For errata on a certain release, click below:
2.0,
2.1,
2.2,
2.3,
2.4,
2.5,
2.6,
2.7,
2.8,
2.9,
3.0,
3.1,
3.2,
3.3,
3.4,
3.5,
3.6,
3.7,
3.8,
3.9,
4.0,
4.1,
4.2,
4.3,
4.4,
4.5,
4.6,
4.7,
4.8,
4.9,
5.0,
5.1,
5.2,
5.3,
5.4,
5.5,
5.6,
5.7,
5.8,
5.9,
6.0,
6.1,
6.2,
6.3,
6.4,
6.5,
6.6,
6.7,
6.8,
6.9,
7.0,
7.1,
7.2,
7.3,
7.4,
7.5,
7.6,
7.7,
7.8.
Patches for the OpenBSD base system are distributed as unified diffs.
Each patch is cryptographically signed with the
signify(1) tool and contains
usage instructions.
All the following patches are also available in one
tar.gz file
for convenience.
Alternatively, the syspatch(8)
utility can be used to apply binary updates.
Full binary updates are made available on the following architectures:
amd64, i386, arm64.
On other architectures, only machine-independent updates are produced (and
these are exceedingly rare).
Patches for supported releases are also incorporated into the
-stable branch, which is maintained for one year
after release.
-
001: SECURITY FIX: June 2, 2026
All architectures
Multiple vulnerabilites in the X server dri2, sync, saver and Xkb
extensions.
A source code patch exists which remedies this problem.
-
002: RELIABILITY FIX: June 2, 2026
All architectures
Fixes for a variety of crashing bugs in smtpd(8).
A source code patch exists which remedies this problem.
-
003: RELIABILITY FIX: June 2, 2026
amd64 arm64
In vmd(8), fix a variety of crashing bugs and misbehavior of -b flag.
A source code patch exists which remedies this problem.
-
004: RELIABILITY FIX: July 16, 2026
All architectures
Fix some info leaks, kernel crashes, and pinsyscall(8) / kbind(8)
locking failures.
A source code patch exists which remedies this problem.
-
005: SECURITY FIX: July 16, 2026
All architectures
Fix numerous problems in the System V (sem, msg, ipc) system call
layers.
A source code patch exists which remedies this problem.
-
006: RELIABILITY FIX: July 16, 2026
All architectures
Fix double-free, memory leaks, and vnode references in NFS server.
A source code patch exists which remedies this problem.
-
007: RELIABILITY FIX: July 16, 2026
All architectures
Stricter IPsec and IPComp input validation prevents kernel crash.
A source code patch exists which remedies this problem.
-
008: RELIABILITY FIX: August 11, 2026
All architectures
Heap or stack corruption in npppd(8) LCP option handling could lead
to crashes.
A source code patch exists which remedies this problem.
-
009: RELIABILITY FIX: August 11, 2026
All architectures
iked(8) could be crashed remotely pre authentication.
A source code patch exists which remedies this problem.
-
010: SECURITY FIX: August 22, 2026
All architectures
Interface ioctl(4) could leak 4 bytes of kernel memory.
A source code patch exists which remedies this problem.
-
011: RELIABILITY FIX: August 22, 2026
All architectures
A race in pledge(2) namei check could trigger a kernel panic.
A source code patch exists which remedies this problem.
-
012: SECURITY FIX: August 22, 2026
All architectures
The sysctl(2) kern.proc could leak kernel memory.
A source code patch exists which remedies this problem.
-
013: RELIABILITY FIX: August 22, 2026
All architectures
TIOCGSID on tty(4) could trigger a kernel panic.
A source code patch exists which remedies this problem.
-
014: SECURITY FIX: August 22, 2026
All architectures
Backport all changes from libexpat 2.8.3.
CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132
CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406
CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410
CVE-2026-56411 CVE-2026-56412 CVE-2026-72522
A source code patch exists which remedies this problem.