untrusted comment: verify with openbsd-79-base.pub RWTSdNN9A3yvWGYqjudpg8Kqm4RriDcznmKUh4UwvAQE5cxt5QoLVfNMYv3hzT1ooRHWD5nJtR2M2WqvWxPEXL4q9SXSXZFj0Qw= OpenBSD 7.9 errata 028, September 30, 2026: After wg(4) interface destruction a use-after-free coould be triggered by incoming packets. Apply by doing: signify -Vep /etc/signify/openbsd-79-base.pub -x 028_wgbind.patch.sig \ -m - | (cd /usr/src && patch -p0) And then rebuild and install a new kernel: KK=`sysctl -n kern.osversion | cut -d# -f1` cd /usr/src/sys/arch/`machine`/compile/$KK make obj make config make make install Index: sys/net/if_wg.c =================================================================== RCS file: /cvs/src/sys/net/if_wg.c,v diff -u -p -r1.48 if_wg.c --- sys/net/if_wg.c 13 Apr 2026 01:10:39 -0000 1.48 +++ sys/net/if_wg.c 21 Sep 2026 01:39:39 -0000 @@ -785,22 +785,24 @@ wg_socket_close(struct socket **so) int wg_bind(struct wg_softc *sc, in_port_t *portp, int *rtablep) { - int ret = 0, rtable = *rtablep; - in_port_t port = *portp; + int ret = 0, rtable; + in_port_t port; struct socket *so4; #ifdef INET6 struct socket *so6; int retries = 0; retry: #endif + port = *portp; + rtable = *rtablep; if ((ret = wg_socket_open(&so4, AF_INET, &port, &rtable, sc)) != 0) return ret; #ifdef INET6 if ((ret = wg_socket_open(&so6, AF_INET6, &port, &rtable, sc)) != 0) { + wg_socket_close(&so4); if (ret == EADDRINUSE && *portp == 0 && retries++ < 100) goto retry; - wg_socket_close(&so4); return ret; } #endif