OpenBSD Journal

OpenBSD Journal

OpenSSH 9.9 released!

Contributed by grey on from the now with post-quantum key exchange! dept.

In a fediverse post, Damien Miller (djm@) announced the availability of the new OpenSSH version 9.9:

OpenSSH 9.9 has just been released. New features include support for hybrid ML-KEM X25519 post-quantum key exchange (using a formally-verified ML-KEM implementation), improved controls to drop and penalise unwanted connections, faster NTRUPrime key exchange code and more.

Read more…

OpenBGPD 8.6 released

Contributed by rueda on from the borderline routed dept.

Claudio Jeker (claudio@) announced the release of version 8.6 of OpenBGPD, the OpenBSD project's Border Gateway Protocol (BGP) daemon:

We have released OpenBGPD 8.6, which will be arriving in the
OpenBGPD directory of your local OpenBSD mirror soon.

This release includes the following changes to the previous release:

Read more…

OpenBSD -current has moved to version 7.6

Contributed by rueda on from the here-we-go-again dept.

The OpenBSD 7.6 release cycle is entering its final phases…

With the following commit, Theo de Raadt (deraadt@) moved -current to version 7.6:

CVSROOT:	/cvs
Module name:	src
Changes by:	deraadt@cvs.openbsd.org	2024/09/17 07:39:17

Modified files:
	sys/conf       : newvers.sh 

Log message:
head into release

For those unfamiliar with the process: this is not the 7.6 release, but is part of the standard build-up to the release.

Remember: It's time to start using "-D snap" with pkg_add(1) (and pkg_info(1)).

(Regular readers will know what comes next…)
This serves as an excellent reminder to upgrade snapshots frequently, test both base and ports, and report problems [plus, of course, donate!].

Game of Trees 0.103 released

Contributed by rueda on from the again-and-again-and dept.

Version 0.103 of Game of Trees has been released (and the port updated).

* got 0.103; 2024-09-24
  see git repository history for per-change authorship information
- fix bug causing performance to degrade as more and more pack files appear
- tog: add diff view 'p' keymap to write the diff to file
- tog: display diffstat in diff view when diffing blobs or trees directly
- gotwebd: show commit id prefix on briefs page
- add support for HMAC digests to gotd HTTP notifications
- move authentication credentials from gotd.conf(5) to gotd-secrets.conf(5)
- fix spurious tog regression test failures on slower machines
- restore abort() calls in lib/hash.c to quiet potential compiler warnings
- gotwebd: unbreak listing of tags on the summary page (regression from 0.102)
- gotwebd: minor tweaks to the HTML for ease of styling

rpki-client 9.2 released

Contributed by rueda on from the key-route dept.

Sebastian Benoit (benno@) announced the release of version 9.2 of rpki-client, the essential component for routing security.

See the full announcement for further details.

Here are some key excerpts from the release announcement:

This release includes the following changes to the previous release:

- Ensure synchronization jobs are stopped when the timeout is reached.

- Fix a corner case in repository handling. If the last RRDP repository
  failed to load, rpki-client would fail to fall back to rsync due to an
  ordering bug in the event loop.

- Improve detection of duplicate file paths. Only trigger a duplicate
  error if a valid path is revisited otherwise a bad CA could prevent
  legitimate files from being considered valid.

- Normalize internal representation of the caRepository to have a
  trailing slash and ensure that the rpkiManifest is a file inside it.

No unmodified files remain from original import of OpenBSD

Contributed by rueda on from the plus-ça-change dept.

All files from the original import of OpenBSD have now been modified (or deleted). Appropriately, Theo de Raadt (deraadt@) made the change:

CVSROOT:	/cvs
Module name:	src
Changes by:	deraadt@cvs.openbsd.org	2024/08/23 11:29:08

Modified files:
	games/quiz     : Makefile 
	games/quiz/datfiles: index 
Added files:
	games/quiz/datfiles: ship 
Removed files:
	games/quiz/datfiles: greek 

Log message:
The greek quiz is so obscure that it is ridiculous -- noone can play
this.  Replace it with a new quiz about galley (ship) parts.  This
commit changes the *LAST UNMODIFIED ORIGINAL FILE* (meaning revision
1.1.1.1) from the original import that created OpenBSD on Oct 18,
1995.  With this commit, we have completed an amusing mission of
replacing the final parts of the original OpenBSD.

We have reached OpenBSD of Theseus.

ideas & assistance from mglocker, naval terminology help from jmc

Donate!

Donate to OpenBSD

Features

We are constantly on the lookout for stories of how you put OpenBSD to work. Please submit any informative articles on how OpenBSD is helping your company.

OpenBSD Errata

OpenBSD 7.5

0102024-09-17 RELIABILITY Invalid ELF files could result in kernel crash.
0092024-09-17 SECURITY In readdir name validation exclude any '/' to avoid unexpected directory traversal on untrusted file systems.
0082024-09-17 SECURITY Avoid possible mbuf double free in NFS client and server implementation. Do not use uninitialized variable in error handling of NFS server.
0072024-09-17 SECURITY In libexpat add integer range checks. CVE-2024-45490 CVE-2024-45491 CVE-2024-45492
0062024-08-19 SECURITY cron(8) and crontab(1) can crash due to incorrect /step values. CVE-2024-43688
0052024-08-02 SECURITY sndiod(8) main process could crash due to buffer overread.

Unofficial RSS feed of OpenBSD errata

OpenBSD 7.4

0222024-09-17 SECURITY In readdir name validation exclude any '/' to avoid unexpected directory traversal on untrusted file systems.
0212024-09-17 SECURITY Avoid possible mbuf double free in NFS client and server implementation. Do not use uninitialized variable in error handling of NFS server.
0202024-09-17 SECURITY In libexpat add integer range checks. CVE-2024-45490 CVE-2024-45491 CVE-2024-45492
0192024-08-19 SECURITY cron(8) and crontab(1) can crash due to incorrect /step values. CVE-2024-43688
0182024-08-02 SECURITY sndiod(8) main process could crash due to buffer overread.
0172024-06-26 RELIABILITY Repair a withdraw desyncronization problem in bgpd(8).

Unofficial RSS feed of OpenBSD errata

XML/RSS/RDF

Users wishing RSS/RDF summary files of OpenBSD Journal can retrieve: RSS feed

Options are available.

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]