unFKNreal writes
"A fellow by the name of Georgi Guninski has discovered a
local root compromise
in OpenBSD 2.8 & 2.9. He says its due to a race in the kernel, similar to the linux kernel race a few months back."
The
patch is out
as of a few hours ago. Even a BSD newbie like me got his firewall patched and rebooted with no problem, after taking a moment to reread the
patching instructions
and
kernel rebuild FAQ.
The bad news: the hole was posted to bugtraq Thursday morning, with exploit code, so the black hats had a jump on you (sadly, note the
date
Guninski says OpenBSD was informed). If your system has any users you don't fully trust, check it over carefully after you patch!
Update 3h later by
J : Apparently NetBSD is affected too, and a fix is
in-tree.