<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>syspatch.se – OpenBSD errata</title>
<link href="https://syspatch.se/"/><link rel="self" href="https://syspatch.se/atom.xml"/>
<id>https://syspatch.se/</id>
<updated>2026-09-30T00:00:00Z</updated>
<entry><title>OpenBSD 7.9 errata 030: uidrange</title><link href="https://syspatch.se/7.9/030_uidrange.html"/><id>https://syspatch.se/7.9/030_uidrange.html</id><updated>2026-09-30T00:00:00Z</updated><summary>Incorrect upper bound for uid and gid can result in -1 being used.</summary></entry>
<entry><title>OpenBSD 7.9 errata 029: sysvsem</title><link href="https://syspatch.se/7.9/029_sysvsem.html"/><id>https://syspatch.se/7.9/029_sysvsem.html</id><updated>2026-09-30T00:00:00Z</updated><summary>Semaphore operation semop(2) could trigger a use-after-free in the
kernel.</summary></entry>
<entry><title>OpenBSD 7.9 errata 028: wgbind</title><link href="https://syspatch.se/7.9/028_wgbind.html"/><id>https://syspatch.se/7.9/028_wgbind.html</id><updated>2026-09-30T00:00:00Z</updated><summary>After wg(4) interface destruction a use-after-free coould be triggered
by incoming packets.</summary></entry>
<entry><title>OpenBSD 7.9 errata 027: iked</title><link href="https://syspatch.se/7.9/027_iked.html"/><id>https://syspatch.se/7.9/027_iked.html</id><updated>2026-09-30T00:00:00Z</updated><summary>A malicious IKEv2 peer could crash iked(8), or cause a certificate
validation verdict to be applied to the wrong peer identity.</summary></entry>
<entry><title>OpenBSD 7.9 errata 026: sysvipc</title><link href="https://syspatch.se/7.9/026_sysvipc.html"/><id>https://syspatch.se/7.9/026_sysvipc.html</id><updated>2026-09-30T00:00:00Z</updated><summary>A reference counting bug could lead to use-after-free in the kernel.</summary></entry>
<entry><title>OpenBSD 7.9 errata 025: procargs</title><link href="https://syspatch.se/7.9/025_procargs.html"/><id>https://syspatch.se/7.9/025_procargs.html</id><updated>2026-09-30T00:00:00Z</updated><summary>An errant process could cause ps(1) to crash due to a buffer overflow
in sysctl(2).</summary></entry>
<entry><title>OpenBSD 7.9 errata 024: libressl</title><link href="https://syspatch.se/7.9/024_libressl.html"/><id>https://syspatch.se/7.9/024_libressl.html</id><updated>2026-09-30T00:00:00Z</updated><summary>Fix a variety of bugs in libressl:
- Remove RelativeDistinguishedName support for CRL distribution points
- Ensure verify callbacks always returning 1 can see a hostname mismatch
- Correct botched size check in dtls1_preprocess_fragment()
- Limit size of buffered DTLS handshake messages
- Avoid potential overread on interrupted retransmission in DTLS
- Fix OCSP responder authorization bypass in libtls and ocspcheck(8)</summary></entry>
<entry><title>OpenBSD 7.9 errata 023: unbound</title><link href="https://syspatch.se/7.9/023_unbound.html"/><id>https://syspatch.se/7.9/023_unbound.html</id><updated>2026-09-30T00:00:00Z</updated><summary>Update unbound(8) to version 1.26.1.
CVE-2026-14586 CVE-2026-32665 CVE-2026-32792 CVE-2026-33278
CVE-2026-40622 CVE-2026-40691 CVE-2026-41292 CVE-2026-41637
CVE-2026-42534 CVE-2026-42923 CVE-2026-42944 CVE-2026-42955
CVE-2026-42959 CVE-2026-42960 CVE-2026-44390 CVE-2026-44608
CVE-2026-44621 CVE-2026-44687 CVE-2026-44690 CVE-2026-46582
CVE-2026-50045 CVE-2026-50046 CVE-2026-50243 CVE-2026-50248
CVE-2026-50251 CVE-2026-50252 CVE-2026-52863 CVE-2026-54478
CVE-2026-55708 CVE-2026-55717 CVE-2026-55973 CVE-2026-55990
CVE-2026-55991 CVE-2026-56416 CVE-2026-56444</summary></entry>
<entry><title>OpenBSD 7.9 errata 022: nsd</title><link href="https://syspatch.se/7.9/022_nsd.html"/><id>https://syspatch.se/7.9/022_nsd.html</id><updated>2026-09-30T00:00:00Z</updated><summary>Update nsd(8) to version 4.15.2.
CVE-2026-12244 CVE-2026-12245 CVE-2026-12246 CVE-2026-12490
CVE-2026-18664 CVE-2026-18916 CVE-2026-19401 CVE-2026-19538</summary></entry>
<entry><title>OpenBSD 7.9 errata 021: ldapd</title><link href="https://syspatch.se/7.9/021_ldapd.html"/><id>https://syspatch.se/7.9/021_ldapd.html</id><updated>2026-09-14T00:00:00Z</updated><summary>In ldapd(8), an authentication result from one transaction could be
applied to another.</summary></entry>
<entry><title>OpenBSD 7.9 errata 020: xserver</title><link href="https://syspatch.se/7.9/020_xserver.html"/><id>https://syspatch.se/7.9/020_xserver.html</id><updated>2026-09-14T00:00:00Z</updated><summary>Multiple vulnerabilities in the X server and server side font library.
CVE-2026-55999 CVE-2026-56000 CVE-2026-56001 CVE-2026-56002
CVE-2026-56003</summary></entry>
<entry><title>OpenBSD 7.9 errata 019: expat</title><link href="https://syspatch.se/7.9/019_expat.html"/><id>https://syspatch.se/7.9/019_expat.html</id><updated>2026-09-14T00:00:00Z</updated><summary>Backport all changes from libexpat 2.8.4.
CVE-2026-66046 CVE-2026-76641 CVE-2026-76957</summary></entry>
<entry><title>OpenBSD 7.9 errata 018: shmat</title><link href="https://syspatch.se/7.9/018_shmat.html"/><id>https://syspatch.se/7.9/018_shmat.html</id><updated>2026-09-14T00:00:00Z</updated><summary>Prevent integer overflow in shmat(4).</summary></entry>
<entry><title>OpenBSD 7.9 errata 017: wscons</title><link href="https://syspatch.se/7.9/017_wscons.html"/><id>https://syspatch.se/7.9/017_wscons.html</id><updated>2026-09-14T00:00:00Z</updated><summary>Prevent integer overflow in wscons(4).</summary></entry>
<entry><title>OpenBSD 7.9 errata 016: nfs</title><link href="https://syspatch.se/7.9/016_nfs.html"/><id>https://syspatch.se/7.9/016_nfs.html</id><updated>2026-09-14T00:00:00Z</updated><summary>A malicous NFS server could aid a local user in avoiding access
controls.</summary></entry>
<entry><title>OpenBSD 7.9 errata 015: smtpd</title><link href="https://syspatch.se/7.9/015_smtpd.html"/><id>https://syspatch.se/7.9/015_smtpd.html</id><updated>2026-09-14T00:00:00Z</updated><summary>In smtpd(8) a custom MDA could execute arbitrary code as an
unprivileged recipient user.</summary></entry>
<entry><title>OpenBSD 7.9 errata 014: expat</title><link href="https://syspatch.se/7.9/014_expat.html"/><id>https://syspatch.se/7.9/014_expat.html</id><updated>2026-08-22T00:00:00Z</updated><summary>Backport all changes from libexpat 2.8.3.
CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132
CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406
CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410
CVE-2026-56411 CVE-2026-56412 CVE-2026-72522</summary></entry>
<entry><title>OpenBSD 7.9 errata 013: ttyioctl</title><link href="https://syspatch.se/7.9/013_ttyioctl.html"/><id>https://syspatch.se/7.9/013_ttyioctl.html</id><updated>2026-08-22T00:00:00Z</updated><summary>TIOCGSID on tty(4) could trigger a kernel panic.</summary></entry>
<entry><title>OpenBSD 7.9 errata 012: kernproc</title><link href="https://syspatch.se/7.9/012_kernproc.html"/><id>https://syspatch.se/7.9/012_kernproc.html</id><updated>2026-08-22T00:00:00Z</updated><summary>The sysctl(2) kern.proc could leak kernel memory.</summary></entry>
<entry><title>OpenBSD 7.9 errata 011: nipledge</title><link href="https://syspatch.se/7.9/011_nipledge.html"/><id>https://syspatch.se/7.9/011_nipledge.html</id><updated>2026-08-22T00:00:00Z</updated><summary>A race in pledge(2) namei check could trigger a kernel panic.</summary></entry>
<entry><title>OpenBSD 7.9 errata 010: ifioctl</title><link href="https://syspatch.se/7.9/010_ifioctl.html"/><id>https://syspatch.se/7.9/010_ifioctl.html</id><updated>2026-08-22T00:00:00Z</updated><summary>Interface ioctl(4) could leak 4 bytes of kernel memory.</summary></entry>
<entry><title>OpenBSD 7.9 errata 009: iked</title><link href="https://syspatch.se/7.9/009_iked.html"/><id>https://syspatch.se/7.9/009_iked.html</id><updated>2026-08-11T00:00:00Z</updated><summary>iked(8) could be crashed remotely pre authentication.</summary></entry>
<entry><title>OpenBSD 7.9 errata 008: npppd</title><link href="https://syspatch.se/7.9/008_npppd.html"/><id>https://syspatch.se/7.9/008_npppd.html</id><updated>2026-08-11T00:00:00Z</updated><summary>Heap or stack corruption in npppd(8) LCP option handling could lead
to crashes.</summary></entry>
<entry><title>OpenBSD 7.9 errata 007: ipsec</title><link href="https://syspatch.se/7.9/007_ipsec.html"/><id>https://syspatch.se/7.9/007_ipsec.html</id><updated>2026-07-16T00:00:00Z</updated><summary>Stricter IPsec and IPComp input validation prevents kernel crash.</summary></entry>
<entry><title>OpenBSD 7.9 errata 006: nfs</title><link href="https://syspatch.se/7.9/006_nfs.html"/><id>https://syspatch.se/7.9/006_nfs.html</id><updated>2026-07-16T00:00:00Z</updated><summary>Fix double-free, memory leaks, and vnode references in NFS server.</summary></entry>
<entry><title>OpenBSD 7.9 errata 005: sysv</title><link href="https://syspatch.se/7.9/005_sysv.html"/><id>https://syspatch.se/7.9/005_sysv.html</id><updated>2026-07-16T00:00:00Z</updated><summary>Fix numerous problems in the System V (sem, msg, ipc) system call
layers.</summary></entry>
<entry><title>OpenBSD 7.9 errata 004: elf</title><link href="https://syspatch.se/7.9/004_elf.html"/><id>https://syspatch.se/7.9/004_elf.html</id><updated>2026-07-16T00:00:00Z</updated><summary>Fix some info leaks, kernel crashes, and pinsyscall(8) / kbind(8)
locking failures.</summary></entry>
<entry><title>OpenBSD 7.9 errata 003: vmd</title><link href="https://syspatch.se/7.9/003_vmd.html"/><id>https://syspatch.se/7.9/003_vmd.html</id><updated>2026-06-02T00:00:00Z</updated><summary>In vmd(8), fix a variety of crashing bugs and misbehavior of -b flag.</summary></entry>
<entry><title>OpenBSD 7.9 errata 002: smtpd</title><link href="https://syspatch.se/7.9/002_smtpd.html"/><id>https://syspatch.se/7.9/002_smtpd.html</id><updated>2026-06-02T00:00:00Z</updated><summary>Fixes for a variety of crashing bugs in smtpd(8).</summary></entry>
<entry><title>OpenBSD 7.9 errata 001: xserver</title><link href="https://syspatch.se/7.9/001_xserver.html"/><id>https://syspatch.se/7.9/001_xserver.html</id><updated>2026-06-02T00:00:00Z</updated><summary>Multiple vulnerabilites in the X server dri2, sync, saver and Xkb
extensions.</summary></entry>
</feed>
