{"id":40196,"date":"2021-03-26T14:01:43","date_gmt":"2021-03-26T14:01:43","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32140\/Buffer-Overruns-License-Violations-And-Bad-Code-FreeBSD-13s-Close-Call.html"},"modified":"2021-03-26T14:01:43","modified_gmt":"2021-03-26T14:01:43","slug":"buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/","title":{"rendered":"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13&#8217;s Close Call"},"content":{"rendered":"<figure class=\"intro-image intro-left\"><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/03\/freebsd-beastie-this-is-fine-800x450.jpg\" alt=\"FreeBSD's core development team, for the most part, does not appear to see the need to update their review and approval procedures.\"><figcaption class=\"caption\">\n<div class=\"caption-text\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/03\/freebsd-beastie-this-is-fine.jpg\" class=\"enlarge-link\" data-height=\"844\" data-width=\"1500\">Enlarge<\/a> <span class=\"sep\">\/<\/span> FreeBSD&#8217;s core development team, for the most part, does not appear to see the need to update their review and approval procedures.<\/div>\n<div class=\"caption-credit\">Aurich Lawson (after KC Green)<\/div>\n<\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"><a title=\"154 posters participating, including story author\" class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/03\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">305<\/span> <span class=\"visually-hidden\"> with 154 posters participating, including story author<\/span> <\/a> <\/p>\n<div class=\"share-links\">\n<h4>Share this story<\/h4>\n<\/p><\/div>\n<\/aside>\n<p><!-- cache hit 190:single\/related:9df27bc37f7ed5e99888ee5f93ab58c8 --><!-- empty -->At first glance, Matthew Macy seemed like a perfectly reasonable choice to port WireGuard into the FreeBSD kernel. WireGuard is an encrypted point-to-point tunneling protocol, part of what most people think of as a &#8220;VPN.&#8221; FreeBSD is a Unix-like operating system that powers everything from Cisco and Juniper routers to Netflix&#8217;s network stack, and Macy had plenty of experience on its dev team, including work on multiple network drivers.<\/p>\n<p>So when Jim Thompson, the CEO of Netgate, which makes FreeBSD-powered routers, decided it was time for FreeBSD to enjoy the same level of in-kernel WireGuard support that Linux does, he reached out to offer Macy a contract. Macy would port WireGuard into the FreeBSD kernel, where Netgate could then use it in the company&#8217;s popular pfSense router distribution. The contract was offered without deadlines or milestones; Macy was simply to get the job done on his own schedule.<\/p>\n<p>With Macy&#8217;s level of experience\u2014with kernel coding and network stacks in particular\u2014the project looked like a slam dunk. But things went awry almost immediately. WireGuard founding developer Jason Donenfeld didn&#8217;t hear about the project until it surfaced on a FreeBSD mailing list, and Macy didn&#8217;t seem interested in Donenfeld&#8217;s assistance when offered. After roughly nine months of part-time development, Macy committed his port\u2014largely unreviewed and inadequately tested\u2014directly into the HEAD section of FreeBSD&#8217;s code repository, where it was scheduled for incorporation into FreeBSD 13.0-RELEASE.<\/p>\n<p>This unexpected commit raised the stakes for Donenfeld, whose project would ultimately be judged on the quality of any production release under the WireGuard name. Donenfeld identified numerous problems with Macy&#8217;s code, but rather than object to the port&#8217;s release, Donenfeld decided to fix the issues. He collaborated with FreeBSD developer Kyle Evans and with Matt Dunwoodie, an OpenBSD developer who had worked on WireGuard for that operating system. The three replaced almost all of Macy&#8217;s code in a mad week-long sprint.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>This went over very poorly with Netgate, which sponsored Macy&#8217;s work. Netgate had already taken Macy&#8217;s beta code from a FreeBSD 13 release candidate and placed it into production in pfSense&#8217;s 2.5.0 release. The forklift upgrade performed by Donenfeld and collaborators\u2014along with Donenfeld&#8217;s sharp characterization of Macy&#8217;s code\u2014presented the company with a serious PR problem.<\/p>\n<p>Netgate&#8217;s public response included&nbsp;<a href=\"https:\/\/lists.freebsd.org\/pipermail\/dev-commits-src-main\/2021-March\/002835.html\">accusations<\/a> of &#8220;irrational bias against mmacy and Netgate&#8221; and irresponsible <a href=\"https:\/\/www.netgate.com\/blog\/painful-lessons-learned-in-security-and-community.html\">disclosure<\/a>&nbsp;of &#8220;a number of zero-day exploits&#8221;\u2014despite Netgate&#8217;s near-simultaneous&nbsp;<a href=\"https:\/\/www.netgate.com\/blog\/painful-lessons-learned-in-security-and-community.html\">declaration<\/a>&nbsp;that no actual vulnerabilities existed.<\/p>\n<p>This combative response from Netgate raised increased scrutiny from many sources, which uncovered surprising elements of Macy&#8217;s own past. He and his wife Nicole had been&nbsp;<a href=\"https:\/\/www.theregister.com\/2008\/04\/24\/kip_macy_arrest\/\">arrested<\/a> in 2008 after two years spent attempting to illegally evict tenants from a small San Francisco apartment building the pair had bought.<\/p>\n<p>The Macys&#8217; attempts to force their tenants out included sawing through floor support joists to make the building unfit for human habitation, sawing <a href=\"https:\/\/www.theregister.com\/2008\/04\/24\/kip_macy_arrest\/\">holes<\/a> directly through the floors of tenants&#8217; apartments, and forging extremely threatening emails appearing to be from the tenants themselves. The couple <a href=\"https:\/\/abcnews.go.com\/US\/exclusive-landlord-hell-defends-terrorizing-apartment-tenants\/story?id=20875476\">fled<\/a> to Italy to avoid prosecution but were eventually extradited back to the US\u2014where they pled guilty to a reduced set of felonies and served four years and four months each.<\/p>\n<p>Macy&#8217;s history as a landlord, unsurprisingly, dogged him professionally\u2014which contributed to his own lack of attention to the doomed WireGuard port.<\/p>\n<p>&#8220;I didn&#8217;t even want to do this work,&#8221; Macy eventually told us. &#8220;I was burned out, spent many months with post-COVID&nbsp;syndrome&#8230;&nbsp;I&#8217;d suffered through years of verbal abuse from non-doers and semi-non-doers in the project whose one big one up on me is that they aren&#8217;t felons. I jumped at the opportunity to leave the project in December&#8230; I just felt a moral obligation to get [the WireGuard port] over the finish line. So you&#8217;ll have to forgive me if my final efforts were a bit half-hearted.&#8221;<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>This admission answers why such an experienced, qualified developer might produce inferior code\u2014but it raises much larger questions about process and procedure within the FreeBSD core committee itself.<\/p>\n<p>How did so much sub-par code make it so far into a major open source operating system? Where was the code review which should have stopped it? And why did both the FreeBSD core team and Netgate seem more focused on the fact that the code was being disparaged than its actual quality?<\/p>\n<h2>Code quality<\/h2>\n<p>The first issue is whether Macy&#8217;s code actually had significant problems. Donenfeld said that it did, and he <a href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2021-March\/006494.html\">identified<\/a> a number of major issues:<\/p>\n<ul>\n<li>Sleep to mitigate race conditions<\/li>\n<li>Validation functions which simply return true<\/li>\n<li>Catastrophic cryptographic vulnerabilities<\/li>\n<li>Pieces of the wg protocol left unimplemented<\/li>\n<li>Kernel panics<\/li>\n<li>Security bypasses<\/li>\n<li>Printf statements deep in crypto code<\/li>\n<li>&#8220;Spectacular&#8221; buffer overflows<\/li>\n<li>Mazes of Linux\u2192FreeBSD ifdefs<\/li>\n<\/ul>\n<p>But Netgate argued that Donenfeld had gone overboard with his negative assessment. The original Macy code, they argued, was simply not that bad.<\/p>\n<p>Despite not having any kernel developers on-staff, Ars was able to verify at least some of Donenfeld&#8217;s claims directly, quickly, and without external assistance. For instance, finding a validation function which simply returned true\u2014and <code>printf<\/code> statements buried deep in cryptographic loops\u2014required nothing more complicated than <code>grep<\/code>.<\/p>\n<h3>Empty validation function<\/h3>\n<p>In order to confirm or deny the claim of an empty validation function\u2014one which always &#8220;returns true&#8221; rather than actually validating the data passed to it\u2014we searched for instances of <code>return true<\/code>&nbsp;or <code>return (true)<\/code>&nbsp;in Macy&#8217;s <code>if_wg<\/code>&nbsp;code, as checked into FreeBSD <code>13.0-HEAD<\/code>.<\/p>\n<pre class=\"language-bash\"><code>root@banshee:~\/macy-freebsd-wg\/sys\/dev\/if_wg# grep -ir 'return.*true' . | wc -l\n21<\/code><\/pre>\n<p>This is a small enough number of returns to easily hand-audit, so we then used <code>grep<\/code>&nbsp;to find the same data but with three lines of code coming immediately before and after each <code>return true<\/code>:<\/p>\n<pre class=\"language-bash\"><code>root@banshee:~\/macy-freebsd-wg\/sys\/dev\/if_wg# grep -ir -A3 -B3 'return.*true' .<\/code><\/pre>\n<p>Among the valid uses of <code>return true<\/code>, we discovered one empty validation function, in <code>module\/module.c<\/code>:<\/p>\n<pre class=\"language-c\"><code>wg_allowedip_valid(const struct wg_allowedip *wip)\n{ return (true);\n}<\/code><\/pre>\n<p>It&#8217;s probably worth mentioning that this empty validation function is not buried at the bottom of a sprawling mass of code\u2014<code>module.c<\/code>&nbsp;as written is only 863 total lines of code.<\/p>\n<p>We did not attempt to chase down the use of this function any further, but it appears to be intended to check whether a packet&#8217;s source and\/or destination belongs to WireGuard&#8217;s <code>allowed-ips<\/code>&nbsp;list, which determines what packets may be routed down a given WireGuard tunnel.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32140\/Buffer-Overruns-License-Violations-And-Bad-Code-FreeBSD-13s-Close-Call.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":40197,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[9296],"class_list":["post-40196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinewirelessflawbsdpatch"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Buffer Overruns, License Violations, And Bad Code: FreeBSD 13&#039;s Close Call 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13&#039;s Close Call 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-26T14:01:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13&#8217;s Close Call\",\"datePublished\":\"2021-03-26T14:01:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/\"},\"wordCount\":1113,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg\",\"keywords\":[\"headline,wireless,flaw,bsd,patch\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/\",\"name\":\"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13's Close Call 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg\",\"datePublished\":\"2021-03-26T14:01:43+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg\",\"width\":800,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,wireless,flaw,bsd,patch\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinewirelessflawbsdpatch\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13&#8217;s Close Call\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13's Close Call 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/","og_locale":"en_US","og_type":"article","og_title":"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13's Close Call 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-03-26T14:01:43+00:00","og_image":[{"width":800,"height":450,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13&#8217;s Close Call","datePublished":"2021-03-26T14:01:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/"},"wordCount":1113,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg","keywords":["headline,wireless,flaw,bsd,patch"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/","url":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/","name":"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13's Close Call 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg","datePublished":"2021-03-26T14:01:43+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call.jpg","width":800,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,wireless,flaw,bsd,patch","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinewirelessflawbsdpatch\/"},{"@type":"ListItem","position":3,"name":"Buffer Overruns, License Violations, And Bad Code: FreeBSD 13&#8217;s Close Call"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=40196"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40196\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/40197"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=40196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=40196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=40196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}