← Back

Openbsd

openbsd

Vendor: Openbsd • 198 CVEs

CVEs (198)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openbsd
1Openbsd
Apr 24, 2026
Apr 21, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_opt_len * 8 - 2" expre...Show more
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_opt_len * 8 - 2" expression with no preceding check for whether nd_opt_len is zero.Show less
1Openbsd
1Openbsd
Sep 5, 2025
Mar 20, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash.
1Openbsd
1Openbsd
Sep 23, 2025
Dec 6, 2024
6.2 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
1Openbsd
1Openbsd
Sep 23, 2025
Dec 5, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.
1Openbsd
1Openbsd
Sep 23, 2025
Dec 5, 2024
4.1 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
1Openbsd
1Openbsd
Oct 2, 2025
Nov 15, 2024
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
1Openbsd
1Openbsd
Aug 14, 2025
May 7, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An atta...Show more
OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of multicast routing. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. . Was ZDI-CAN-16112.Show less
1Openbsd
1Openbsd
Aug 14, 2025
May 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An atta...Show more
OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of multicast routing. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. . Was ZDI-CAN-14540.Show less
2Freebsd
Openbsd
2Freebsd
Openbsd
Jun 17, 2025
Apr 11, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.
1Openbsd
1Openbsd
Oct 10, 2025
Mar 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
1Openbsd
1Openbsd
Oct 10, 2025
Mar 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
1Openbsd
1Openbsd
Oct 10, 2025
Mar 1, 2024
N/A· v4
6.2 MEDIUM· v3
N/A· v2
In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.
1Openbsd
1Openbsd
Nov 21, 2024
Aug 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequen...Show more
OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.Show less
1Openbsd
2Libressl
Openbsd
Nov 21, 2024
Jun 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
1Openbsd
2Libressl
Openbsd
Feb 7, 2025
Apr 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
1Openbsd
2Libressl
Openbsd
Feb 10, 2025
Apr 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore...Show more
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.Show less
2Openbsd
Opensmtpd
2Openbsd
Opensmtpd
Nov 4, 2025
Apr 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
1Openbsd
1Openbsd
Mar 6, 2025
Mar 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
1Openbsd
1Openbsd
Nov 21, 2024
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can preve...Show more
slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.Show less
1Openbsd
1Openbsd
Nov 21, 2024
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitati...Show more
engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.Show less