TrueNAS 25.10.5 brings an updated Linux kernel version 6.12.95, which patches multiple security-related CVEs, including SharedFrag (CVE-2026-43503) and PeditCOW (CVE-2026-46331) local privilege escalation vulnerabilities, as well as six more upstream security fixes.
Beyond the kernel, this release also delivers a number of TrueNAS specific fixes:
- A console memory leak was identified that could consume excess RAM
- Corrects several smartctl parsing errors that produced inaccurate drive SMART health reports
- Resolves an error that caused TrueCloud Backup jobs to hang indefinitely when an error occurred in the underlying restic software
- Tightens SSH key handling for replication and cloud credentials
- Obtains full RFC 5322 compliance for emails to ensure reliable delivery
- Improves the robustness of Enterprise HA for block storage
- And fixes a bug that blocked share ACL editing in certain edge cases
For full details on all of the updates, check out the TrueNAS 25.10 changelog on the TrueNAS Docs site.
https://www.truenas.com/blog/truenas-25-10-5-resolving-security-vulnerabilities





