untrusted comment: verify with openbsd-78-base.pub RWS3/nvFmk4SWT3mjQQMMdTjRJ8G8OEPK7VoWAlMSWpJXeoI8tKrIlTNoi4w5ckREhPHbjgZTE4rXN8AsZYwfa225RTYUNYyHgw= OpenBSD 7.8 errata 061, September 30, 2026: An errant process could cause ps(1) to crash due to a buffer overflow in sysctl(2). Apply by doing: signify -Vep /etc/signify/openbsd-78-base.pub -x 061_procargs.patch.sig \ -m - | (cd /usr/src && patch -p0) And then rebuild and install a new kernel: KK=`sysctl -n kern.osversion | cut -d# -f1` cd /usr/src/sys/arch/`machine`/compile/$KK make obj make config make make install Index: sys/kern/kern_sysctl.c =================================================================== RCS file: /cvs/src/sys/kern/kern_sysctl.c,v diff -u -p -r1.483.2.1 kern_sysctl.c --- sys/kern/kern_sysctl.c 14 Jul 2026 12:12:33 -0000 1.483.2.1 +++ sys/kern/kern_sysctl.c 19 Sep 2026 22:00:00 -0000 @@ -2229,6 +2229,17 @@ sysctl_proc_args(int *name, u_int namele vargv = pss.ps_envstr; } + /* + * Clamp to avoid overflow, using ARG_MAX is only an approximation. + * It is not possible to execve() with this many elements, so this only + * happens if a process has changed its strings. + */ + if (cnt > ARG_MAX) { + /* Hard cap, so don't return ENOMEM, caller can't retry */ + error = EINVAL; + goto out; + } + /* -1 to have space for a terminating NUL */ limit = *oldlenp - 1; *oldlenp = 0;