Backport three security fixes from the groff-1.24.2 release.
OK naddy@ on a previous, minimally different version of this patch.
From the groff-1.24.2 release announcement (September 28, 2026):
"This release corrects command injection security vulnerabilities
(CWE-78) in the mmroff, pdfmom, and pre-grohtml programs. The last of
these is a preprocessor that is run when groff or troff is run with the
-T html or -T xhtml options. The vulnerabilities are variously
14-26 years old. Malicious input can escape groff's default "safer"
mode, running commands embedded in that input at the user's privilege
level. The groff development team recommends this release to any users
who employ the named tools or GNU troff output formats with untrusted
inputs.
Man page rendering is not vulnerable unless rendering (X)HTML."
set_dist_point_name(): tiny tweak to restore previous behavior
Allocate fnm before allocating *pdp. This way a second call to to
set_dist_point_name() has a tiny little chance of succeeding.
ok beck ("I strongly suspect this will never matter anywhere.")
libcrypto: remove support for nameRelativeToCRLIssuer
Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
is sound advice since this garbage was eating memory for breakfast before
signature thanks to the wonderful gem that is the extension cache.
One has to wonder why this was needed in libcrypto... This isn't worth
fixing so off to the bit bucket it goes.
from tb, ok beck jsing
libssl: Avoid potential overread on interrupted retransmission in DTLS
from OpenSSL via jsing
this is errata/7.8/060_libressl.patch.sig
libcrypto: remove support for nameRelativeToCRLIssuer
Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
is sound advice since this garbage was eating memory for breakfast before
signature thanks to the wonderful gem that is the extension cache.
One has to wonder why this was needed in libcrypto... This isn't worth
fixing so off to the bit bucket it goes.
from tb, ok beck jsing
libssl: Avoid potential overread on interrupted retransmission in DTLS
from OpenSSL via jsing
this is errata/7.9/024_libressl.patch.sig
libcrypto: remove support for nameRelativeToCRLIssuer
Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
is sound advice since this garbage was eating memory for breakfast before
signature thanks to the wonderful gem that is the extension cache.
One has to wonder why this was needed in libcrypto... This isn't worth
fixing, so off to the bit bucket it goes.
ok beck jsing
sys/qwz: reclaim incomplete RX batches
Process and replenish reaped buffers even when the batch contains no
complete MSDU. Error only and incomplete bacthes must not leave buffers
or descriptors on temporary lists.
OK: stsp@
sys/qwz: retain unused RX descriptors
Draw RX descriptors from the free list only when the caller supplies
none. Return unused descriptors on every refill exit, including
allocation failures and a full ring. This fixes qwz-specific ownership.
OK: stsp@
sys/qwz: reuse RDDM buffers
Based on sys/dev/pci/if_qwx_pci.c,v 1.31
Reuse the RDDM data and vector buffers on repeated MHI starts to avoid
leaking their allocations. Reprogram the BHIE RX vector after startup
clears its registers; returning early would leave them unset.
OK: stsp@