NetBSD 10.2 has been released with security fixes, including a patch for a remotely triggerable kernel bug in ipfilter. The flaw is a null pointer dereference, meaning the kernel tries to read memory through a null pointer. An attacker outside the machine could trigger it on systems using ipfilter to filter traffic at the network edge.
Because ipfilter is often deployed on NetBSD machines positioned at the edge of a network, the bug is exposed to remote traffic. The update closes that hole, and administrators running ipfilter are advised to update to NetBSD 10.2.