NetBSD 10.2 security fixes close a remote kernel bug in ipfilter
PatchNetBSD 10.2ipfilterOur summary
The NetBSD Project released NetBSD 10.2 with a fix for a remotely triggerable null pointer dereference in ipfilter that could crash the kernel, plus a TCP timestamp issue that exposes 4 bytes of kernel stack data. The update also addresses unspecified security issues in NFS and telnet, updates OpenSSL to 3.0.21, Xorg to 21.1.24, and xkbcomp to 1.5.0, and includes fixes for libXpm CVE-2026-4367 and unbound CVE-2025-11411. Administrators should upgrade NetBSD 10 systems, updating the kernel and modules before userspace when using a manual upgrade path.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.