Hi,
Today a number of security advisories in third party software are being addressed. Also, a bad dhcp6c patch has been reverted which requires a manual reboot to take full effect.
CAUTION: The OpenSSH update prevents SSH sessions from being established. You need to restart OpenSSH from the GUI or run the console command "pluginctl -s openssh restart" or reboot the system in order to unbreak it.
Here are the full patch notes:
- interfaces: improve DHCPv6 requirement rules on WAN interface
- interfaces: support reading more attributes in ifconfig output parser
- interfaces: correct logic of resolve flag in ARP table (contributed by Kevin Pelzel)
- reporting: add NetFlow IPv6 support for destinations
- kea-dhcp: add description field to subnets
- kea-dhcp: add next-server option to subnets (contributed by Harm Kroon)
- wireguard: fix IP protocol detection for manual gateway
- ui: remove aria-hidden from dialogs (contributed by Jason Fayre)
- ui: properly break out selectpicker options in modals
- plugins: os-bind 1.32[1]
- plugins: os-caddy 1.6.0[2]
- plugins: os-ddclient 1.22[3]
- plugins: os-nginx 1.33[4]
- plugins: os-theme-cicada 1.36 (contributed by Team Rebellion)
- plugins: os-theme-vicuna 1.46 (contributed by Team Rebellion)
- plugins: os-zabbix-agent 1.14[5]
- plugins: os-zabbix-proxy 1.11[6]
- ports: dhcp6c 20240710 reverts faulty Debian patch
- ports: krb5 1.21.3[7]
- ports: nss 3.101[8]
- ports: openssh 9.8p1[9]
- ports: openvpn 2.6.11[10]
- ports: suricata 7.0.6[11]
A hotfix release was issued as 24.1.10_1:
- interfaces: allow DHCPv6 server answer from a GUA
A hotfix release was issued as 24.1.10_2:
- interfaces: allow DHCPv6 multicast as well
A hotfix release was issued as 24.1.10_3:
- firewall: fix regression in GeoIP aliases selector
A hotfix release was issued as 24.1.10_8:
- firewall: fix one-to-one NAT migration with external address without a subnet set
- firmware: add fingerprint and upgrade hint for 24.7
- firmware: prefer ZFS over UFS in upgrade message
- firmware: remove unneeded Unbound DNS database upgrade script
- firmware: remove stale Squid plugin upgrade script
Stay safe,
Your OPNsense team