OpenBSD Journal

OpenBSD Journal

In -current, chromium (and derivatives) now have VA-API support

Contributed by rueda on from the smooth-and-cool dept.

Following a discussion on ports@, Robert Nagy (robert@) committed VA-API [hardware-assisted video - see previous report] support to the chromium, iridium, and ungoogled-chromium ports.

Note that:

  • Updated (binary) packages for amd64 are just starting to become available.
  • Intel GPUs requires ports graphics/intel-media-driver [and/]or graphics/intel-vaapi-driver.
  • Firefox already has VA-API support.

WPA3 support for OpenBSD 802.11 wireless funded by NLNet Foundation

Contributed by Peter N. M. Hansteen on from the WiFi all chirpy dept.

The project to implement WPA3 support for OpenBSD 802.11 wireless has now been funded by a grant from the NLNet Foundation.

The work is to be carried out by Stefan Sperling (stsp@) and Chirpy Software.

The announcement states,

This project delivers the second open-source implementation of WPA3, the current industry standard for Wi-Fi encryption, specifically for the OpenBSD operating system. Its code can also be integrated by other operating systems to enable modern Wi-Fi encryption, thereby enhancing the diversity and resilience of the global IT ecosystem.

The project has an October 2025 start date, which likely means that work to implement even better Wi-Fi support in our favorite operating system is already under way. Read more from the announcement at the NLNet Foundation website.

We look forward to seeing the tangible results in future commits!

LibreSSL 4.2.0 Released

Contributed by Peter N. M. Hansteen on from the TLS SSLithers out dept.

The LibreSSL project has announced their latest release LibreSSL 4.2.0, with numerous improvements. The release announcement reads,
List:       openbsd-announce
Subject:    LibreSSL 4.2.0 Released
From:       Brent Cook <busterb () gmail ! com>
Date:       2025-10-14 14:19:28


We have released LibreSSL 4.2.0, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon. This is the
first stable release for the 4.2.x branch, also to be available with OpenBSD 7.8

It includes the following changes from LibreSSL 4.1.0:

Read more…

OpenSSH 10.2 released

Contributed by Peter N. M. Hansteen on from the SSH! A more perfect 10 dept.

Cranking up the heat for the upcoming OpenBSD 7.8 release, the OpenSSH project has issued OpenSSH 10.2.

This is a bugfix release that supersedes the previously announced OpenSSH 10.1 in time for the general release.

From the release notes:

Changes since OpenSSH 10.1
==========================

This is a bugfix release, primarily to fix a problem that rendered
ssh(1) unusable when ControlPersist was enabled.

Read more…

OpenSSH 10.1 released

Contributed by Peter N. M. Hansteen on from the SSH! silently released dept.

The OpenSSH project has released OpenSSH 10.1, which is also the release that will be part of the upcoming OpenBSD 7.8 release.

The release was marked by a very unobtrusive sequence of www commits, with the first saying simply

List:       openbsd-cvs
Subject:    CVS: cvs.openbsd.org: www
From:       Damien Miller <djm () cvs ! openbsd ! org>
Date:       2025-10-06 7:11:57


CVSROOT:	/cvs
Module name:	www
Changes by:	djm@cvs.openbsd.org	2025/10/06 01:11:57

Added files:
	openssh/txt    : release-10.1 

Log message:
openssh-10.1 release notes

which points to the OpenSSH 10.1 release notes, giving a fuller description of the new release.

If you're running -current or jumping snapshot to snapshot, you should already be running code equal to or very close to this.

Game of Trees 0.120 released

Contributed by rueda on from the again-and-again-and dept dept.

Version 0.120 of Game of Trees has been released (and the port updated):

  • disable gotwebd authentication if it is not enabled in /etc/gotwebd.conf
  • ensure that GOTWEBD_LOGIN_TIMEOUT is used consistently at build time
  • prevent date-specific gotsysd regress failures due to asctime_r whitespace
  • make gotwebd refuse to start up if the _gotwebd user is root
  • make gotwebd warn if the webserver's user is set to root in /etc/gotwebd.conf
  • add /etc/gotwebd.conf parameters for hiding repositories
  • reject bad hostnames provided to the gotsh weblogin command
  • allow gotwebd to optionally display a login hint when authentication fails

Donate!

Donate to OpenBSD

Features

We are constantly on the lookout for stories of how you put OpenBSD to work. Please submit any informative articles on how OpenBSD is helping your company.

Earlier Articles

OpenBSD Errata

OpenBSD 7.7

0102025-09-30 SECURITY Fix out-of-bounds read and write, memory leaks and incorrect error check for CMS enveloped data.
0092025-09-30 SECURITY In libexpat fix denial of service due to memory exhaustion. CVE-2025-59375 CVE-2024-8176
0082025-07-01 RELIABILITY TIOCUCNTL ioctl(2) could crash the kernel if called with a non-file argument.
0072025-07-01 SECURITY Previous fix for X11 server was incomplete. CVE-2025-49176
0062025-06-17 SECURITY Multiple X11 server issues. CVE-2025-49175 CVE-2025-49176 CVE-2025-49177 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180
0052025-06-17 RELIABILITY In acme-client(1), handle as yet unobserved "processing" state when fetching an issued certificate by retrying instead of giving up.

Unofficial RSS feed of OpenBSD errata

OpenBSD 7.6

0232025-09-30 SECURITY Fix out-of-bounds read and write, memory leaks and incorrect error check for CMS enveloped data.
0222025-09-30 SECURITY In libexpat fix denial of service due to memory exhaustion. CVE-2025-59375 CVE-2024-8176
0212025-07-01 RELIABILITY TIOCUCNTL ioctl(2) could crash the kernel if called with a non-file argument.
0202025-07-01 SECURITY Previous fix for X11 server was incomplete. CVE-2025-49176
0192025-06-17 SECURITY Multiple X11 server issues. CVE-2025-49175 CVE-2025-49176 CVE-2025-49177 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180
0182025-06-17 RELIABILITY In acme-client(1), handle as yet unobserved "processing" state when fetching an issued certificate by retrying instead of giving up.

Unofficial RSS feed of OpenBSD errata

XML/RSS/RDF

Users wishing RSS/RDF summary files of OpenBSD Journal can retrieve: RSS feed

Options are available.

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]