From now on, to improve security, man:ipfilter[4] only allows jails to manipulate ipfilter rules, NAT tables, and ippools if the jail has its own VNET. A number of other improvements have been implemented.
The man:netmap[4] framework had a fix for a TOCTOU vulnerability as well as a bug regarding an integer overflow.
-
+////
[[future-releases]]
== General Notes Regarding Future FreeBSD Releases
@@ -407,3 +407,4 @@
====
This change does not affect the FreeBSD 12.x series of releases.