update net/rtorrent 0.16.24
- various security fixes (e.g., overflow, heap overflow and use-after-free)
- regen test/Makefile.in patch to remove a new, third instance of -ldl
approved by sthen@ and tested by and OK tj@
Update p5-DBI to 1.654
1.654 - 2026-09-25, H.Merijn Brand & Robert Rothenberg
* Fix DBI::sql_type_cast on IV/NV (CVE-2026-88815) (reported by Raj)
* Fix FetchHashKeyName on IV/NV (CVE-2026-88816) (reported by Raj)
* Fix provided in META
With upstream patch for compilation under gcc.
ok sthen@
There is a hidden dep on databases/libhiredis that can cause a build
failure when junking between configure and build. Since enabling this
feature changes PLIST, disable for now and we can re-evaluate after
unlock.
OK lucas@ naddy@
update to png-1.6.59, fixing use-after-free of zlib input in
png_read_end() after incomplete zTXt, iTXt or iCCP decompression
https://github.com/pnggroup/libpng/security/advisories/GHSA-qvg3-h654-xq3j
ok matthieu who has verified that this is not reachable from xenocara's
use of the static-linked copy
set -u _nsd / _unbound as appropriate when running nsd-control /
unbound-control through doas, to match the existing pkg-readme.
from Atanas Vladimirov.
Backport three security fixes from the groff-1.24.2 release.
OK naddy@ on a previous, minimally different version of this patch.
From the groff-1.24.2 release announcement (September 28, 2026):
"This release corrects command injection security vulnerabilities
(CWE-78) in the mmroff, pdfmom, and pre-grohtml programs. The last of
these is a preprocessor that is run when groff or troff is run with the
-T html or -T xhtml options. The vulnerabilities are variously
14-26 years old. Malicious input can escape groff's default "safer"
mode, running commands embedded in that input at the user's privilege
level. The groff development team recommends this release to any users
who employ the named tools or GNU troff output formats with untrusted
inputs.
Man page rendering is not vulnerable unless rendering (X)HTML."
databases/pgbouncer: security update to 1.26.0
see https://www.pgbouncer.org/2026/09/pgbouncer-1-26-0, fixes:
* CVE-2026-19888: DoS due to crash, triggerable by unauthenticated
clients. Caused by a SCRAM client-final-message without a nonce.
* CVE-2026-6668: DoS due to infinite loop, triggerable by unauthenticated
clients. Caused by an integer overflow in the packet buffer growth
logic.
* CVE-2026-6669: DoS due to unbounded work during login, triggerable by a
malicious PostgreSQL server. Caused by an unbounded SCRAM iteration
count.
ok naddy@
qt5/qtbase ports changes, ok rsadowski naddy
- add getexecpath support to qt5/qtbase
- fix builds with ccache; the way this was handled in qtbase could be
simplified as it's already done by ports infrastructure, and the way
it was done here previously isn't compatible with recent bsd.port.mk
changes