7.2 Errata
Patches for the OpenBSD base system are distributed as unified diffs. Each patch is cryptographically signed with the signify(1) tool and contains usage instructions. All the following patches are also available in one tar.gz file for convenience.
Alternatively, the syspatch(8) utility can be used to apply binary updates on the following architectures: amd64, i386, arm64.
Patches for supported releases are also incorporated into the -stable branch.
-
001: SECURITY FIX: October 24, 2022
All architectures
Custom verification callbacks could cause the X.509 verifier to fail to store errors resulting from leaf certificate verification.
A source code patch exists which remedies this problem. -
002: RELIABILITY FIX: October 24, 2022
All architectures
Unbreak ASN.1 indefinite length encoding.
A source code patch exists which remedies this problem. -
003: RELIABILITY FIX: October 27, 2022
All architectures
Restore operation of Apple-specific Fn-key keyboard sequences.
A source code patch exists which remedies this problem. -
004: SECURITY FIX: November 1, 2022
All architectures
In libexpat fix heap use-after-free vulnerability CVE-2022-43680.
A source code patch exists which remedies this problem. -
005: SECURITY FIX: November 14, 2022
All architectures
CVE-2022-44638: An integer overflow in pixman may lead to an out-of-bounds write.
A source code patch exists which remedies this problem. -
006: RELIABILITY FIX: November 26, 2022
amd64
Incorrect reference counting and locking caused a vmm(4) performance regression.
A source code patch exists which remedies this problem. -
007: SECURITY FIX: November 26, 2022
All architectures
A crafted TCP query from localhost could crash the unwind(8) daemon.
A source code patch exists which remedies this problem. -
008: RELIABILITY FIX: November 26, 2022
All architectures
Fix a assertion crash during pfsync state update.
A source code patch exists which remedies this problem. -
009: SECURITY FIX: December 14, 2022
All architectures
In X11 server fix local privileges elevation and remote code execution for ssh X forwarding sessions. This addresses CVE-2022-46340 CVE-2022-46341 CVE-2022-46342 CVE-2022-46343 CVE-2022-46344.
A source code patch exists which remedies this problem. -
010: RELIABILITY FIX: December 14, 2022
amd64
Fix booting vmd(8) guests from ramdisk with more than 4g of memory.
A source code patch exists which remedies this problem. -
011: RELIABILITY FIX: December 14, 2022
amd64 i386
TLB entries were not invalidated for all types of engine on 12th generation Intel graphics (Tiger Lake, Rocket Lake, Alder Lake).
A source code patch exists which remedies this problem. -
012: RELIABILITY FIX: December 16, 2022
All architectures
Removing a domain can result in an out-of-bounds write in acme-client(8).
A source code patch exists which remedies this problem. -
013: SECURITY FIX: January 13, 2023
All architectures
A TCP packet with destination port 0 that matches a pf divert-to rule could crash the kernel.
A source code patch exists which remedies this problem. -
014: SECURITY FIX: January 17, 2023
All architectures
Input validation issues and path validation issues in libXpm can lead to infinite loops, memory corruption or arbitrary command execution. CVE-2022-46285, CVE-2022-44617 and CVE-2022-4883
A source code patch exists which remedies this problem. -
015: SECURITY FIX: January 21, 2023
amd64
vmm(4) exposed unsupported cpuid feature flags to guests.
A source code patch exists which remedies this problem. -
016: SECURITY FIX: January 21, 2023
amd64
vmd(8) exposed unsupported cpuid feature flags to guests.
A source code patch exists which remedies this problem. -
017: SECURITY FIX: February 2, 2023
All architectures
A double-free in the sshd pre-auth unprivileged process (not believed to be exploitable).
A source code patch exists which remedies this problem. -
018: SECURITY FIX: February 7, 2023
All architectures
A malicious certificate revocation list or timestamp response token would allow an attacker to read arbitrary memory.
A source code patch exists which remedies this problem. -
019: SECURITY FIX: February 7, 2023
All architectures
CVE-2023-0494: use after free in the Xinput X server extension.
A source code patch exists which remedies this problem. -
020: SECURITY FIX: February 7, 2023
All architectures
smtpd(8) could abort due to a connection from a local, scoped ipv6 address.
A source code patch exists which remedies this problem. -
021: RELIABILITY FIX: February 26, 2023
All architectures
Missing bounds check in console terminal emulation could cause a kernel crash after receiving specially crafted escape sequences.
A source code patch exists which remedies this problem. -
022: SECURITY FIX: March 16, 2023
All architectures
Out of bounds accesses in libc resolver.
A source code patch exists which remedies this problem. -
023: RELIABILITY FIX: March 23, 2023
All architectures
Incorrect length checks allow an out-of-bounds read in bgpd(8).
A source code patch exists which remedies this problem. -
024: SECURITY FIX: March 29, 2023
All architectures
Xserver, CVE-2023-1393: use after free bug in the Composite server extension.
A source code patch exists which remedies this problem. -
025: RELIABILITY FIX: May 26, 2023
All architectures
IP address inheritance was handled incorrectly in rpki-client(8).
A source code patch exists which remedies this problem. -
026: SECURITY FIX: May 26, 2023
All architectures
A double free or use after free could occur after SSL_clear(3).
A source code patch exists which remedies this problem. -
027: SECURITY FIX: June 15, 2023
All architectures
libX11 CVE-2023-3138 Missing checks in XQueryExtension() return values.
A source code patch exists which remedies this problem. -
028: RELIABILITY FIX: July 12, 2023
All architectures
Incorrect length handling of path attributes in bgpd(8) can lead to a session reset.
A source code patch exists which remedies this problem. -
029: RELIABILITY FIX: July 12, 2023
All architectures
A malformed HTTP request can crash httpd(8), if fastcgi is in use.
A source code patch exists which remedies this problem. -
030: RELIABILITY FIX: July 12, 2023
All architectures
Incomplete validation of ELF headers in execve(2).
A source code patch exists which remedies this problem. -
031: RELIABILITY FIX: July 12, 2023
All architectures
When tracking nexthops over IPv6 multipath routes, or when receiving a NOTIFICATION while reaching an internal limit, bgpd(8) could crash.
A source code patch exists which remedies this problem. -
032: SECURITY FIX: July 19, 2023
All architectures
In ssh-agent(1)'s PKCS#11 provider support, remote execution was possible due to controllable access in low-quality libraries. In addition to fixing this, the ability to remotely load PKCS#11 libraries is now disabled by default (re-enable with '-Oallow-remote-pkcs11').
A source code patch exists which remedies this problem. -
033: SECURITY FIX: July 24, 2023
amd64 i386
Workaround for Zenbleed AMD cpu problem. For i386 and amd64 platforms.
A source code patch exists which remedies this problem. -
034: SECURITY FIX: July 24, 2023
amd64 i386
Add firmware for AMD cpus, to repair past or potential future bugs. For i386 and amd64 platforms.After this step, "fw_update" and "installboot" must be run.
A source code patch exists which remedies this problem. -
035: SECURITY FIX: July 24, 2023
amd64 i386
Install firmware updates for AMD cpus, to repair past or potential future bugs. For i386 and amd64 platforms.
A source code patch exists which remedies this problem. -
036: RELIABILITY FIX: July 24, 2023
All architectures
Missing bounds check in console terminal emulation could cause a kernel crash after receiving specially crafted escape sequences.
A source code patch exists which remedies this problem. -
037: RELIABILITY FIX: July 25, 2023
amd64 i386
Some hypervisors remain unpatched for writes to Zenbleed DE_CFG bit, so skip it.
A source code patch exists which remedies this problem. -
038: SECURITY FIX: September 21, 2023
All architectures
npppd(8) could crash by a l2tp message which has an AVP with wrong length.
A source code patch exists which remedies this problem. -
039: SECURITY FIX: October 3, 2023
All architectures
Fix several input validation errors in libX11 and libXpm. CVE-2023-43785 CVE-2023-43786 CVE-2023-43787 CVE-2023-43788 CVE-2023-43789
A source code patch exists which remedies this problem.