-errata.md).

# FreeBSD 10.0-RELEASE 勘误

## 摘要

本文列出 FreeBSD 10.0-RELEASE 的勘误项，包含发行后或在发行周期后期发现的、未能纳入发行版文档的重要信息。这些信息包括安全公告，以及与可能影响软件或文档运行或可用性相关的消息。在安装本版本 FreeBSD 之前，应始终查阅本文档的最新版本。

FreeBSD 10.0-RELEASE 的勘误文档将维护至 FreeBSD 10.1-RELEASE 发布。

## 引言

本勘误文档包含关于 FreeBSD 10.0-RELEASE 的“最新消息”。在安装本版本之前，务必查阅本文档，以了解可能在发布后已经发现并修复的问题。

随发行版实际分发的任何勘误文档副本（例如在 CDROM 发行版上）按定义均已过时，但其他副本在互联网上保持更新，应作为本发行版的“当前勘误”查阅。这些其他勘误副本位于 <https://www.FreeBSD.org/releases/>，以及任何保持该位置最新镜像的站点。

FreeBSD 10.0-STABLE 的源代码和二进制快照也包含本文档的最新副本（截至快照生成时）。

所有 FreeBSD CERT 安全公告列表，请参阅 <https://www.FreeBSD.org/security/> 或 **ftp\://ftp.FreeBSD.org/pub/FreeBSD/CERT/**。

## 安全公告

| 公告                                                                                                       | 日期               | 主题                                 |
| -------------------------------------------------------------------------------------------------------- | ---------------- | ---------------------------------- |
| [FreeBSD-SA-13:14.openssh](https://www.freebsd.org/security/advisories/FreeBSD-SA-13:14.openssh.asc)     | 2013 年 11 月 19 日 | OpenSSH AES-GCM 内存损坏漏洞             |
| [FreeBSD-SA-14:01.bsnmpd](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:01.bsnmpd.asc)       | 2014 年 1 月 14 日  | bsnmpd 远程拒绝服务漏洞                    |
| [FreeBSD-SA-14:02.ntpd](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:02.ntpd.asc)           | 2014 年 1 月 14 日  | ntpd 分布式反射拒绝服务漏洞                   |
| [FreeBSD-SA-14:03.openssl](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:03.openssl.asc)     | 2014 年 1 月 14 日  | OpenSSL 多个漏洞                       |
| [FreeBSD-SA-14:04.bind](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:04.bind.asc)           | 2014 年 1 月 14 日  | BIND 远程拒绝服务漏洞                      |
| [FreeBSD-SA-14:05.nfsserver](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:05.nfsserver.asc) | 2014 年 4 月 8 日   | NFS 服务器中的死锁                        |
| [FreeBSD-SA-14:06.openssl](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:06.openssl.asc)     | 2014 年 4 月 8 日   | OpenSSL 多个漏洞                       |
| [FreeBSD-SA-14:07.devfs](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:07.devfs.asc)         | 2014 年 4 月 30 日  | 修复 devfs 规则默认不应用于 Jail 的问题         |
| [FreeBSD-SA-14:08.tcp](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:08.tcp.asc)             | 2014 年 4 月 30 日  | 修复 TCP 重组漏洞                        |
| [FreeBSD-SA-14:09.openssl](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:09.openssl.asc)     | 2014 年 4 月 30 日  | 修复 OpenSSL use-after-free 漏洞       |
| [FreeBSD-SA-14:10.openssl](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:10.openssl.asc)     | 2014 年 5 月 15 日  | 修复 OpenSSL NULL 指针解引用漏洞            |
| [FreeBSD-SA-14:11.sendmail](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:11.sendmail.asc)   | 2014 年 6 月 3 日   | 修复 sendmail 不当的 close-on-exec 标志处理 |
| [FreeBSD-SA-14:13.pam](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:13.pam.asc)             | 2014 年 6 月 3 日   | 修复 PAM 策略解析器中的错误处理                 |
| [FreeBSD-SA-14:14.openssl](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:14.openssl.asc)     | 2014 年 6 月 5 日   | 多个漏洞                               |
| [FreeBSD-SA-14:15.iconv](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:15.iconv.asc)         | 2014 年 6 月 24 日  | NULL 指针解引用和数组越界访问                  |
| [FreeBSD-SA-14:16.file](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:16.file.asc)           | 2014 年 6 月 24 日  | 多个漏洞                               |
| [FreeBSD-SA-14:17.kmem](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:17.kmem.asc)           | 2014 年 7 月 8 日   | 控制消息和 SCTP 通知中的内核内存泄露              |
| [FreeBSD-SA-14:18.openssl](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:18.openssl.asc)     | 2014 年 9 月 9 日   | 多个漏洞                               |
| [FreeBSD-SA-14:19.tcp](https://www.freebsd.org/security/advisories/FreeBSD-SA-14:19.tcp.asc)             | 2014 年 9 月 16 日  | TCP 数据包处理中的拒绝服务                    |

## 未解决问题

* 以 FreeBSD/i386 10.0-RELEASE 作为客户机操作系统在 VirtualBox 上运行时，可能会出现磁盘 I/O 访问问题。这取决于某些特定的硬件配置，与特定版本的 VirtualBox 或主机操作系统无关。

  这会导致各种错误并使 FreeBSD 相当不稳定。尽管原因尚不清楚，但禁用 unmapped I/O 可作为一种权宜之计。要禁用它，请在引导菜单中选择 `Escape to loader prompt`，并在 `OK` 提示符后从 [loader(8)](https://man.freebsd.org/cgi/man.cgi?query=loader\&sektion=8\&format=html) 提示符中输入以下行：

  ```sh
  set vfs.unmapped_buf_allowed=0
  boot
  ```

  注意，引导后需要将以下行添加到 **/boot/loader.conf** 中。它会在每次引导时禁用 unmapped I/O：

  ```ini
  vfs.unmapped_buf_allowed=0
  ```

  \[2014-04-03 更新] 据报告，在其他虚拟机管理程序（如 Xen 或 KVM）上运行的虚拟机也可能存在不稳定性。
* Heimdal（FreeBSD 基本系统中 Kerberos 认证的实现）中的一个 bug 已修复。该 bug 可能导致 Heimdal 与包括 MIT Kerberos 在内的其他实现之间的互操作性问题。然而，由于此修复，先前 FreeBSD 发行版中的 Heimdal 及依赖它的某些应用程序，在某些情况下无法与 10.0-RELEASE 中的 Heimdal 协同工作。将为受支持的发行版发布勘误通知以修复此问题。
* [killall(1)](https://man.freebsd.org/cgi/man.cgi?query=killall\&sektion=1\&format=html) 中发现一个 bug。该 bug 会使 `killall -INT` 发送 `SIGTERM` 而非期望的 `SIGINT`，并可能对使用该命令的脚本造成阻塞行为，因为 `-I` 表示“交互式”。可使用 `-SIGINT` 替代作为权宜之计。此 bug 已在 FreeBSD-CURRENT 中修复，并将在 FreeBSD 10.0-STABLE 中修复。
* 启用 TSO（TCP Segmentation Offload，TCP 分段卸载）特性时，[bxe(4)](https://man.freebsd.org/cgi/man.cgi?query=bxe\&sektion=4\&format=html) 驱动可能导致数据包损坏。此特性默认启用，可使用 [ifconfig(8)](https://man.freebsd.org/cgi/man.cgi?query=ifconfig\&sektion=8\&format=html) 的参数 `-tso` 禁用。可在 [rc.conf(5)](https://man.freebsd.org/cgi/man.cgi?query=rc.conf\&sektion=5\&format=html) 中如下指定：

  ```sh
  ifconfig_bxe0="DHCP -tso"
  ```

  此 bug 已在 FreeBSD 10.0-STABLE 中修复。
* 由于与 [pkg(7)](https://man.freebsd.org/cgi/man.cgi?query=pkg\&sektion=7\&format=html) 1.2.x 版本存在轻微不兼容性，[bsdconfig(8)](https://man.freebsd.org/cgi/man.cgi?query=bsdconfig\&sektion=8\&format=html) 会重复列出可安装的软件包列表。这是因为设置了 `PACKAGESITE` 环境变量以保持与旧版本 [pkg(7)](https://man.freebsd.org/cgi/man.cgi?query=pkg\&sektion=7\&format=html) 的向后兼容性。这仅影响可用软件包列表的生成，不影响处理安装软件包时的行为。
* [pw(8)](https://man.freebsd.org/cgi/man.cgi?query=pw\&sektion=8\&format=html) 中的一个回归问题：使用标志 `-G` 时，不会从所提供组列表中未指定的组中移除用户。预期此问题将在 FreeBSD-CURRENT 和 FreeBSD 10.0-STABLE 中得到修正。
* 路由更新时，[ipfw(8)](https://man.freebsd.org/cgi/man.cgi?query=ipfw\&sektion=8\&format=html) 的 `fwd` 动作可能将数据包发送到正确接口但使用错误的链路层地址。此 bug 已在 FreeBSD-CURRENT 中修复，并将在 FreeBSD 10.0-STABLE 中修复。
* [mount\_udf(8)](https://man.freebsd.org/cgi/man.cgi?query=mount_udf\&sektion=8\&format=html) 工具存在一个 bug，使其无法挂载任何 UDF 文件系统。此问题已在 FreeBSD-CURRENT 和 FreeBSD 10.0-STABLE 中修复。
* 使用 sas2flash 工具更新 [mps(4)](https://man.freebsd.org/cgi/man.cgi?query=mps\&sektion=4\&format=html) 控制器上的 LSI 固件可能导致系统挂起或 panic。此问题在 `stable/10` 分支中已通过修订 `r262553` 和 `r262575` 修复，将包含在 FreeBSD 10.1-RELEASE 中。

## 最新消息

无消息。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://book.bsdcn.org/release/freebsd-10.0-release/10.0-errata.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
