For errata on a certain release, click below:
2.0,
2.1,
2.2,
2.3,
2.4,
2.5,
2.6,
2.7,
2.8,
2.9,
3.0,
3.1,
3.2,
3.3,
3.4,
3.5,
3.6,
3.7,
3.8,
3.9,
4.0,
4.1,
4.2,
4.3,
4.4,
4.5,
4.6,
4.7,
4.8,
4.9,
5.0,
5.1,
5.2,
5.3,
5.4,
5.5,
5.6,
5.7,
5.8,
5.9,
6.0,
6.1,
6.2,
6.3,
6.4,
6.5,
6.6,
6.7,
6.8,
6.9,
7.0,
7.1,
7.2,
7.3,
7.4,
7.5,
7.6.
Patches for the OpenBSD base system are distributed as unified diffs.
Each patch is cryptographically signed with the
signify(1) tool and contains
usage instructions.
All the following patches are also available in one
tar.gz file
for convenience.
Alternatively, the syspatch(8)
utility can be used to apply binary updates.
Full binary updates are made available on the following architectures:
amd64, i386, arm64.
On other architectures, only machine-independent updates are produced (and
these are exceedingly rare).
Patches for supported releases are also incorporated into the
-stable branch, which is maintained for one year
after release.
-
001: SECURITY FIX: May 5, 2025
All architectures
Kernel of NFS server could crash if nfsd(8) is enabled and an evil
NFS request is sent to it.
A source code patch exists which remedies this problem.
-
002: RELIABILITY FIX: May 10, 2025
All architectures
Fix sign of UTC offset in some timezone files created by zic(8).
A source code patch exists which remedies this problem.
-
003: RELIABILITY FIX: May 10, 2025
All architectures
Replace incorrect zoneinfo files created by broken zic(8).
A source code patch exists which remedies this problem.
This is a machine-independent patch, so syspatches are made available for all architectures (not just amd64, arm64, i386). Please run syspatch(8) on those machines to get the new zoneinfo files.
-
004: RELIABILITY FIX: June 17, 2025
All architectures
When using syncookies in pf(4), new TCP connections could run into
timeout due to integer underflow.
A source code patch exists which remedies this problem.
-
005: RELIABILITY FIX: June 17, 2025
All architectures
In acme-client(1), handle as yet unobserved "processing" state when
fetching an issued certificate by retrying instead of giving up.
A source code patch exists which remedies this problem.
-
005: SECURITY FIX: June 17, 2025
All architectures
Multiple X11 server issues.
CVE-2025-49175 CVE-2025-49176 CVE-2025-49177 CVE-2025-49178
CVE-2025-49179 CVE-2025-49180
A source code patch exists which remedies this problem.