7.3 Errata
Patches for the OpenBSD base system are distributed as unified diffs. Each patch is cryptographically signed with the signify(1) tool and contains usage instructions. All the following patches are also available in one tar.gz file for convenience.
Alternatively, the syspatch(8) utility can be used to apply binary updates on the following architectures: amd64, i386, arm64.
Patches for supported releases are also incorporated into the -stable branch.
-
001: RELIABILITY FIX: May 3, 2023
All architectures
A new ASPA object appeared in the RPKI ecosystem and exposed bugs in bgpd(8) and rpki-client(8).
A source code patch exists which remedies this problem. -
002: RELIABILITY FIX: May 16, 2023
All architectures
Avoid fatal errors in bgpd(8) due to incorrect refcounting and mishandling of ASPA objects. Fix bgpctl(8) 'show rib in' by renaming 'invalid' into 'disqualified'.
A source code patch exists which remedies this problem. -
003: RELIABILITY FIX: May 26, 2023
All architectures
IP address inheritance was handled incorrectly in rpki-client(8).
A source code patch exists which remedies this problem. -
004: SECURITY FIX: May 26, 2023
All architectures
A double free or use after free could occur after SSL_clear(3).
A source code patch exists which remedies this problem. -
005: SECURITY FIX: June 15, 2023
All architectures
libX11 CVE-2023-3138 Missing checks in XQueryExtension() return values.
A source code patch exists which remedies this problem. -
006: RELIABILITY FIX: July 12, 2023
All architectures
Incorrect length handling of path attributes in bgpd(8) can lead to a session reset.
A source code patch exists which remedies this problem. -
007: RELIABILITY FIX: July 12, 2023
All architectures
A malformed HTTP request can crash httpd(8), if fastcgi is in use.
A source code patch exists which remedies this problem. -
008: RELIABILITY FIX: July 12, 2023
All architectures
Incomplete validation of ELF headers in execve(2).
A source code patch exists which remedies this problem. -
009: RELIABILITY FIX: July 12, 2023
All architectures
When tracking nexthops over IPv6 multipath routes, or when receiving a NOTIFICATION while reaching an internal limit, bgpd(8) could crash.
A source code patch exists which remedies this problem. -
010: SECURITY FIX: July 19, 2023
All architectures
In ssh-agent(1)'s PKCS#11 provider support, remote execution was possible due to controllable access in low-quality libraries. In addition to fixing this, the ability to remotely load PKCS#11 libraries is now disabled by default (re-enable with '-Oallow-remote-pkcs11').
A source code patch exists which remedies this problem. -
011: SECURITY FIX: July 24, 2023
amd64 i386
Workaround for Zenbleed AMD cpu problem. For i386 and amd64 platforms.
A source code patch exists which remedies this problem. -
012: SECURITY FIX: July 24, 2023
amd64 i386
Add firmware for AMD cpus, to repair past or potential future bugs. For i386 and amd64 platforms.After this step, "fw_update" and "installboot" must be run.
A source code patch exists which remedies this problem. -
013: SECURITY FIX: July 24, 2023
amd64 i386
Install firmware updates for AMD cpus, to repair past or potential future bugs. For i386 and amd64 platforms.
A source code patch exists which remedies this problem. -
014: RELIABILITY FIX: July 24, 2023
All architectures
Missing bounds check in console terminal emulation could cause a kernel crash after receiving specially crafted escape sequences.
A source code patch exists which remedies this problem. -
015: RELIABILITY FIX: July 25, 2023
amd64 i386
Some hypervisors remain unpatched for writes to Zenbleed DE_CFG bit, so skip it.
A source code patch exists which remedies this problem. -
016: SECURITY FIX: September 21, 2023
All architectures
npppd(8) could crash by a l2tp message which has an AVP with wrong length.
A source code patch exists which remedies this problem. -
017: SECURITY FIX: October 3, 2023
All architectures
Fix several input validation errors in libX11 and libXpm. CVE-2023-43785 CVE-2023-43786 CVE-2023-43787 CVE-2023-43788 CVE-2023-43789
A source code patch exists which remedies this problem. -
018: SECURITY FIX: October 25, 2023
All architectures
Fix several input validation errors in the X server. CVE-2023-5367 CVE-2023-5380 CVE-2023-5574
A source code patch exists which remedies this problem. -
019: SECURITY FIX: October 25, 2023
All architectures
A network buffer that had to be split at certain length could crash the kernel.
A source code patch exists which remedies this problem. -
020: RELIABILITY FIX: November 21, 2023
All architectures
httpd(8): Avoid a NULL dereference when handling a malformed fastcgi request.
A source code patch exists which remedies this problem. -
021: SECURITY FIX: November 29, 2023
All architectures
A crafted regular expression when compiled by perl can cause a one-byte attacker controlled buffer overflow in a heap allocated buffer. CVE-2023-47038
A source code patch exists which remedies this problem. -
022: RELIABILITY FIX: December 10, 2023
amd64
vmm(4) restored stale GDTR & TR values on vm exit which could lead to memory corruption or kernel deadlocks.
A source code patch exists which remedies this problem. -
023: SECURITY FIX: December 14, 2023
All architectures
Fix out of bounds memory accesses in XRandR and XKB X server extensions. CVE-2023-6377 CVE-2023-6478
A source code patch exists which remedies this problem. -
024: SECURITY FIX: December 18, 2023
All architectures
An SSH protocol weakness (the Terrapin Attack) exists that allows an on-path adversary to disable keystroke timing obfuscation.
A source code patch exists which remedies this problem. -
025: SECURITY FIX: January 16, 2024
All architectures
Fix multiple xserver heap buffer overflows, out of bounds memory accesses and memory corruption. CVE-2023-6816 CVE-2024-0229 CVE-2024-21885 CVE-2024-21886 CVE-2024-0408 CVE-2024-0409
A source code patch exists which remedies this problem. -
026: SECURITY FIX: February 13, 2024
All architectures
DNSSEC protocol vulnerabilities have been discovered that render various DNSSEC validators victims of Denial Of Service while trying to validate specially crafted DNSSEC responses. Fix CVE-2023-50387 and CVE-2023-50868 in unwind(8) and unbound(8).
A source code patch exists which remedies this problem. -
027: SECURITY FIX: March 18, 2024
All architectures
In libexpat fix billion laughs attack vulnerability CVE-2024-28757.
A source code patch exists which remedies this problem. -
028: SECURITY FIX: April 8, 2024
All architectures
Fix multiple heap buffer overread and data leakage in the X11 server Xi extension and use after free in the Render extension. CVE-2024-31080 CVE-2024-31081 CVE-2024-31083
A source code patch exists which remedies this problem.