OPNsense 24.1.8 Bugfix Release

Die Community Edition der OPNSense erhielt das Bugfix Release 24.1.8. Neben eine neue Kernel Version wurde der Endlosloop im DHCRelay Daemon gefixt, sowie weitere kleinere Fehler behoben. Als Ankündigung teilen die Entwickler mit, dass OPNsense 24.7 auf FreeBSD 14.1 basieren wird, weitere Infos folgen. Ein Reboot wird durchgeführt.

OPNsense 24.1.8 Release Notes

  • system: fix regression in gateways migration causing far gateway option to be set incorrectly
  • system: work around fatal password_hash() change in PHP 8.2.18
  • system: move net.inet.icmp.drop_redirect sysctl to automatic mode
  • system: add Google Drive configuration as an XMLRPC sync target
  • interfaces: detect and ignore “detached” state for IPv6
  • interfaces: remove unused imports from sockstat list
  • firewall: use the new $.replaceInputWithSelector() for source/destination networks in MVC filter pages
  • firewall: fix empty rule label rendered as “null” on sessions page
  • ipsec: fix faulty “-” usage in URIs
  • isc-dhcp: take into account that multple ia-pd can be delegated
  • kea-dhcp: simplified the controller code
  • unbound: change blocklist processing in _blocklist_reader()
  • unbound: allow RFC 2181 compatible names in query forwarding
  • mvc: silence spurious validation message when explicitly asked to ignore them
  • ui: prevent vertical modal overflows and instead present a scrollbar
  • ui: add $.replaceInputWithSelector() action
  • ui: handle static page CSRF without Phalcon
  • plugins: os-caddy 1.5.6[1]
  • src: pfsync: fix use of invalidated stack variable
  • src: pfsync: cope with multiple pending plus messages
  • src: ipfw: skip to the start of the loop when following a keep-state rule
  • src: bridge: use IF_MINMTU
  • src: bridge: change MTU for new members
  • src: ethernet: support ARP for 802 networks
  • src: ethernet: fix logging of frame length
  • src: debugnet: fix logging of frame length
  • src: wg: use ENETUNREACH when transmitting to a non-existent peer
  • src: fib_algo: lower level of algorithm switching messages to LOG_INFO
  • src: libpfctl: fix incorrect pcounters array size
  • src: pf: always mark states as unlinked before detaching them
  • src: vxlan: add checking for loops and nesting of tunnels
  • src: igc: increase default per-queue interrupt rate to 20000
  • ports: dhcrelay 0.5 fixes endless loop on packet read
  • ports: hyperscan 5.4.2[2]
  • ports: libxml 2.11.8[3]
  • ports: ntp 4.2.8p18[4]
  • ports: openssl fix for CVE-2024-4603
  • ports: phalcon 5.7.0[5]
  • ports: py-duckdb 0.10.3[6]

