Reattempt the upgrade to gnupg-2.5.24
Upstream published a fix for regression that broke mail/notmuch
configure. Updating now means smaller steps if we need an update for
a security issue in the next 8.0 OpenBSD release. ok sthen@ naddy@
cherrypick fix for CPython CVE-2026-19445: Use-after-free of a
server-side SSLContext when sni_callback switches contexts. ok tb kmos
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context
to SSLSocket.context (the documented way to select a certificate per
server name) and nothing else keeps the original ssl.SSLContext alive.
Typical cases are servers that create an SSLContext per connection or
replace it while connections are open.
update net/libtorrent 0.16.24
- major bump due to removed symbols
- unbreaks tests by linking using static archive (from tj@)
approved by sthen@ and tested by and OK tj@
update net/rtorrent 0.16.24
- various security fixes (e.g., overflow, heap overflow and use-after-free)
- regen test/Makefile.in patch to remove a new, third instance of -ldl
approved by sthen@ and tested by and OK tj@
Update p5-DBI to 1.654
1.654 - 2026-09-25, H.Merijn Brand & Robert Rothenberg
* Fix DBI::sql_type_cast on IV/NV (CVE-2026-88815) (reported by Raj)
* Fix FetchHashKeyName on IV/NV (CVE-2026-88816) (reported by Raj)
* Fix provided in META
With upstream patch for compilation under gcc.
ok sthen@
There is a hidden dep on databases/libhiredis that can cause a build
failure when junking between configure and build. Since enabling this
feature changes PLIST, disable for now and we can re-evaluate after
unlock.
OK lucas@ naddy@
update to png-1.6.59, fixing use-after-free of zlib input in
png_read_end() after incomplete zTXt, iTXt or iCCP decompression
https://github.com/pnggroup/libpng/security/advisories/GHSA-qvg3-h654-xq3j
ok matthieu who has verified that this is not reachable from xenocara's
use of the static-linked copy
set -u _nsd / _unbound as appropriate when running nsd-control /
unbound-control through doas, to match the existing pkg-readme.
from Atanas Vladimirov.
Backport three security fixes from the groff-1.24.2 release.
OK naddy@ on a previous, minimally different version of this patch.
From the groff-1.24.2 release announcement (September 28, 2026):
"This release corrects command injection security vulnerabilities
(CWE-78) in the mmroff, pdfmom, and pre-grohtml programs. The last of
these is a preprocessor that is run when groff or troff is run with the
-T html or -T xhtml options. The vulnerabilities are variously
14-26 years old. Malicious input can escape groff's default "safer"
mode, running commands embedded in that input at the user's privilege
level. The groff development team recommends this release to any users
who employ the named tools or GNU troff output formats with untrusted
inputs.
Man page rendering is not vulnerable unless rendering (X)HTML."