Patch released NetBSD 10.2 info-disclosure ipfilter NetBSD Project
NetBSD 10.2 security fixes close a remote kernel bug in ipfilter
CVE Tools coverage
The NetBSD Project released NetBSD 10.2 with a fix for a remotely triggerable null pointer dereference in ipfilter that could crash the kernel, plus a TCP timestamp issue that exposes 4 bytes of kernel stack data. The update also addresses unspecified security issues in NFS and telnet, updates OpenSSL to 3.0.21, Xorg to 21.1.24, and xkbcomp to 1.5.0, and includes fixes for libXpm CVE-2026-4367 and unbound CVE-2025-11411. Administrators should upgrade NetBSD 10 systems, updating the kernel and modules before userspace when using a manual upgrade path.