OpenBSD Errata: June 12th, 2017 (wsmux)

2017-06-12 Thread T.J. Townsend
Errata patches for wsmux have been released for OpenBSD 6.1 and 6.0. An unprivileged console user can cause a kernel crash. Binary updates for the amd64 and i386 platforms are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: May 2nd, 2017

2017-05-02 Thread T.J. Townsend
Errata patches for dhcpd, vmm, LibreSSL and softraid have been released for OpenBSD 6.1 today. Details can be found on this page: https://www.openbsd.org/errata61.html Binary updates for the amd64 and i386 platforms are also available via the syspatch utility. Note that syspatch uses the mirror

OpenBSD Errata: May 8th, 2017 (libssl)

2017-05-08 Thread T.J. Townsend
Errata patches for libssl have been released for OpenBSD 6.1 and 6.0. Incorrect DTLS cookie handling can result in a NULL pointer dereference. Binary updates for the amd64 and i386 platforms are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: October 13th, 2017 (tcb_invalid)

2017-10-13 Thread T.J. Townsend
Errata patches have been released for OpenBSD 6.2 and 6.1. A local user could trigger a kernel panic by using an invalid TCB value. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: September 28th, 2017 (tcb)

2017-09-28 Thread T.J. Townsend
Errata patches have been released for OpenBSD 6.1 and 6.0. Out of bounds TCB settings may result in a kernel panic. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: October 4th, 2017 (xrstor_resume)

2017-10-04 Thread T.J. Townsend
Errata patches have been released for OpenBSD 6.1 and 6.0. A kernel executable address was leaked to userland. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata pages: https://www.openbsd.org/errata60.html

OpenBSD Errata: December 10th, 2017 (mpls)

2017-12-10 Thread T.J. Townsend
Errata patches have been released for OpenBSD 6.2 and 6.1. A number of bugs were discovered in the MPLS stack that can be used to remotely trigger kernel crashes. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on

OpenBSD Errata: December 1st, 2017 (fktrace)

2017-12-01 Thread T.J. Townsend
An errata patch has been released for OpenBSD 6.2. The fktrace(2) system call had insufficient security checks. This update disables fktrace(2) entirely. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the

OpenBSD Errata: May 8th, 2018 (ipseclen)

2018-05-08 Thread T.J. Townsend
Errata patches for IPsec have been released for OpenBSD 6.3 and 6.2. Incorrect handling of fragmented IPsec packets could result in a system crash. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: June 17th, 2018 (intelfpu)

2018-06-17 Thread T.J. Townsend
Errata patches for x86 floating-point units have been released for OpenBSD 6.3. Intel CPUs speculatively access FPU registers even when the FPU is disabled, so data (including AES keys) from previous contexts could be discovered if using the lazy-save approach. Binary updates for the amd64

OpenBSD Errata: January 14th, 2018 (libssl)

2018-01-14 Thread T.J. Townsend
Errata patches for libssl have been released for OpenBSD 6.2. An incorrect TLS extensions block is generated when no extensions are present, which can result in handshake failures. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches

OpenBSD Errata: July 31st, 2018 (ioport)

2018-07-30 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.2. IO port permissions were incorrectly restricted. Binary updates for the i386 platform are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: August 4th, 2018 (fpuinit)

2018-08-06 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.2. Incorrect initialization of the FPU caused floating point exceptions when running on Xen. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: August 24th, 2018 (vmml1tf)

2018-08-23 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.2. The Intel L1TF bug allows a vmm guest to read host memory. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: August 24th, 2018 (fpufork)

2018-08-23 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.2. State from the FPU of one userland process could be exposed to other processes. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: July 25th, 2018 (ipsecexpire)

2018-07-24 Thread T.J. Townsend
Errata patches for IPsec have been released for OpenBSD 6.3 and 6.2. When an IPsec key expired, the kernel could panic due to unfinished timeout tasks. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the

OpenBSD Errata: July 25th, 2018 (execsize)

2018-07-24 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.2. A regular user could trigger a system crash by executing an invalid ELF binary. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the

OpenBSD Errata: March 1st, 2018 (meltdown)

2018-02-28 Thread T.J. Townsend
Errata patches for a speculative execution flaw in Intel CPUs have been released for OpenBSD 6.2 and 6.1. Intel CPUs contain a flaw called "Meltdown" which allows userspace programs to access kernel memory. Binary updates for the amd64 platform are available via the syspatch utility. Source code

OpenBSD Errata: April 21st, 2018 (gif)

2018-04-21 Thread T.J. Townsend
Errata patches for the generic tunnel interface driver have been released for OpenBSD 6.3. In the gif(4) interface, use the specified protocol for IPv6, plug an mbuf leak, and avoid a use after free. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility.

OpenBSD Errata: April 21st, 2018 (arp)

2018-04-21 Thread T.J. Townsend
Errata patches for the kernel's Address Resolution Protocol implementation have been released for OpenBSD 6.3. ARP replies could be sent on the wrong member of a bridge(4) interface. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code

OpenBSD Errata: April 21st, 2018 (libtls)

2018-04-21 Thread T.J. Townsend
Errata patches for libtls have been released for OpenBSD 6.3. Additional data is inadvertently removed when private keys are cleared from TLS configuration, which can prevent OCSP from functioning correctly. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch

OpenBSD Errata: April 21st, 2018 (httpd)

2018-04-21 Thread T.J. Townsend
Errata patches for httpd have been released for OpenBSD 6.2 and 6.3. httpd can leak file descriptors when servicing range requests. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: March 20th, 2018 (ipsec)

2018-03-19 Thread T.J. Townsend
Errata patches for IPsec have been released for OpenBSD 6.2 and 6.1. The IPsec AH header could be longer than the network packet, resulting in a kernel crash. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the

OpenBSD Errata: October 25th, 2018 (xserver)

2018-10-25 Thread T.J. Townsend
Errata patches for Xorg have been released for OpenBSD 6.3 and 6.4. The Xorg X server incorrectly validates certain options, allowing arbitrary files to be overwritten. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be

OpenBSD Errata: September 21st, 2018 (ldtr)

2018-09-20 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.2. On AMD CPUs, LDTR must be managed crossing between VMs. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata pages:

OpenBSD Errata: December 20th, 2018 (recvwait)

2018-12-18 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.4. While recv(2) with the MSG_WAITALL flag was receiving control messages from a socket, the kernel could panic. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code

OpenBSD Errata: December 22nd, 2018 (pcbopts)

2018-12-20 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.4. The setsockopt(2) system call could overflow mbuf cluster kernel memory by 4 bytes. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the

OpenBSD Errata: November 29th, 2018 (qcow2)

2018-11-29 Thread T.J. Townsend
Errata patches for vmd have been released for OpenBSD 6.4. Writing more than 4GB to a qcow2 volume corrupts the virtual disk. Binary updates for the amd64 and i386 platforms are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: November 29th, 2018 (uipc)

2018-11-29 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.4. UNIX domain sockets leak kernel memory with MSG_PEEK on SCM_RIGHTS, or can attempt excessive memory allocations leading to a crash. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch

OpenBSD Errata: November 29th, 2018 (smtpd)

2018-11-29 Thread T.J. Townsend
Errata patches for OpenSMTPD have been released for OpenBSD 6.4. The mail.mda and mail.lmtp delivery agents were not reporting temporary failures correctly, causing smtpd to bounce messages in some cases where it should have retried them. Binary updates for the amd64, i386, and arm64 platforms

OpenBSD Errata: November 29th, 2018 (perl)

2018-11-29 Thread T.J. Townsend
Errata patches for perl have been released for OpenBSD 6.3 and 6.4. Various overflows exist in perl. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: November 17th, 2018 (blinding)

2018-11-17 Thread T.J. Townsend
Errata patches for libcrypto have been released for OpenBSD 6.3. Timing side channels may leak information about DSA and ECDSA private keys. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: November 17th, 2018 (portsmash)

2018-11-17 Thread T.J. Townsend
Errata patches for libcrypto have been released for OpenBSD 6.4. The portsmash vulnerability allows exfiltration of elliptic curve keys. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: November 17th, 2018 (lockf)

2018-11-17 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.4. A recent change to POSIX file locks could cause incorrect results during lock acquisition. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on

OpenBSD Errata: January 27th, 2019 (nfs)

2019-01-26 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.4. Missing length checks in the NFS server and client can lead to crashes and other errors. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on

OpenBSD Errata: January 27th, 2019 (mincore)

2019-01-26 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3 and 6.4. The mincore() system call can be used to observe memory access patterns of other processes. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found

OpenBSD Errata: January 27th, 2019 (unveil)

2019-01-26 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.4. The unveil() system call can leak memory. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: March 27th, 2019 (vmmints)

2019-03-26 Thread T.J. Townsend
Errata patches for vmm have been released for OpenBSD 6.3 and 6.4. GDT and IDT limits were improperly restored during VMM context switches. Binary updates for the amd64 and i386 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: March 1st, 2019 (pf6frag)

2019-02-28 Thread T.J. Townsend
Errata patches for pf have been released for OpenBSD 6.3 and 6.4. Fragmented IPv6 packets may be erroneously passed by pf or lead to a crash. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata

OpenBSD Errata: March 22nd, 2019 (pficmp)

2019-03-21 Thread T.J. Townsend
Errata patches for pf have been released for OpenBSD 6.3 and 6.4. A state in pf could pass ICMP packets to a destination IP address that did not match the state. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on

OpenBSD Errata: May 29th, 2019 (mds)

2019-05-28 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.4 and 6.5. Intel CPUs have a cross privilege side-channel attack. (MDS) Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: June 10th, 2019 (bgpd)

2019-06-09 Thread T.J. Townsend
Errata patches for OpenBGPD have been released for OpenBSD 6.5. Several issues were corrected in bgpd: "network" statements with no fixed prefix were incorrectly removed when configuration was reloaded, "export default-route" did not work, and "network 0.0.0.0/0" could not be used in some cases.

OpenBSD Errata: June 10th, 2019 (libssl)

2019-06-09 Thread T.J. Townsend
Errata patches for LibreSSL have been released for OpenBSD 6.5. TLS handshakes fail if a client supporting TLS 1.3 tries to connect to an OpenBSD server and sends a key share extension that does not include X25519. Binary updates for the amd64, i386, and arm64 platforms are available via the

OpenBSD Errata: May 16th, 2019 (srtp)

2019-05-16 Thread T.J. Townsend
Errata patches for LibreSSL have been released for OpenBSD 6.4 and 6.5. LibreSSL servers did not provide an SRTP profile, so DTLS negotiation failed. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: May 3rd, 2019 (rip6cksum)

2019-05-01 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.3, 6.4, and 6.5. If a userland program sets the IPv6 checksum offset on a raw socket, an incoming packet could crash the kernel. ospf6d is such a program. Binary updates for the amd64, i386, and arm64 platforms are available via the

OpenBSD Errata: August 2nd, 2019 (smtpd)

2019-08-02 Thread T.J. Townsend
Errata patches for OpenSMTPD have been released for OpenBSD 6.4 and 6.5. smtpd can crash on excessively large input, causing a denial of service. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: September 2nd, 2019 (resume)

2019-09-01 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.4 and 6.5. Resume forgot to restore MSR/PAT configuration. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: September 2nd, 2019 (frag6ecn)

2019-09-01 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.4 and 6.5. When processing ECN bits on incoming IPv6 fragments, the kernel could crash. Per default pf fragment reassemble prevents the crash. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch

OpenBSD Errata: September 14th, 2019 (expat)

2019-09-14 Thread T.J. Townsend
Errata patches for expat have been released for OpenBSD 6.4 and 6.5. Libexpat 2.2.6 was affected by the heap overflow CVE-2019-15903. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: August 9th, 2019 (swapgs)

2019-08-08 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.4 and 6.5. Intel CPUs have another cross privilege side-channel attack. (SWAPGS) Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: July 25th, 2019 (tcpsack)

2019-07-24 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.4 and 6.5. By creating long chains of TCP SACK holes, an attacker could possibly slow down the system temporarily. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches

OpenBSD Errata: October 3rd, 2019 (sysupgrade)

2019-10-02 Thread T.J. Townsend
Errata patches for sysupgrade have been released for OpenBSD 6.5. The sysupgrade utility can be used to upgrade the system to the next release or to a new snapshot. This errata adds sysupgrade to OpenBSD 6.5 to simplify the process of upgrading to 6.6 when it's released. Binary updates for the

OpenBSD Errata: October 31st, 2019 (bgpd)

2019-10-30 Thread T.J. Townsend
Errata patches for OpenBGPD have been released for OpenBSD 6.6. bgpd(8) can crash on nexthop changes or during startup in certain configurations. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: November 16th, 2019 (net80211)

2019-11-16 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.5 and 6.6. The kernel could crash due to a NULL pointer dereference in net80211. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: November 16th, 2019 (ifioctl)

2019-11-16 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.5 and 6.6. A regular user could change some network interface parameters due to missing checks in the ioctl(2) system call. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code

OpenBSD Errata: November 16th, 2019 (sysupgrade)

2019-11-16 Thread T.J. Townsend
Errata patches for sysupgrade have been released for OpenBSD 6.5 and 6.6. A new kernel may require newer firmware images when using sysupgrade. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: November 22nd, 2019 (mesa)

2019-11-21 Thread T.J. Townsend
Errata patches for Mesa have been released for OpenBSD 6.5 and 6.6. Shared memory regions used by some Mesa drivers had permissions which allowed others to access that memory. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can

OpenBSD Errata: November 22nd, 2019 (inteldrm)

2019-11-21 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.5 and 6.6. A local user could cause the system to hang by reading specific registers when Intel Gen8/Gen9 graphics hardware is in a low power state. A local user could perform writes to memory that should be blocked with Intel Gen9

OpenBSD Errata: December 8th, 2019 (suauth)

2019-12-08 Thread T.J. Townsend
Errata patches for su have been released for OpenBSD 6.5 and 6.6. A user can log in with a different user's login class. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: December 18th, 2019 (eret)

2019-12-17 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.5 and 6.6. ARM64 CPUs speculatively execute instructions after ERET. Binary updates for the arm64 platform are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: December 11th, 2019 (ldso)

2019-12-11 Thread T.J. Townsend
Errata patches for ld.so have been released for OpenBSD 6.5 and 6.6. ld.so may fail to remove the LD_LIBRARY_PATH environment variable for set-user-ID and set-group-ID executables in low memory conditions. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch

OpenBSD Errata: October 28th, 2019 (bpf)

2019-10-27 Thread T.J. Townsend
Errata patches for BPF have been released for OpenBSD 6.6. bpf(4) has a race condition during device removal. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: October 28th, 2019 (ber)

2019-10-27 Thread T.J. Townsend
Errata patches for libutil have been released for OpenBSD 6.6. Various third party applications may crash due to symbol collision. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: October 5th, 2019 (unbound)

2019-10-03 Thread T.J. Townsend
Errata patches for unbound have been released for OpenBSD 6.4 and 6.5. Specially crafted queries may crash unwind and unbound. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: October 5th, 2019 (dhcpd)

2019-10-03 Thread T.J. Townsend
Errata patches for dhcpd have been released for OpenBSD 6.4 and 6.5. dhcpd leaks 4 bytes of stack to the network. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: December 20th, 2019 (ripd)

2019-12-19 Thread T.J. Townsend
Errata patches for ripd have been released for OpenBSD 6.5 and 6.6. ripd(8) fails to validate authentication lengths. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: December 20th, 2019 (ftp)

2019-12-19 Thread T.J. Townsend
Errata patches for ftp have been released for OpenBSD 6.5 and 6.6. ftp(1) will follow remote redirects to local files. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: February 24th, 2020 (smtpd_envelope)

2020-02-24 Thread T.J. Townsend
Errata patches for OpenSMTPD have been released for OpenBSD 6.5 and 6.6. An out of bounds read in smtpd allows an attacker to inject arbitrary commands into the envelope file which are then executed as root. Separately, missing privilege revocation in smtpctl allows arbitrary commands to be run

OpenBSD Errata: January 30th, 2020 (smtpd_tls)

2020-01-28 Thread T.J. Townsend
Errata patches for OpenSMTPD have been released for OpenBSD 6.5 and 6.6. smtpd can crash on opportunistic TLS downgrade, causing a denial of service. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: January 30th, 2020 (smtpd_exec)

2020-01-28 Thread T.J. Townsend
Errata patches for OpenSMTPD have been released for OpenBSD 6.5 and 6.6. An incorrect check allows an attacker to trick mbox delivery into executing arbitrary commands as root and lmtp delivery into executing arbitrary commands as an unprivileged user. Binary updates for the amd64, i386, and

OpenBSD Errata: February 17th, 2020 (vmm_pvclock)

2020-02-16 Thread T.J. Townsend
Errata patches for vmm have been released for OpenBSD 6.6. A missing range check in the vmm pvclock allows a guest to write to host memory. Binary updates for the amd64 platform are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: January 17th, 2020 (inteldrmctx)

2020-01-15 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.5 and 6.6. Execution Unit state was not cleared on context switch with Intel Gen9 graphics hardware. Binary updates for the amd64 and i386 platforms are available via the syspatch utility. Source code patches can be found on the

OpenBSD Errata: March 13th, 2020 (sosplice)

2020-03-12 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.5 and 6.6. Local outbound UDP broadcast or multicast packets sent by a spliced socket can crash the kernel. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be

OpenBSD Errata: March 10th, 2020 (sysctl)

2020-03-10 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.5 and 6.6. Missing input validation in sysctl(2) can be used to crash the kernel. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: April 19th, 2020 (drm)

2020-04-17 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.5 and 6.6. There was an incorrect test for root in the DRM Linux compatiblity code. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: April 7th, 2020 (dhcpd)

2020-04-06 Thread T.J. Townsend
Errata patches for dhcpd have been released for OpenBSD 6.5 and 6.6. dhcpd could reference freed memory after releasing a lease with an unusually long uid. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the

OpenBSD Errata: May 22nd, 2020 (ssh)

2020-05-18 Thread T.J. Townsend
Errata patches for ssh-keygen have been released for OpenBSD 6.7. When attempting to download resident keys from a FIDO token that does not require a password/PIN, ssh-keygen would crash with a NULL dereference. Binary updates for the amd64, i386, and arm64 platforms are available via the

OpenBSD Errata: May 22nd, 2020 (rpki)

2020-05-18 Thread T.J. Townsend
Errata patches for rpki-client have been released for OpenBSD 6.7. rpki-client could hang because of an improper waitpid idiom for rsync processes. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: May 13th, 2020 (wscons)

2020-05-13 Thread T.J. Townsend
Errata patches for wscons have been released for OpenBSD 6.5, 6.6, and 6.7. An out-of-bounds index access in wscons(4) can cause a kernel crash. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

OpenBSD Errata: May 22nd, 2020 (unbound)

2020-05-20 Thread T.J. Townsend
Errata patches for unbound and unwind have been released for OpenBSD 6.6 and 6.7. Specially crafted queries may crash unbound and unwind. Both can be tricked into amplifying an incoming query. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source

OpenBSD Errata: May 22nd, 2020 (libssl)

2020-05-20 Thread T.J. Townsend
Errata patches for LibreSSL have been released for OpenBSD 6.7. A TLS client with peer verification disabled may crash when contacting a server that sends an empty certificate list. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code

OpenBSD Errata: September 5th, 2020 (amdgpu)

2020-09-03 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.6 and 6.7. A buffer overflow was discovered in an amdgpu ioctl. Binary updates for the amd64 and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: October 6th, 2020 (mmap)

2020-10-05 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.7. mmap can exhaust kernel memory for PROT_NONE MAP_SHARED mappings. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: August 25th, 2020 (xserverlen)

2020-08-25 Thread T.J. Townsend
Errata patches for Xorg have been released for OpenBSD 6.6 and 6.7. Various X server extensions had deficient input validation. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: August 25th, 2020 (xinitom)

2020-08-25 Thread T.J. Townsend
Errata patches for libX11 have been released for OpenBSD 6.6 and 6.7. An integer overflow in libX11 could lead to a double free. Additionally, fix a regression in ximcp. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be

OpenBSD Errata: August 18th, 2020 (libssl)

2020-08-17 Thread T.J. Townsend
Errata patches for LibreSSL have been released for OpenBSD 6.7. The previous errata patch 019 broke bidirectional SSL_shutdown. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: May 25th, 2020 (smtpd_sockaddr)

2020-05-24 Thread T.J. Townsend
Errata patches for OpenSMTPD have been released for OpenBSD 6.7. Incorrect use of getpeername(2) storage for outgoing IPv6 connections corrupts stack memory. The nature of the corruption and existing mitigations appear to make this difficult to effectively target. Binary updates for the amd64,

OpenBSD Errata: June 1st, 2020 (perl)

2020-06-01 Thread T.J. Townsend
Errata patches for Perl have been released for OpenBSD 6.6 and 6.7. Several problems in Perl's regular expression compiler could lead to corruption of the intermediate language state of a compiled regular expression. Binary updates for the amd64, i386, and arm64 platforms are available via the

OpenBSD Errata: October 29th, 2020 (bgpd)

2020-10-27 Thread T.J. Townsend
Errata patches for OpenBGPD have been released for OpenBSD 6.7 and 6.8. In bgpd, the roa-set parser could leak memory. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: July 16th, 2020 (tty)

2020-07-15 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.6 and 6.7. tty subsystem abuse can impact performance badly. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: July 22nd, 2020 (tty)

2020-07-21 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.6 and 6.7. Only pty devices need reprint delays. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: August 7th, 2020 (ximcp)

2020-08-06 Thread T.J. Townsend
Errata patches for libX11 have been released for OpenBSD 6.6 and 6.7. The recent security errata broke X11 input methods. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: July 31st, 2020 (dix)

2020-07-31 Thread T.J. Townsend
Errata patches for Xorg have been released for OpenBSD 6.6 and 6.7. Pixmaps inside the xserver were an info leak. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: July 31st, 2020 (ximcp)

2020-07-31 Thread T.J. Townsend
Errata patches for libX11 have been released for OpenBSD 6.6 and 6.7. Malformed messages can cause heap corruption in the X Input Method client implementation in libX11. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be

OpenBSD Errata: July 9th, 2020 (shmget)

2020-07-09 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.6 and 6.7. shmget IPC_STAT leaked some kernel data. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: June 8th, 2020 (asr)

2020-06-07 Thread T.J. Townsend
Errata patches for libc have been released for OpenBSD 6.6 and 6.7. libc's resolver could get into a corrupted state. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: June 11th, 2020 (x509)

2020-06-09 Thread T.J. Townsend
Errata patches for LibreSSL have been released for OpenBSD 6.6 and 6.7. libcrypto may fail to build a valid certificate chain due to expired untrusted issuer certificates. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be

OpenBSD Errata: June 5th, 2020 (hid)

2020-06-04 Thread T.J. Townsend
Errata patches for the kernel have been released for OpenBSD 6.6 and 6.7. Malicious HID descriptors could be misparsed. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective errata page:

OpenBSD Errata: July 27th, 2020 (rpki)

2020-07-27 Thread T.J. Townsend
Errata patches for rpki-client have been released for OpenBSD 6.7. In rpki-client, incorrect use of EVP_PKEY_cmp allows an authentication bypass. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the errata page:

OpenBSD Errata: July 27th, 2020 (iked)

2020-07-27 Thread T.J. Townsend
Errata patches for OpenIKED have been released for OpenBSD 6.6 and 6.7. In iked, incorrect use of EVP_PKEY_cmp allows an authentication bypass. Binary updates for the amd64, i386, and arm64 platforms are available via the syspatch utility. Source code patches can be found on the respective

  1   2   >