untrusted comment: verify with openbsd-78-base.pub RWS3/nvFmk4SWe6cHssyL6Ms0SU0TzuSizIW3PEC1xZv9xJZtkl98N4Gx6r6Q2wLl7sgGh480GBtL7csodO0AD5DRwCNWmaeaQw= OpenBSD 7.8 errata 064, September 30, 2026: After wg(4) interface destruction a use-after-free coould be triggered by incoming packets. Apply by doing: signify -Vep /etc/signify/openbsd-78-base.pub -x 064_wgbind.patch.sig \ -m - | (cd /usr/src && patch -p0) And then rebuild and install a new kernel: KK=`sysctl -n kern.osversion | cut -d# -f1` cd /usr/src/sys/arch/`machine`/compile/$KK make obj make config make make install Index: sys/net/if_wg.c =================================================================== RCS file: /cvs/src/sys/net/if_wg.c,v diff -u -p -r1.47 if_wg.c --- sys/net/if_wg.c 17 Sep 2025 12:35:55 -0000 1.47 +++ sys/net/if_wg.c 21 Sep 2026 01:42:03 -0000 @@ -782,22 +782,24 @@ wg_socket_close(struct socket **so) int wg_bind(struct wg_softc *sc, in_port_t *portp, int *rtablep) { - int ret = 0, rtable = *rtablep; - in_port_t port = *portp; + int ret = 0, rtable; + in_port_t port; struct socket *so4; #ifdef INET6 struct socket *so6; int retries = 0; retry: #endif + port = *portp; + rtable = *rtablep; if ((ret = wg_socket_open(&so4, AF_INET, &port, &rtable, sc)) != 0) return ret; #ifdef INET6 if ((ret = wg_socket_open(&so6, AF_INET6, &port, &rtable, sc)) != 0) { + wg_socket_close(&so4); if (ret == EADDRINUSE && *portp == 0 && retries++ < 100) goto retry; - wg_socket_close(&so4); return ret; } #endif