changelogs:

pull/434/head
Ad Schellevis 2 years ago
parent b6089f6a66
commit 06c1202fe2

@ -8,7 +8,7 @@ Community Edition
:width: 600px
:align: center
As of January 2015 there have been *233* releases leading to the latest version *22.7.2*
As of January 2015 there have been *237* releases leading to the latest version *22.7.6*
named "Powerful Panther".

@ -122,7 +122,7 @@ Here are the full patch notes:
* ports: dhcp6c ignores advertise messages with none of requested data and missed status codes
* ports: libressl 3.1.5 `[6] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.1.5-relnotes.txt>`__
* ports: lighttpd 1.4.56 `[7] <https://www.lighttpd.net/2020/11/29/1.4.56/>`__
* ports: nss 3.60 `[8] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.60_release_notes>`__
* ports: nss 3.60 `[8] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_60.html>`__
* ports: openssl 1.1.1i `[9] <https://www.openssl.org/news/secadv/20201208.txt>`__
* ports: pcre2 10.36 `[10] <https://www.pcre.org/changelog.txt>`__
* ports: sudo 1.9.4 `[11] <https://www.sudo.ws/stable.html#1.9.4>`__
@ -180,7 +180,7 @@ Here are the full patch notes:
* src: fix multiple vulnerabilities in rtsold `[7] <FREEBSD:FreeBSD-SA-20:32.rtsold>`__
* src: update timezone database information `[8] <FREEBSD:FreeBSD-EN-20:20.tzdata>`__
* ports: krb5 1.18.3 `[9] <https://web.mit.edu/kerberos/krb5-1.18/>`__
* ports: nss 3.59 `[10] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.59_release_notes>`__
* ports: nss 3.59 `[10] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_59.html>`__
* ports: openldap 2.4.56 `[11] <https://www.openldap.org/software/release/changes.html>`__
* ports: openssh 8.4p1 `[12] <https://www.openssh.com/txt/release-8.4>`__
* ports: php 7.3.25 `[13] <https://www.php.net/ChangeLog-7.php#7.3.25>`__
@ -272,7 +272,7 @@ Here are the full patch notes:
* src: update Realtek re driver to upstream version 1.96.04 (contributed by Laurent Dinclaux)
* ports: curl 7.73.0 `[3] <https://curl.se/changes.html#7_73_0>`__
* ports: libxml fixes for CVE-2019-20388, CVE-2020-7595 and CVE-2020-24977
* ports: nss 3.58 `[4] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.58_release_notes>`__
* ports: nss 3.58 `[4] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_58.html>`__
* ports: openssl 1.1.1h `[5] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: php 7.3.23 `[6] <https://www.php.net/ChangeLog-7.php#7.3.23>`__
* ports: pkg 1.15.10
@ -331,7 +331,7 @@ Here are the full patch notes:
* src: set PAX_HARDENING_NOSHLIBRANDOM in the RTLD by default
* src: fix kernel panic while trying to read multicast stream
* ports: mpd 5.9 `[13] <http://mpd.sourceforge.net/doc5/mpd4.html#4>`__
* ports: nss 3.57 `[14] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes>`__
* ports: nss 3.57 `[14] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_57.html>`__
* ports: php 7.3.22 `[15] <https://www.php.net/ChangeLog-7.php#7.3.22>`__
* ports: pkg 1.15.6 `[16] <https://github.com/freebsd/freebsd-ports/commit/fd4f5566aea>`__
@ -384,7 +384,7 @@ Here are the full patch notes:
* src: default "show bad packets" tunable to off in e100 driver
* src: fix unsolicited promisc mode in e1000 driver
* src: add valectl to the system commands
* ports: ca_root_nss/nss 3.56 `[4] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.56_release_notes>`__
* ports: ca_root_nss/nss 3.56 `[4] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_56.html>`__
* ports: curl 7.72.0 `[5] <https://curl.se/changes.html#7_72_0>`__
* ports: libressl 3.1.4 `[6] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.1.4-relnotes.txt>`__
* ports: openldap 2.4.51 `[7] <https://www.openldap.org/software/release/changes.html>`__
@ -474,7 +474,7 @@ Here are the full patch notes against version 20.7-RC1:
* src: prevent netgraph page fault for LTE usage
* ports: dnsmasq 2.82 `[4] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: monit 5.27.0 `[5] <https://mmonit.com/monit/changes/>`__
* ports: nss 3.55 `[6] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes>`__
* ports: nss 3.55 `[6] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_55.html>`__
* ports: sudo 1.9.2 `[7] <https://www.sudo.ws/stable.html#1.9.2>`__
Known issues and limitations:

@ -54,7 +54,7 @@ Here are the full patch notes:
* ports: flock 2.37.2
* ports: hostapd 2.10 `[12] <https://w1.fi/cgit/hostap/plain/hostapd/ChangeLog>`__
* ports: lighttpd 1.4.63 `[13] <https://www.lighttpd.net/2021/12/4/1.4.63/>`__
* ports: nss 3.74 `[14] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.74_release_notes>`__
* ports: nss 3.74 `[14] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_74.html>`__
* ports: openssl 1.1.1m `[15] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: openvpn 2.5.5 `[16] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.5>`__
* ports: php 7.4.27 `[17] <https://www.php.net/ChangeLog-7.php#7.4.27>`__
@ -130,7 +130,7 @@ Here are the full patch notes:
* plugins: os-zabbix-proxy 1.6 `[10] <https://github.com/opnsense/plugins/blob/stable/21.7/net-mgmt/zabbix-proxy/pkg-descr>`__
* ports: curl 7.80.0 `[11] <https://curl.se/changes.html#7_80_0>`__
* ports: dnsmasq fixes multiple regressions
* ports: nss 3.73 `[12] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.73_release_notes>`__
* ports: nss 3.73 `[12] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_73.html>`__
* ports: php 7.4.26 `[13] <https://www.php.net/ChangeLog-7.php#7.4.26>`__
* ports: phpseclib 2.0.35 `[14] <https://github.com/phpseclib/phpseclib/releases/tag/2.0.35>`__
* ports: suricata 6.0.4 `[15] <https://forum.suricata.io/t/suricata-6-0-4-and-5-0-8-released/1942>`__
@ -238,7 +238,7 @@ Here are the full patch notes:
* ports: dnspython 2.1.0 `[18] <https://dnspython.readthedocs.io/en/stable/whatsnew.html>`__
* ports: jinja 3.0.1 `[19] <https://jinja.palletsprojects.com/en/3.0.x/changes/#version-3-0-1>`__
* ports: lighttpd 1.4.61 `[20] <https://www.lighttpd.net/2021/10/28/1.4.61/>`__
* ports: nss 3.72 `[21] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.72_release_notes>`__
* ports: nss 3.72 `[21] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_72.html>`__
* ports: openssh 8.8p1 `[22] <https://www.openssh.com/txt/release-8.8>`__
* ports: openvpn 2.5.4 `[23] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.4>`__
* ports: pcre2 10.39 `[24] <https://www.pcre.org/changelog.txt>`__
@ -403,7 +403,7 @@ Here are the full patch notes:
* ports: monit 5.29.0 `[21] <https://mmonit.com/monit/changes/>`__
* ports: mpd5 adds L2TP interoperability fix from upstream
* ports: nettle 3.7.3
* ports: nss 3.70 `[22] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.70_release_notes>`__
* ports: nss 3.70 `[22] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_70.html>`__
* ports: openvpn 2.5.3 `[23] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.3>`__
* ports: pcre 8.45 `[24] <https://www.pcre.org/original/changelog.txt>`__
* ports: php 7.4.23 `[25] <https://www.php.net/ChangeLog-7.php#7.4.23>`__

@ -97,7 +97,7 @@ Here are the full patch notes:
* ports: filterlog adds CARP IPv6 support and moves label to previously reserved spot
* ports: isc-dhcp 4.4.2-P1 `[9] <https://downloads.isc.org/isc/dhcp/4.4.2-P1/dhcp-4.4.2-P1-RELNOTES>`__
* ports: libxml 2.9.12 `[10] <http://www.xmlsoft.org/news.html>`__
* ports: nss 3.67 `[11] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.67_release_notes>`__
* ports: nss 3.67 `[11] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_67.html>`__
* ports: openldap 2.4.59 `[12] <https://www.openldap.org/software/release/changes.html>`__
* ports: openssl 1.1.1l `[13] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: pcre2 10.37 `[14] <https://www.pcre.org/changelog.txt>`__
@ -200,7 +200,7 @@ Here are the full patch notes:
* src: linux: prevent integer overflow in futex_requeue `[15] <FREEBSD:EN-21:22.linux_futex>`__
* ports: filterlog 0.4 adds label support to output if applicable
* ports: libxml fix for CVE-2021-3541
* ports: nss 3.65 `[16] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.65_release_notes>`__
* ports: nss 3.65 `[16] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_65.html>`__
* ports: openssh 8.6p1 `[17] <https://www.openssh.com/txt/release-8.6>`__
* ports: php 7.3.28 `[18] <https://www.php.net/ChangeLog-7.php#7.3.28>`__
* ports: py-yaml 5.4.1
@ -510,7 +510,7 @@ Here are the full patch notes:
* src: arp: avoid segfaulting due to out-of-bounds memory access
* src: fix multiple OpenSSL vulnerabilities `[24] <FREEBSD:FreeBSD-SA-21:07.openssl>`__
* src: axgbe: enable receive all mode to bypass the MAC filter to avoid dropping CARP MAC addresses
* ports: ca_root_nss / nss 3.63 `[25] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.63_release_notes>`__
* ports: ca_root_nss / nss 3.63 `[25] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_63.html>`__
* ports: curl 7.75.0 `[26] <https://curl.se/changes.html#7_75_0>`__
* ports: dnsmasq 2.84 `[27] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: igmpproxy 0.3 `[28] <https://github.com/pali/igmpproxy/releases/tag/0.3>`__

@ -51,11 +51,12 @@ Here are the full patch notes:
* plugins: os-postfix 1.23 `[2] <https://github.com/opnsense/plugins/blob/stable/22.1/mail/postfix/pkg-descr>`__
* plugins: os-stunnel 1.0.5 adds intermediates to server chain (contributed by Johnny S. Lee)
* plugins: os-telegraf 1.12.5 `[3] <https://github.com/opnsense/plugins/blob/stable/22.1/net-mgmt/telegraf/pkg-descr>`__
* ports: nss 3.80 `[4] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.80_release_notes>`__
* ports: nss 3.80 `[4] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_80.html>`__
* ports: py-vici 5.9.3
* ports: python 3.9.13 `[5] <https://docs.python.org/release/3.9.13/whatsnew/changelog.html>`__
* ports: sudo 1.9.11p3 `[6] <https://www.sudo.ws/stable.html#1.9.11p3>`__
* ports: syslog-ng 3.37.1 `[7] <https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-3.37.1>`__
* ports: unbound 1.16.2 `[8] <https://nlnetlabs.nl/projects/unbound/download/#unbound-1-16-2>`__
A hotfix release was issued as 22.4.3_1:
@ -117,7 +118,7 @@ Here are the full patch notes:
* ports: curl 7.84.0 `[7] <https://curl.se/changes.html#7_84_0>`__
* ports: krb5 1.20 `[8] <https://web.mit.edu/kerberos/krb5-1.20/>`__
* ports: lighttpd 1.4.65 `[9] <https://www.lighttpd.net/2022/6/7/1.4.65/>`__
* ports: nss 3.79 `[10] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.79_release_notes>`__
* ports: nss 3.79 `[10] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_79.html>`__
* ports: openssl 1.1.1q `[11] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: openvpn 2.5.7 `[12] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.7>`__
* ports: php 7.4.30 `[13] <https://www.php.net/ChangeLog-7.php#7.4.30>`__
@ -196,7 +197,7 @@ Here are the full patch notes:
* ports: expat 2.4.8 `[11] <https://github.com/libexpat/libexpat/blob/R_2_4_8/expat/Changes>`__
* ports: libxml 2.9.13 `[12] <http://www.xmlsoft.org/news.html>`__
* ports: monit 5.32.0 `[13] <https://mmonit.com/monit/changes/>`__
* ports: nss 3.78 `[14] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.78_release_notes>`__
* ports: nss 3.78 `[14] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_78.html>`__
* ports: pcre2 10.40 `[15] <https://www.pcre.org/changelog.txt>`__
* ports: php 7.4.29 `[16] <https://www.php.net/ChangeLog-7.php#7.4.29>`__
* ports: phpseclib 2.0.37 `[17] <https://github.com/phpseclib/phpseclib/releases/tag/2.0.37>`__
@ -486,7 +487,7 @@ Here are the full patch notes:
* ports: krb5 1.19.3 `[26] <https://web.mit.edu/kerberos/krb5-1.19/>`__
* ports: lighttpd 1.4.64 `[27] <https://www.lighttpd.net/2022/1/19/1.4.64/>`__
* ports: monit 5.30.0 `[28] <https://mmonit.com/monit/changes/>`__
* ports: nss 3.76 `[29] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.76_release_notes>`__
* ports: nss 3.76 `[29] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_76.html>`__
* ports: openssh 8.9p1 `[30] <https://www.openssh.com/txt/release-8.9>`__
* ports: openssl 1.1.1n `[31] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: openvpn 2.5.6 `[32] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.6>`__

@ -448,7 +448,7 @@ Here are the full patch notes:
* dns: improve forwarder interface listening generation
* rc: silence backup warnings about stripped leading slashes
* ports: bind 9.10.4-P3 `[2] <http://ftp.isc.org/isc/bind9/9.10.4-P3/RELEASE-NOTES-bind-9.10.4-P3.html>`__
* ports: ca_root_nss 3.27.1 `[3] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.27.1_release_notes>`__
* ports: ca_root_nss 3.27.1 `[3] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_27_1.html>`__
* ports: libressl 2.3.8 `[4] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.3.8-relnotes.txt>`__
* ports: unbound 1.5.10 `[5] <https://nlnetlabs.nl/projects/unbound/download/#unbound-1-5-10>`__

@ -122,7 +122,7 @@ Here are the full patch notes:
* ports: dhcp6c ignores advertise messages with none of requested data and missed status codes
* ports: libressl 3.1.5 `[6] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.1.5-relnotes.txt>`__
* ports: lighttpd 1.4.56 `[7] <https://www.lighttpd.net/2020/11/29/1.4.56/>`__
* ports: nss 3.60 `[8] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.60_release_notes>`__
* ports: nss 3.60 `[8] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_60.html>`__
* ports: openssl 1.1.1i `[9] <https://www.openssl.org/news/secadv/20201208.txt>`__
* ports: pcre2 10.36 `[10] <https://www.pcre.org/changelog.txt>`__
* ports: sudo 1.9.4 `[11] <https://www.sudo.ws/stable.html#1.9.4>`__
@ -180,7 +180,7 @@ Here are the full patch notes:
* src: fix multiple vulnerabilities in rtsold `[7] <FREEBSD:FreeBSD-SA-20:32.rtsold>`__
* src: update timezone database information `[8] <FREEBSD:FreeBSD-EN-20:20.tzdata>`__
* ports: krb5 1.18.3 `[9] <https://web.mit.edu/kerberos/krb5-1.18/>`__
* ports: nss 3.59 `[10] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.59_release_notes>`__
* ports: nss 3.59 `[10] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_59.html>`__
* ports: openldap 2.4.56 `[11] <https://www.openldap.org/software/release/changes.html>`__
* ports: openssh 8.4p1 `[12] <https://www.openssh.com/txt/release-8.4>`__
* ports: php 7.3.25 `[13] <https://www.php.net/ChangeLog-7.php#7.3.25>`__
@ -272,7 +272,7 @@ Here are the full patch notes:
* src: update Realtek re driver to upstream version 1.96.04 (contributed by Laurent Dinclaux)
* ports: curl 7.73.0 `[3] <https://curl.se/changes.html#7_73_0>`__
* ports: libxml fixes for CVE-2019-20388, CVE-2020-7595 and CVE-2020-24977
* ports: nss 3.58 `[4] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.58_release_notes>`__
* ports: nss 3.58 `[4] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_58.html>`__
* ports: openssl 1.1.1h `[5] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: php 7.3.23 `[6] <https://www.php.net/ChangeLog-7.php#7.3.23>`__
* ports: pkg 1.15.10
@ -331,7 +331,7 @@ Here are the full patch notes:
* src: set PAX_HARDENING_NOSHLIBRANDOM in the RTLD by default
* src: fix kernel panic while trying to read multicast stream
* ports: mpd 5.9 `[13] <http://mpd.sourceforge.net/doc5/mpd4.html#4>`__
* ports: nss 3.57 `[14] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes>`__
* ports: nss 3.57 `[14] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_57.html>`__
* ports: php 7.3.22 `[15] <https://www.php.net/ChangeLog-7.php#7.3.22>`__
* ports: pkg 1.15.6 `[16] <https://github.com/freebsd/freebsd-ports/commit/fd4f5566aea>`__
@ -384,7 +384,7 @@ Here are the full patch notes:
* src: default "show bad packets" tunable to off in e100 driver
* src: fix unsolicited promisc mode in e1000 driver
* src: add valectl to the system commands
* ports: ca_root_nss/nss 3.56 `[4] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.56_release_notes>`__
* ports: ca_root_nss/nss 3.56 `[4] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_56.html>`__
* ports: curl 7.72.0 `[5] <https://curl.se/changes.html#7_72_0>`__
* ports: libressl 3.1.4 `[6] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.1.4-relnotes.txt>`__
* ports: openldap 2.4.51 `[7] <https://www.openldap.org/software/release/changes.html>`__
@ -474,7 +474,7 @@ Here are the full patch notes against version 20.7-RC1:
* src: prevent netgraph page fault for LTE usage
* ports: dnsmasq 2.82 `[4] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: monit 5.27.0 `[5] <https://mmonit.com/monit/changes/>`__
* ports: nss 3.55 `[6] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes>`__
* ports: nss 3.55 `[6] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_55.html>`__
* ports: sudo 1.9.2 `[7] <https://www.sudo.ws/stable.html#1.9.2>`__
Known issues and limitations:

@ -66,7 +66,7 @@ Here are the full patch notes:
* plugins: os-zabbix-agent 1.9 `[4] <https://github.com/opnsense/plugins/blob/stable/21.1/net-mgmt/zabbix-agent/pkg-descr>`__
* ports: curl 7.78.0 `[5] <https://curl.se/changes.html#7_78_0>`__
* ports: filterlog adds CARP IPv6 support and moves label to previously reserved spot
* ports: nss 3.68 `[6] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.68_release_notes>`__
* ports: nss 3.68 `[6] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_68.html>`__
* ports: php 7.4.21 `[7] <https://www.php.net/ChangeLog-7.php#7.4.21>`__
* ports: python 3.7.11 `[8] <https://docs.python.org/release/3.7.11/whatsnew/changelog.html>`__
* ports: syslog-ng 3.33.2 `[9] <https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-3.33.2>`__
@ -127,7 +127,7 @@ Here are the full patch notes:
* ports: clog 1.0.2 fixes garbage header write on init
* ports: libxml 2.9.12 `[7] <http://www.xmlsoft.org/news.html>`__
* ports: nettle 3.7.3
* ports: nss 3.67 `[8] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.67_release_notes>`__
* ports: nss 3.67 `[8] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_67.html>`__
* ports: openvpn 2.5.3 `[9] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.3>`__
* ports: php 7.4.20 `[10] <https://www.php.net/ChangeLog-7.php#7.4.20>`__
* ports: phpseclib 2.0.32 `[11] <https://github.com/phpseclib/phpseclib/releases/tag/2.0.32>`__
@ -191,7 +191,7 @@ Here are the full patch notes:
* src: pms data corruption `[6] <FREEBSD:FreeBSD-EN-21:14.pms>`__
* ports: curl 7.77.0 `[7] <https://curl.se/changes.html#7_77_0>`__
* ports: isc-dhcp 4.4.2-P1 `[8] <https://downloads.isc.org/isc/dhcp/4.4.2-P1/dhcp-4.4.2-P1-RELNOTES>`__
* ports: nss 3.66 `[9] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.66_release_notes>`__
* ports: nss 3.66 `[9] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_66.html>`__
* ports: openldap 2.4.59 `[10] <https://www.openldap.org/software/release/changes.html>`__
* ports: pcre2 10.37 `[11] <https://www.pcre.org/changelog.txt>`__
* ports: phalcon 4.1.2 `[12] <https://github.com/phalcon/cphalcon/releases/tag/v4.1.2>`__
@ -268,7 +268,7 @@ Here are the full patch notes:
* ports: filterlog 0.4 adds label support to output if applicable
* ports: libressl 3.3.3 `[12] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.3.3-relnotes.txt>`__
* ports: libxml fix for CVE-2021-3541
* ports: nss 3.65 `[13] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.65_release_notes>`__
* ports: nss 3.65 `[13] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_65.html>`__
* ports: openssh 8.6p1 `[14] <https://www.openssh.com/txt/release-8.6>`__
* ports: openvpn 2.4.11 `[15] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24#OpenVPN2.4.11>`__
* ports: php 7.3.28 `[16] <https://www.php.net/ChangeLog-7.php#7.3.28>`__
@ -420,7 +420,7 @@ Here are the full patch notes:
* plugins: os-wireguard 1.5 `[5] <https://github.com/opnsense/plugins/blob/stable/21.1/net/wireguard/pkg-descr>`__
* plugins: os-wol 2.4 fixes dashboard widget (contributed by kulikov-a)
* src: fix multiple OpenSSL vulnerabilities `[6] <FREEBSD:FreeBSD-SA-21:07.openssl>`__
* ports: ca_root_nss / nss 3.63 `[7] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.63_release_notes>`__
* ports: ca_root_nss / nss 3.63 `[7] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_63.html>`__
* ports: libressl 3.2.5 `[8] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.2.5-relnotes.txt>`__
* ports: openldap 2.4.58 `[9] <https://www.openldap.org/software/release/changes.html>`__
* ports: openssh fix for double free in ssh-agent `[10] <https://ftp.openbsd.org/pub/OpenBSD/patches/6.8/common/015_sshagent.patch.sig>`__
@ -492,7 +492,7 @@ Here are the full patch notes:
* src: arp: avoid segfaulting due to out-of-bounds memory access
* ports: cpdup 1.22 `[8] <https://github.com/DragonFlyBSD/cpdup/releases/tag/v1.22>`__
* ports: krb5 1.19.1 `[9] <https://web.mit.edu/kerberos/krb5-1.19/>`__
* ports: nss 3.62 `[10] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.62_release_notes>`__
* ports: nss 3.62 `[10] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_62.html>`__
* ports: pkg now provides fallback for version mismatch on pkg-add
* ports: python 3.7.10 `[11] <https://docs.python.org/release/3.7.10/whatsnew/changelog.html>`__
* ports: syslog-ng 3.31.1 `[12] <https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-3.31.1>`__
@ -731,7 +731,7 @@ Here are the full patch notes against 20.7.8:
* src: fix traffic graph not showing bandwidth when IPS is enabled
* ports: dnsmasq 2.83 `[9] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: igmpproxy 0.3 `[10] <https://github.com/pali/igmpproxy/releases/tag/0.3>`__
* ports: nss 3.61 `[11] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.61_release_notes>`__
* ports: nss 3.61 `[11] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_61.html>`__
* ports: openldap 2.4.57 `[12] <https://www.openldap.org/software/release/changes.html>`__
* ports: py-netaddr 0.8.0 `[13] <https://pypi.org/project/netaddr/0.8.0/>`__
* ports: sudo 1.9.5p2 `[14] <https://www.sudo.ws/stable.html#1.9.5p2>`__

@ -76,7 +76,7 @@ Here are the full patch notes:
* ports: flock 2.37.2
* ports: hostapd 2.10 `[12] <https://w1.fi/cgit/hostap/plain/hostapd/ChangeLog>`__
* ports: lighttpd 1.4.63 `[13] <https://www.lighttpd.net/2021/12/4/1.4.63/>`__
* ports: nss 3.74 `[14] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.74_release_notes>`__
* ports: nss 3.74 `[14] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_74.html>`__
* ports: openssl 1.1.1m `[15] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: openvpn 2.5.5 `[16] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.5>`__
* ports: php 7.4.27 `[17] <https://www.php.net/ChangeLog-7.php#7.4.27>`__
@ -124,7 +124,7 @@ Here are the full patch notes:
* src: axgbe: log GPIO signals on EEPROM read fails
* ports: curl 7.80.0 `[3] <https://curl.se/changes.html#7_80_0>`__
* ports: dnsmasq fixes multiple regressions
* ports: nss 3.73 `[4] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.73_release_notes>`__
* ports: nss 3.73 `[4] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_73.html>`__
* ports: php 7.4.26 `[5] <https://www.php.net/ChangeLog-7.php#7.4.26>`__
* ports: phpseclib 2.0.35 `[6] <https://github.com/phpseclib/phpseclib/releases/tag/2.0.35>`__
* ports: suricata disables Netmap API version 14 introduced in 21.7.6
@ -257,7 +257,7 @@ Here are the full patch notes for version 21.7.5:
* src: fix kernel panic in vmci driver initialization `[13] <FREEBSD:FreeBSD-EN-21:28.vmci>`__
* src: timezone database information update `[14] <FREEBSD:FreeBSD-EN-21:29.tzdata>`__
* ports: lighttpd 1.4.61 `[15] <https://www.lighttpd.net/2021/10/28/1.4.61/>`__
* ports: nss 3.72 `[16] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.72_release_notes>`__
* ports: nss 3.72 `[16] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_72.html>`__
* ports: openssh 8.8p1 `[17] <https://www.openssh.com/txt/release-8.8>`__
* ports: pcre2 10.39 `[18] <https://www.pcre.org/changelog.txt>`__
* ports: php 7.4.25 `[19] <https://www.php.net/ChangeLog-7.php#7.4.25>`__
@ -340,7 +340,7 @@ Here are the full patch notes:
* ports: jinja 3.0.1 `[8] <https://jinja.palletsprojects.com/en/3.0.x/changes/#version-3-0-1>`__
* ports: libressl 3.3.5 `[9] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.3.5-relnotes.txt>`__
* ports: lighttpd 1.4.60 `[10] <https://www.lighttpd.net/2021/10/3/1.4.60/>`__
* ports: nss 3.71 `[11] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.71_release_notes>`__
* ports: nss 3.71 `[11] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_71.html>`__
* ports: openvpn 2.5.4 `[12] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.4>`__
* ports: php 7.4.24 `[13] <https://www.php.net/ChangeLog-7.php#7.4.24>`__
* ports: strongswan 5.9.4 `[14] <https://github.com/strongswan/strongswan/releases/tag/5.9.4>`__
@ -388,7 +388,7 @@ Here are the full patch notes:
* plugins: os-telegraf 1.12.1 `[6] <https://github.com/opnsense/plugins/blob/stable/21.7/net-mgmt/telegraf/pkg-descr>`__
* ports: dnsmasq 2.86 `[7] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: filterlog 0.5 removes unused IPv6 options support
* ports: nss 3.70 `[8] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.70_release_notes>`__
* ports: nss 3.70 `[8] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_70.html>`__
* ports: pcre 8.45 `[9] <https://www.pcre.org/original/changelog.txt>`__
* ports: python 3.8.12 `[10] <https://docs.python.org/release/3.8.12/whatsnew/changelog.html>`__
* ports: sudo 1.9.8p1 `[11] <https://www.sudo.ws/stable.html#1.9.8p1>`__
@ -477,7 +477,7 @@ Here are the full patch notes:
* src: fix multiple OpenSSL vulnerabilities `[6] <FREEBSD:FreeBSD-SA-21:16.openssl>`__ `[7] <FREEBSD:FreeBSD-SA-21:17.openssl>`__
* ports: ifinfo 13.0
* ports: libressl 3.3.4 `[8] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.3.4-relnotes.txt>`__
* ports: nss 3.69 `[9] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.69_release_notes>`__
* ports: nss 3.69 `[9] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_69.html>`__
* ports: monit 5.29.0 `[10] <https://mmonit.com/monit/changes/>`__
* ports: mpd5 adds L2TP interoperability fix from upstream
* ports: openssl 1.1.1l `[11] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
@ -693,7 +693,7 @@ Here are the full patch notes:
* ports: filterlog adds CARP IPv6 support and moves label to previously reserved spot
* ports: libxml 2.9.12 `[15] <http://www.xmlsoft.org/news.html>`__
* ports: nettle 3.7.3
* ports: nss 3.68 `[16] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.68_release_notes>`__
* ports: nss 3.68 `[16] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_68.html>`__
* ports: openvpn 2.5.3 `[17] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.3>`__
* ports: php 7.4.21 `[18] <https://www.php.net/ChangeLog-7.php#7.4.21>`__
* ports: phpseclib 2.0.32 `[19] <https://github.com/phpseclib/phpseclib/releases/tag/2.0.32>`__
@ -885,7 +885,7 @@ Here are the full patch notes against 21.1.7:
* ports: drop hardening options to ease migration to FreeBSD ports tree
* ports: libxml 2.9.12 `[6] <http://www.xmlsoft.org/news.html>`__
* ports: nettle 3.7.3
* ports: nss 3.67 `[7] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.67_release_notes>`__
* ports: nss 3.67 `[7] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_67.html>`__
* ports: openvpn 2.5.3 `[8] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.3>`__
* ports: php 7.4.20 `[9] <https://www.php.net/ChangeLog-7.php#7.4.20>`__
* ports: phpseclib 2.0.32 `[10] <https://github.com/phpseclib/phpseclib/releases/tag/2.0.32>`__

@ -73,7 +73,7 @@ Here are the full patch notes:
* plugins: os-stunnel 1.0.5 adds intermediates to server chain (contributed by Johnny S. Lee)
* plugins: os-telegraf 1.12.5 `[3] <https://github.com/opnsense/plugins/blob/stable/22.1/net-mgmt/telegraf/pkg-descr>`__
* ports: curl 7.84.0 `[4] <https://curl.se/changes.html#7_84_0>`__
* ports: nss 3.80 `[5] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.80_release_notes>`__
* ports: nss 3.80 `[5] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_80.html>`__
* ports: openssl 1.1.1q `[6] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: phalcon 5.0.0RC2 `[7] <https://github.com/phalcon/cphalcon/releases/tag/v5.0.0RC2>`__
* ports: py-vici 5.9.3
@ -134,7 +134,7 @@ Here are the full patch notes:
* src: assorted non-functional cleanups and typo corrections
* ports: krb5 1.20 `[5] <https://web.mit.edu/kerberos/krb5-1.20/>`__
* ports: lighttpd 1.4.65 `[6] <https://www.lighttpd.net/2022/6/7/1.4.65/>`__
* ports: nss 3.79 `[7] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.79_release_notes>`__
* ports: nss 3.79 `[7] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_79.html>`__
* ports: openvpn 2.5.7 `[8] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.7>`__
* ports: php 7.4.30 `[9] <https://www.php.net/ChangeLog-7.php#7.4.30>`__
* ports: py-certifi 2022.5.18.1
@ -238,7 +238,7 @@ Here are the full patch notes:
* plugins: os-zabbix-agent 1.12 `[5] <https://github.com/opnsense/plugins/blob/stable/22.1/net-mgmt/zabbix-agent/pkg-descr>`__
* plugins: os-zabbix-proxy 1.8 `[6] <https://github.com/opnsense/plugins/blob/stable/22.1/net-mgmt/zabbix-proxy/pkg-descr>`__
* ports: curl 7.83.0 `[7] <https://curl.se/changes.html#7_83_0>`__
* ports: nss 3.78 `[8] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.78_release_notes>`__
* ports: nss 3.78 `[8] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_78.html>`__
* ports: openssl 1.1.1o `[9] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: pcre2 10.40 `[10] <https://www.pcre.org/changelog.txt>`__
* ports: php 7.4.29 `[11] <https://www.php.net/ChangeLog-7.php#7.4.29>`__
@ -324,7 +324,7 @@ Here are the full patch notes:
* ports: expat 2.4.8 `[11] <https://github.com/libexpat/libexpat/blob/R_2_4_8/expat/Changes>`__
* ports: libxml 2.9.13 `[12] <http://www.xmlsoft.org/news.html>`__
* ports: monit 5.32.0 `[13] <https://mmonit.com/monit/changes/>`__
* ports: nss 3.77 `[14] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.77_release_notes>`__
* ports: nss 3.77 `[14] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_77.html>`__
* ports: python 3.8.13 `[15] <https://docs.python.org/release/3.8.13/whatsnew/changelog.html>`__
@ -416,7 +416,7 @@ Here are the full patch notes:
* ports: dpinger 3.2 `[3] <https://github.com/dennypage/dpinger/releases/tag/v3.2>`__
* ports: expat 2.4.7 `[4] <https://github.com/libexpat/libexpat/blob/R_2_4_7/expat/Changes>`__
* ports: krb5 1.19.3 `[5] <https://web.mit.edu/kerberos/krb5-1.19/>`__
* ports: nss 3.76 `[6] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.76_release_notes>`__
* ports: nss 3.76 `[6] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_76.html>`__
* ports: openssh 8.9p1 `[7] <https://www.openssh.com/txt/release-8.9>`__
* ports: sudo 1.9.10 `[8] <https://www.sudo.ws/stable.html#1.9.10>`__
* ports: syslog-ng 3.36.1 `[9] <https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-3.36.1>`__
@ -576,7 +576,7 @@ Here are the full patch notes:
* ports: expat 2.4.4 `[9] <https://github.com/libexpat/libexpat/blob/R_2_4_4/expat/Changes>`__
* ports: lighttpd 1.4.64 `[10] <https://www.lighttpd.net/2022/1/19/1.4.64/>`__
* ports: monit 5.30.0 `[11] <https://mmonit.com/monit/changes/>`__
* ports: nss 3.75 `[12] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.75_release_notes>`__
* ports: nss 3.75 `[12] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_75.html>`__
* ports: pcre / pcre2 enable JIT support
* ports: phpseclib 2.0.36 `[13] <https://github.com/phpseclib/phpseclib/releases/tag/2.0.36>`__
* ports: strongswan 5.9.5 `[14] <https://github.com/strongswan/strongswan/releases/tag/5.9.5>`__
@ -769,7 +769,7 @@ Here are the full patch notes against version 21.7.7:
* ports: flock 2.37.2
* ports: hostapd 2.10 `[15] <https://w1.fi/cgit/hostap/plain/hostapd/ChangeLog>`__
* ports: lighttpd 1.4.63 `[16] <https://www.lighttpd.net/2021/12/4/1.4.63/>`__
* ports: nss 3.74 `[17] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.74_release_notes>`__
* ports: nss 3.74 `[17] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_74.html>`__
* ports: openssl 1.1.1m `[18] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: openvpn 2.5.5 `[19] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.5>`__
* ports: pecl-psr 1.2.0 `[20] <https://pecl.php.net/package-changelog.php?package=psr&release=1.2.0>`__
@ -875,7 +875,7 @@ Here are the full patch notes:
* src: revert upstream permission change for /root directory
* src: fix kernel build creating wrong linkers.hint file
* ports: hostapd 2.10 `[3] <https://w1.fi/cgit/hostap/plain/hostapd/ChangeLog>`__
* ports: nss 3.74 `[4] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.74_release_notes>`__
* ports: nss 3.74 `[4] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_74.html>`__
* ports: pecl-psr 1.2.0 `[5] <https://pecl.php.net/package-changelog.php?package=psr&release=1.2.0>`__
* ports: pkg fixes validation failures on HTTPS fetch in static binary `[6] <https://cgit.freebsd.org/ports/commit/?id=08342c9812d>`__
* ports: sqlite 3.37.2 `[7] <https://sqlite.org/releaselog/3_37_2.html>`__
@ -1006,7 +1006,7 @@ Here are the full patch notes against 21.7.7:
* ports: filterlog 0.6 `[12] <https://github.com/opnsense/ports/commit/2e27655d84>`__
* ports: flock 2.37.2
* ports: lighttpd 1.4.63 `[13] <https://www.lighttpd.net/2021/12/4/1.4.63/>`__
* ports: nss 3.73.1 `[14] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.73.1_release_notes>`__
* ports: nss 3.73.1 `[14] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_73_1.html>`__
* ports: openssl 1.1.1m `[15] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: openvpn 2.5.5 `[16] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn25#Changesin2.5.5>`__
* ports: phalcon 4.1.3 `[17] <https://github.com/phalcon/cphalcon/releases/tag/v4.1.3>`__

@ -34,6 +34,244 @@ can be found below as well.
* Full mirror list: https://opnsense.org/download/
--------------------------------------------------------------------------
22.7.6 (October 12, 2022)
--------------------------------------------------------------------------
This update fixes CRL code handling with third party software and sandboxes
the code to avoid dealing with boot-time issues ever again. However, due to
the nature of the sandboxing no automatic fix can be made for the following
case:
Creating and using an empty CRL in OpenVPN broke in 22.7.5 due to an ancient
bug not populating the empty CRL in binary format: the side effect "correcting"
this at runtime was removed. 22.7.6 will now correctly populate the binary
format of the empty CRL upon creation in the config.xml as originally intended.
The options to manually fix existing empty CRLs are as follows:
* Remove the CRL from OpenVPN as it is unused anyway, or
* Add a dummy certificate to it to populate the CRL properly, or
* Add and remove a random existing certificate to populate an empty CRL.
These fixes can be carried out on older installation without a problem as well
prior to upgrading to avoid OpenVPN from not working post-upgrade.
Here are the full patch notes:
* system: fix inconsistent is_crl_internal() implementation
* system: make sure we always generate a CRL when saved
* system: sandbox code handling CRL manipulation in the CRL manager page
* system: wrap global product information handling into a singleton
* system: move get_nameservers() to ifctl use
* reporting: traffic graph polling interval selection and UX tweaks
* interfaces: port 6RD/6to4 to ifctl use
* interfaces: optionally use reverse DNS resolution for ARP table hostnames (contributed by soif)
* interfaces: allow user-configurable VLAN device names with certain restrictions `[1] <https://github.com/opnsense/core/issues/6038>`__
* interfaces: small cleanup on get_real_interface()
* firewall: simplify port forward rule logic for delete and toggle and make sure to toggle firewall rule as well
* firewall: various performance and usability improvements in live log
* firewall: extend all firewall rules with a UUID to align with MVC code upon edit
* firmware: display license validity when applicable in business edition
* ipsec: ACL fix for sessions users
* unbound: support setting type value for DNS over TLS/Query Forwarding API (contributed by kulikov-a)
* unbound: convert advanced settings to MVC/API
* mvc: remove "clear all", "copy" and "paste" options when only a single entry is allowed
* mvc: fix typo in searchRecordsetBase()
* ports: isc-dhcp 4.4.3P1 `[2] <https://downloads.isc.org/isc/dhcp/4.4.3-P1/dhcp-4.4.3-P1-RELNOTES>`__
* ports: phalcon 5.0.3 `[3] <https://github.com/phalcon/cphalcon/releases/tag/v5.0.3>`__
* ports: php 8.0.24 `[4] <https://www.php.net/ChangeLog-8.php#8.0.24>`__
* ports: squid no-forgery patch fix
* ports: strongswan 5.9.8 `[5] <https://github.com/strongswan/strongswan/releases/tag/5.9.8>`__
--------------------------------------------------------------------------
22.7.5 (October 05, 2022)
--------------------------------------------------------------------------
Today we are fixing a security issue involving the "installer" user and
kernel-based TCP panics that some have been fighting with since FreeBSD 13.
Some ports and plugins have also been updated now that the holiday season
is coming to its inevitable end.
The security issue arises on fresh 22.7 installs only due to a boot-time
optimization of user account handling since 22.1.8. Users are not reset
on each boot anymore which improved boot times with many users but also made
the "installer" user stick with the default password in this situation.
Physical access to the console with this user was possible under these
conditions even after installation and updates were completed. SSH access
was also possible when both not restricting login to keys and allowing root
login manually. The mandatory reboot after the update to 22.7.5 or higher
remedies this problem.
In a default install the issue could only be exploited by manual console
access. In general we want to advise users not to yield shell/console
access to non-administrators, restrict physical access if applicable, and
not offer SSH access based on user accounts, especially when SSH is accessible
from the WAN side without a VPN.
In any case we recommend all users of 22.7.x to update immediately or
take the necessary precautions to avoid the "installer" user from being
accessed in an unauthorized fashion.
Here are the full patch notes:
* system: remove stray installer account from fresh 22.7 installations
* system: only use withPadding() for RSA based public keys in CRL code
* system: remove unnecessary crl_update() calls in CRL code
* system: extend pool options support in gateway groups
* system: move get_searchdomains() to ifctl use and allow FQDN
* system: add replacement hook for rc.resolv_conf_generate script
* system: replace "dns reload" backend call with portable alternative
* system: remove obsolete rc.resolv_conf_generate script
* system: bring back the buttons action in OpenVPN dashboard widget (contributed by kulikov-a)
* system: assorted cleanups for IXR library used for XMLRPC
* system: catch errors in RSS dashboard widget
* system: stop reading product info from global $g variable in system information dashboard widget
* system: structurally improve boot sequence with regard to hosts/resolv.conf generation
* system: add keyUsage extension and follow RFC on basicConstraints in CA config (contributed by kulikov-a)
* interfaces: migrate wireless creation to legacy_interface_listget()
* firewall: support TOS/DSCP matching in firewall rules
* firewall: add os-firewall alias paths in getAliasSource() to prevent removal when being used
* firewall: get lockout interface from get_primary_interface_from_list()
* firewall: fix PHP 8 error in port forwarding page
* firewall: fix PHP 8 error in aliases (contributed by kulikov-a)
* firewall: parse pftop internal data conversion (contributed by kulikov-a)
* firmware: opnsense-update: return subscription key via -K if it exists
* ipsec: allow to set rightca in mobile phase 1 with EAP-TLS
* ipsec: fix multiple phase 2 IP addresses on the same interface (contributed by Wagner Sartori Junior)
* unbound: account for hostname during PTR creation
* unbound: maintain a consistent dnsbl cache state
* unbound: reduce blocklist read timeout (contributed by kulikov-a)
* web proxy: update pattern to zst for the Arch packages (contributed by gacekjk)
* plugins: os-crowdsec 1.0.1 `[1] <https://github.com/opnsense/plugins/blob/stable/22.7/security/crowdsec/pkg-descr>`__
* plugins: os-ddclient 1.9 `[2] <https://github.com/opnsense/plugins/blob/stable/22.7/dns/ddclient/pkg-descr>`__
* plugins: os-freeradius 1.9.21 `[3] <https://github.com/opnsense/plugins/blob/stable/22.7/net/freeradius/pkg-descr>`__
* plugins: os-nginx 1.30 `[4] <https://github.com/opnsense/plugins/blob/stable/22.7/www/nginx/pkg-descr>`__
* src: ifconfig: print interface name on SIOCIFCREATE2 error
* src: igc: do not start in promiscuous mode by default
* src: tcp: correctly compute the retransmit length for all 64-bit platforms
* src: tcp: fix cwnd restricted SACK retransmission loop
* src: tcp: fix computation of offset
* src: tcp: send ACKs when requested
* ports: dnsmasq 2.87 `[5] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: expat 2.4.9 `[6] <https://github.com/libexpat/libexpat/blob/R_2_4_9/expat/Changes>`__
* ports: lighttpd 1.4.67 `[7] <https://www.lighttpd.net/2022/9/17/1.4.67/>`__
* ports: nss 3.83 `[8] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_83.html>`__
* ports: phalcon 5.0.2 `[9] <https://github.com/phalcon/cphalcon/releases/tag/v5.0.2>`__
* ports: php 8.0.23 `[10] <https://www.php.net/ChangeLog-8.php#8.0.23>`__
* ports: phpseclib 3.0.16 `[11] <https://github.com/phpseclib/phpseclib/releases/tag/3.0.16>`__
* ports: python 3.9.14 `[12] <https://docs.python.org/release/3.9.14/whatsnew/changelog.html>`__
* ports: sqlite 3.39.3 `[13] <https://sqlite.org/releaselog/3_39_3.html>`__
* ports: squid 5.7 `[14] <http://www.squid-cache.org/Versions/v5/squid-5.7-RELEASENOTES.html>`__
* ports: suricata 6.0.8 `[15] <https://suricata.io/2022/09/27/suricata-6-0-7-released/>`__
* ports: unbound 1.16.3 `[16] <https://nlnetlabs.nl/projects/unbound/download/#unbound-1-16-3>`__
--------------------------------------------------------------------------
22.7.4 (September 07, 2022)
--------------------------------------------------------------------------
This update addresses more issues with the somewhat unfortunate phpseclib 3
migration. WAN IPv6 SLAAC mode now works more reliably and TLS 1.3 web GUI
configurations will enforce the expectations by software clients regarding
interoperability.
Last but not least the "assign VLAN parent and enable" migration note from
22.1 is no longer required as the boot will attempt to configure all existing
hardware devices once with the selected defaults.
Here are the full patch notes:
* system: enforce RFC 8446 by requiring TLS_AES_128_GCM_SHA256 for TLS 1.3
* system: consider CRL end dates after 2050 as "lifetime" in GeneralizedTime format
* system: revert the default CRL hashing back to what it was in phpseclib 2
* system: match TLS cipher suites and commands in web GUI settings (contributed by kulikov-a)
* system: improve error message of CRL validation failure (contributed by kulikov-a)
* system: fix phpseclib 3 use for CSR parsing on certificates page
* system: add the default "-c" option to backend pluginctl invokes for consistency
* system: rework console port assignment regarding wireless handling
* interfaces: configure all hardware features for present devices
* interfaces: bring up IPv6 device manually since SLAAC will not do that automatically
* interfaces: merge DHCPv4 / DHCPv6 buttons on overview page (contributed by Maurice Walker)
* interfaces: add support for requesting DNS info via stateless DHCPv6 (contributed by Maurice Walker)
* dnsmasq: restart during "newwanip" event
* ports: curl 7.85.0 `[1] <https://curl.se/changes.html#7_85_0>`__
* ports: libxml 2.10.2 `[2] <http://www.xmlsoft.org/news.html>`__
* ports: sqlite 3.39.2 `[3] <https://sqlite.org/releaselog/3_39_2.html>`__
* ports: syslog-ng 3.38.1 `[4] <https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-3.38.1>`__
--------------------------------------------------------------------------
22.7.3 (September 01, 2022)
--------------------------------------------------------------------------
Pick up the new FreeBSD security advisories while also introducing assorted
reliability improvements. CRL now works again for elliptic curve with the
adoption of version 3 of phpseclib. Wireless handling was improved due to
PHP 8 errors and coding style issues. It is also the subject of further work
for 23.1.
Here are the full patch notes:
* system: migrate CRL handling to phpseclib 3
* system: run monitor reload inside system_routing_configure()
* system: fix IPv6 link-local HTTP_REFERER check (contributed by Maurice Walker)
* system: fix assorted PHP 8 warnings in the codebase
* system: extend nameservers script return for debugging purposes, i.e. "configctl system list nameservers debug"
* system: lighttpd obsoletion of server listing directive, disabled by default
* system: decode stored CRL data before display (contributed by kulikov-a)
* interfaces: update link-local matching pattern
* interfaces: PPP is an exception, only created after interface configuration
* interfaces: only remove known primary addresses in interface_bring_down()
* interfaces: improve shell banner address return in prefix-only IPv6 case
* interfaces: improve problematic <wireless/> node handling
* interfaces: DHCP does not signal RELEASE
* interfaces: web GUI locale sorts files differently when invoking ifctl
* interfaces: improve legacy_interface_listget()
* interfaces: only parse actual options in legacy_interfaces_details(), not nd6 options
* firewall: implement a router file read fallback for new ifctl :slaac suffix
* firewall: stick-address only in effect with pool option and multiple routers
* firewall: remove dead pptpd server code
* captive portal: lighttpd deprecation of legacy SSL options, disabled by default
* dhcp: allow rapid-commit message exchange in IPv6 server (contributed by Maurice Walker)
* firmware: major upgrade "pkgs" set was still unknown to plugin sync
* intrusion detection: fix enable rule button and present active detail overwrite if present
* ipsec: fixed widget link (contributed by Patrik Kernstock)
* unbound: improve FQDN handling when address is moving in DHCP watcher
* unbound: prevent DNS rebinding check and DNSSEC validation on explicit forwarded domains
* unbound: restrict creation of PTR records for both the system domain and host overrides
* unbound: add AAAA-only mode (contributed by Maurice Walker)
* lang: fix syntax errors in French translation (contributed by kulikov-a)
* ui: fix type cast issue in Bootgrid
* plugins: os-ddclient relaxes validation of description field
* plugins: os-frr 1.30 `[1] <https://github.com/opnsense/plugins/blob/stable/22.7/net/frr/pkg-descr>`__
* plugins: os-nginx now uses simplified NAME_setup service handling
* plugins: os-wireguard 1.12 `[2] <https://github.com/opnsense/plugins/blob/stable/22.7/net/wireguard/pkg-descr>`__
* plugins: os-zabbix-agent 1.13 `[3] <https://github.com/opnsense/plugins/blob/stable/22.7/net-mgmt/zabbix-agent/pkg-descr>`__
* plugins: os-zabbix-proxy 1.9 `[4] <https://github.com/opnsense/plugins/blob/stable/22.7/net-mgmt/zabbix-proxy/pkg-descr>`__
* src: rc: improve NAME_setup integration
* src: zlib: fix a bug when getting a gzip header extra field with inflate() `[5] <FREEBSD:FreeBSD-SA-22:13.zlib>`__
* src: tzdata: import tzdata 2022b and 2022c `[6] <FREEBSD:FreeBSD-EN-22:20.tzdata>`__
* ports: ldns 1.8.3 `[7] <https://raw.githubusercontent.com/NLnetLabs/ldns/1.8.3/Changelog>`__
* ports: liblz4 1.9.4
* ports: libxml 2.10.1 `[8] <http://www.xmlsoft.org/news.html>`__
* ports: nss 3.82 `[9] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_82.html>`__
* ports: phpseclib 3.0.14 `[10] <https://github.com/phpseclib/phpseclib/releases/tag/3.0.14>`__
A hotfix release was issued as 22.7.3_2:
* system: work around phpseclib 3 flagging RSA-PSS as an invalid key alogrithm
* system: check for existing X509 class before doing CRL update
--------------------------------------------------------------------------
22.7.2 (August 17, 2022)
--------------------------------------------------------------------------
@ -117,7 +355,7 @@ Here are the full patch notes:
* plugins: os-netdata 1.2 `[5] <https://github.com/opnsense/plugins/blob/stable/22.7/net-mgmt/netdata/pkg-descr>`__
* plugins: os-nginx 1.29 `[6] <https://github.com/opnsense/plugins/blob/stable/22.7/www/nginx/pkg-descr>`__
* ports: libxml 2.9.14 `[7] <http://www.xmlsoft.org/news.html>`__
* ports: nss 3.81 `[8] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.81_release_notes>`__
* ports: nss 3.81 `[8] <https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_81.html>`__
* ports: rrdtool 1.8.0 `[9] <https://github.com/oetiker/rrdtool-1.x/blob/master/CHANGES>`__
* ports: unbound 1.16.2 `[10] <https://nlnetlabs.nl/projects/unbound/download/#unbound-1-6-2>`__

Loading…
Cancel
Save