Patches for the OpenBSD base system are distributed as unified diffs.
Each patch is cryptographically signed with the
signify(1) tool and contains
usage instructions.
All the following patches are also available in one
tar.gz file
for convenience.
Alternatively, the syspatch(8)
utility can be used to apply binary updates.
Full binary updates are made available on the following architectures:
amd64, i386, arm64.
On other architectures, only machine-independent updates are produced (and
these are exceedingly rare).
Patches for supported releases are also incorporated into the
-stable branch, which is maintained for one year
after release.
020: SECURITY FIX: September 14, 2026All architectures
Multiple vulnerabilities in the X server and server side font library.
CVE-2026-55999 CVE-2026-56000 CVE-2026-56001 CVE-2026-56002
CVE-2026-56003
A source code patch exists which remedies this problem.
022: SECURITY FIX: September 30, 2026All architectures
Update nsd(8) to version 4.15.2.
CVE-2026-12244 CVE-2026-12245 CVE-2026-12246 CVE-2026-12490
CVE-2026-18664 CVE-2026-18916 CVE-2026-19401 CVE-2026-19538
A source code patch exists which remedies this problem.
023: SECURITY FIX: September 30, 2026All architectures
Update unbound(8) to version 1.26.1.
CVE-2026-14586 CVE-2026-32665 CVE-2026-32792 CVE-2026-33278
CVE-2026-40622 CVE-2026-40691 CVE-2026-41292 CVE-2026-41637
CVE-2026-42534 CVE-2026-42923 CVE-2026-42944 CVE-2026-42955
CVE-2026-42959 CVE-2026-42960 CVE-2026-44390 CVE-2026-44608
CVE-2026-44621 CVE-2026-44687 CVE-2026-44690 CVE-2026-46582
CVE-2026-50045 CVE-2026-50046 CVE-2026-50243 CVE-2026-50248
CVE-2026-50251 CVE-2026-50252 CVE-2026-52863 CVE-2026-54478
CVE-2026-55708 CVE-2026-55717 CVE-2026-55973 CVE-2026-55990
CVE-2026-55991 CVE-2026-56416 CVE-2026-56444
A source code patch exists which remedies this problem.
024: SECURITY FIX: September 30, 2026All architectures
Fix a variety of bugs in libressl:
Remove RelativeDistinguishedName support for CRL distribution points
Ensure verify callbacks always returning 1 can see a hostname mismatch
Correct botched size check in dtls1_preprocess_fragment()
Limit size of buffered DTLS handshake messages
Avoid potential overread on interrupted retransmission in DTLS
Fix OCSP responder authorization bypass in libtls and ocspcheck(8)
027: SECURITY FIX: September 30, 2026All architectures
A malicious IKEv2 peer could crash iked(8), or cause a certificate
validation verdict to be applied to the wrong peer identity.
A source code patch exists which remedies this problem.