https://man.openbsd.org/syspatch
On Wed, Sep 30, 2026 at 8:25 AM Kapetanakis Giannis <[email protected]> wrote: > > Hi, > > We rely on nsd and unbound from base for our DNS infrastructure, so I'd like > to understand how updates to them are handled for -stable. > > Errata 022 for 7.9 updates nsd to 4.15.2, from 4.14.2 as shipped with 7.9, if > I read it correctly. > Upstream, in the meantime, there were: > > - NSD 4.14.3 security release (Jun 25) > - NSD 4.15.0 release (Jul 7) > - NSD 4.15.1 security release (Aug 26) > - NSD 4.15.2 release (Sep 2) > > I'm asking because OpenBSD usually gets security fixes out very quickly, so > the gap here surprised me. > > I'm not complaining or demanding anything, I'd just like to understand the > process: how does the project decide when nsd/unbound security releases > become an errata, and what led to doing it now rather than with 4.14.3 or > 4.15.1? > Or was it something in 4.15.2, rather than the earlier CVEs, that triggered > it? > > Knowing this would help us plan (e.g. whether to track upstream ourselves for > these daemons). > > regards, > > Giannis > > ps: Stuart, none of this is aimed at you. My question is about the process, > not the people doing the work. Much respect for everything you do for > OpenBSD, not only nsd and unbound. > > >

