BSDSec

deadsimple BSD Security Advisories and Announcements

OpenBSD Errata: May 22nd, 2020 (ssh)

Errata patches for ssh-keygen have been released for OpenBSD 6.7.

When attempting to download resident keys from a FIDO token that does not
require a password/PIN, ssh-keygen would crash with a NULL dereference.

Binary updates for the amd64, i386, and arm64 platforms are available via
the syspatch utility. Source code patches can be found on the errata page:

  https://www.openbsd.org/errata67.html