TrueNAS 25.10.6: Resolving a Truckload of CVEs

}

August 12, 2026

Patch notes are supposed to be boring. A short list of CVEs, a version bump, nothing to see here. That stopped being true the moment AI models got better at finding vulnerabilities than most people are at writing proof-of-concepts for them.

TL;DR: TrueNAS 25.10.5 shipped last month with a normal batch of kernel CVE fixes. TrueNAS 25.10.6 ships fixes for more than 250 upstream CVEs just 19 days later, plus eight TrueNAS-specific fixes spanning Fibre Channel, NFS, and HA failover. None of them are flagged as under active exploitation in the official notes – but at this volume, batching fixes into the next scheduled release stops making sense.

The Math Changed, Not TrueNAS

Every OS vendor is living this right now, not just us. Microsoft’s July update alone patched over 600 CVEs – a volume that would have taken years to work through five years ago. Anthropic’s Project Glasswing found that its Claude Mythos model could autonomously surface thousands of previously unknown vulnerabilities across every major OS and browser, and Epoch AI has since tracked a 3.5x spike in disclosed CVEs. Older, less-scrutinized platforms aren’t safer by comparison. They just haven’t had a model pointed at them yet.

TrueNAS isn’t exempt from that math, and pretending otherwise would be the actual security risk. What changes is how fast we act on what gets found.

What’s Actually Fixed

TrueNAS 25.10.6 bumps the Linux kernel from v6.12.95 to v6.12.99, the latest 6.12 LTS release, pulling in fixes for more than 250 upstream CVEs. 25.10.5 gave its two headline vulnerabilities nicknames – SharedFrag, PeditCOW. At 250-plus, naming each one stops making sense, but a handful are still worth calling out by number: a reference count underflow in the TCP request socket queue (CVE-2026-53260), an NFS server that failed to release layout state after a failed lease request (CVE-2026-53399), and out-of-bounds reads in the NVMe target discovery log and authentication handling (CVE-2026-64320 and CVE-2026-64319). None of these are flagged as under active exploitation in the official notes — this is proactive patching, not incident response. The TrueNAS 25.10 changelog has the complete list.

This release also moves the NVIDIA GPU driver to the 580 branch (v580.173.02). The previous 570 branch hit end of life and won’t build against the newer Linux kernel used, so the update wasn’t optional for anyone running GPU passthrough or transcoding workloads.

Beyond the kernel and GPU driver, this release also fixes:

  • Crashes when Fibre Channel target mode starts or stops on Enterprise systems
  • An NFS server hang that could stop expiring clients after a brief network interruption — bad enough to require a reboot to clear
  • False drive self-test failure alerts caused by TrueNAS reading the wrong SMART result
  • Deduplication table (DDT) pruning errors that could misjudge entry age or overflow counters on very large tables
  • A stuck Save button that blocked directory services configuration changes after upgrading from 25.04
  • The ability to change the ALUA setting on Enterprise HA systems even when the standby controller is unreachable
  • Failover speed on Enterprise HA systems, by moving a remote disk scan out of the critical failover path
  • Audit entry parsing that could crash and restart the audit handler

Six Point Releases In, Still the Version to Run

TrueNAS 25.10 is running on over 160,000 systems – the widest install base any TrueNAS release has had, with Community Edition and Enterprise both defaulting to it. That base is also why we can be direct about this: none of the CVEs fixed in 25.10.6 are flagged as under active exploitation in the official notes.

That’s the case for shipping fast instead of batching fixes into a slower, “safer-looking” cycle. A vulnerability sitting unpatched for three months because it’s waiting on the next scheduled release isn’t safer. It’s just quieter, right up until it isn’t.

Why This Doesn’t Change the Plan for TrueNAS 26

TrueNAS 26 moving to an annual release cadence is about major releases, not patches. Point releases like 25.10.6 keep shipping on whatever cycle the CVE volume demands — the annual cadence buys engineering more runway to refine each major version, not a slower security response in between. If anything, six point releases in ten months is the model working as intended: a long testing window for the big release, a fast lane for everything urgent that shows up after.

Still Open, Still Free to Use

With so much else in flux – usage-based billing for AI credits, entire categories of physical media disappearing – TrueNAS is holding to its open-core business model: true data ownership and data sovereignty for everyone, funded by TrueNAS Enterprise appliances with production support behind them.

TrueNAS Connect, introduced alongside TrueNAS 25.10, gives power users a path to more capability at a nominal cost, and a way to help fund the software and the community around it. A free “Foundation” tier stays available for anyone still evaluating TrueNAS or working with a tight budget.

Download TrueNAS Community Edition to try it yourself. If you need TrueNAS Support backing validated Enterprise hardware, talk to our sales team about TrueNAS Enterprise.

FAQ

What’s fixed in TrueNAS 25.10.6?
A Linux kernel update to v6.12.99 resolving more than 250 upstream CVEs, an NVIDIA GPU driver update to the 580 branch, and TrueNAS-specific fixes for Fibre Channel target crashes, an NFS server hang, false SMART alerts, deduplication table pruning, a stuck directory services Save button, ALUA changes during HA failover, failover speed, and audit log parsing.

Is TrueNAS 25.10 ready for mission-critical workloads?
Yes. It’s the most widely deployed TrueNAS release to date, and six point releases of production-sourced fixes since October 2025 – including this release’s HA failover speed and ALUA fixes – are exactly why it’s our recommended version for Enterprise appliances.

How often does TrueNAS patch security vulnerabilities?
Roughly every six to eight weeks on a normal cycle. 25.10.5 to 25.10.6 shipped in 19 days, because AI-assisted vulnerability research doesn’t wait for a normal cycle.

What changes with TrueNAS 26’s annual release cadence?
Major releases move from twice a year to once a year, giving engineering more time to refine each one. Point releases – the kind fixing CVEs – keep shipping on whatever schedule the threat landscape requires.

Share On Social: