Confluencer
Well-known member
Das Service-Release 25.12.1 wurde am 18.03.2026 veröffentlicht (Release-Notes).
Upgrade mit "Attended Sysupgrade" verlief mal wieder unproblematisch.
Neben neuer Kernel Version und neuen Paket Versionen sind wieder Security Fixes enthalten:
Upgrade mit "Attended Sysupgrade" verlief mal wieder unproblematisch.
Neben neuer Kernel Version und neuen Paket Versionen sind wieder Security Fixes enthalten:
OpenWrt components (Trail of Bits audit, February 2026):
LuCI:
- CVE-2026-30871: Stack buffer overflow in umdns DNS PTR query handling (HIGH)
- CVE-2026-30872: Stack buffer overflow in umdns IPv6 reverse DNS lookup (HIGH)
- CVE-2026-30873: Memory leak in jsonpath when processing strings, labels, and regexp tokens (LOW)
- CVE-2026-30874: Command execution via PATH environment variable filter bypass in procd (LOW)
Additional hardening from the same Trail of Bits audit (no CVE assigned):
- odhcpd: fix stack buffer overflow in DHCPv6 Identity Association logging
- procd: fix out-of-bounds write in cgroup path building and cgroup rule application