I-OpenWrt 23.05.3 sele ikhutshwe, funda malunga nokuphuculwa kwayo okuphawulekayo kunye notshintsho

I-OpenWrt

I-OpenWrt yi-firmware esekwe kwi-Linux yosasazo efakwe kwizixhobo ezifana neerotha zomntu.

Kutshanje, uluntu lwe-OpenWrt lukhutshwe, ngeposti yebhlog, i ukukhululwa kwenguqulelo entsha ezinzileyo ye-OpenWrt series 23.05.3, apho abaphuhlisi basebenze ukuphumeza uthotho lweempucuko ezibalulekileyo kunye neempawu ezintsha eziphucula ukusebenza, kunye nokongeza inkxaso yezixhobo ezitsha kwaye, ngakolunye uhlangothi, kwakhona ukusombulula uluhlu lweempazamo kunye nobuthathaka obufunyenweyo.

Kwabo bangaziyo nge-OpenWrt, ndingakuxelela ukuba oku unikezelo lweLinux, elungiselelwe ukusetyenziswa kunye nezixhobo zenethiwekhi ezinje ngeerotha kunye neendawo zofikelelo. Ixhasa amaqonga ahlukeneyo kunye nezakhiwo, kwaye inenkqubo yokwakha eyenza kube lula ukwenza i-firmware yesiko kunye neepakethe eziyimfuneko ezifakwe ngaphambili kwimisebenzi ethile.

Yintoni entsha kwi-OpenWrt 23.05.3?

Olu guqulelo lutsha lwe-OpenWrt 23.05.3 Ulungiso oluphunyeziweyo lokhuseleko lugqama kakhulu, apho oku kulandelayo kukhankanyiwe ukuba kusonjululwe:

  • I-CVE-2023-36328: Kulungiswe inani elipheleleyo lokuba semngciphekweni wokuphuphuma kwi-mp_grow kwi-libtommath kwi-Dropbear.
  • I-CVE-2023-48795: ukuba sesichengeni kwiprotocol ye-SSH echaphazela iinguqulelo ngaphambi kwe-9.6 ye-OpenSSH kunye nezinye iimveliso. Ivumela abahlaseli abakude ukuba badlule iitshekhi zemfezeko, ezinokukhokelela ekwehliseni umgangatho okanye ukukhubaza iimpawu ezithile zokhuseleko. Lo mbandela uchaphazela iimveliso ze-SSH ezininzi kunye namathala eencwadi, kubandakanya i-OpenSSH, iDropbear, iPuTTY, iParamiko, iWinSCP, phakathi kwabanye. Kuyacetyiswa ukuba kuphuculwe kwiinguqulelo ezikhuselekileyo ukunciphisa lo mngcipheko wokhuseleko.
  • I-CVE-2023-50868: Kusonjululwe umba kwi-dnsmasq evumele ukwaliwa kwenkonzo kude ngeempendulo ze-DNSSEC.
  • I-CVE-2024-0727: Ukuba sesichengeni kwi-OpenSSL xa kusetyenzwa ngeefayile ezikhohlakeleyo ze-PKCS12, ezinokubangela ingozi kunye nokwaliwa kohlaselo lwenkonzo. Ii-aplikeshini ezilayisha iifayile ze-PKCS12 ezivela kwimithombo engathenjwa zinokuyeka ngesiquphe. Kuyacetyiswa ukuba uhlaziye i-OpenSSL ukunciphisa umngcipheko wokhuseleko.

Enye imbalasane yenguqulelo entsha yi inkxaso ephuculweyo kunye nokongezwa kwezixhobo ezitsha, kuba Uzinzo lwe-Ethernet kwi-Orange Pi R1 Plus kunye nezixhobo ezisekelwe kwi-Mediatek MT7981 kunye ne-MT7986 chips, ngelixa izixhobo mpc85xx inyuse i-RAM ekhoyo kwi-Extreme Networks WS-AP3825 kunye nenkxaso eyongeziweyo yezixhobo ezahlukeneyo, kuquka i-UniFi UK-Ultra, ASUS RT-AX59U, Cudy RE3000 v1, TP-Link EAP225v5, phakathi kwabanye.

Kukwagxininiswa ukuba i uninzi lwamalungu ahlaziywa kwi-Linux Kernel version 5.15.150 (kwinguqulelo yangaphambili iKernel esetyenzisiweyo yayiyinguqulo 5.15.137) kunye nohlaziyo lwe-mwlwifi, mt76, netifd, bcm27xx-gpu-fw, mbedtls, openssl, kunye namanye amalungu.

Kwelinye icala, kwi-OpenWrt 23.05.3 Kulungiswe imiba yobuxoki yokuqalisa kwakhona kwizixhobo ezithile, inkxaso ye-hardware efana ne-WPA3 iphuculwe kwaye ukuzinza kwenkqubo jikelele kuye kwaphuculwa.

Olunye utshintsho evelele kule nguqulo intsha:

  • Uphuculo olwenziweyo ukwandisa i-RAM ekhoyo kwezinye izixhobo
  • I-RTC esisigxina ye-IEI-World Puzzle M90x izixhobo
  • Umncedisi we-Dropbear SSH uphucule kakhulu isantya sokudlulisa idatha xa usebenzisa i-scp utility.
  • Ubomi beseshoni ye-AMPDU esisigxina
  • Imiba emiselweyo yemowudi yokubeka iliso kwi-mt76
  • I-Netgear GS110TPP ye-OEM yokuFakela ukulungisa
  • Ukulungisa iTypo kwiipropati ze-spi kwi-Centron CT3003
  • Ukuziphatha kwabalandeli kuphuculwe kwi-mt7981
  • Isusiwe i-kmod-usb2 ye-GL-MT6000
  • Iphakheji ye-mt7981-wo-firmware yenziwe ngokuzenzekelayo
  • Kongezwe iinkcazo zesimo se-LED ezingekhoyo kwi-GL-MT6000
  • Fixed BPI-R3 mac idilesi ye-wifi

Ukuba ufuna ukwazi ngakumbi ngayo malunga neenkcukacha ezidityanisiweyo kolu khululo lutsha lwe-OpenWrt firmware 23.05.3 ungakhangela ulwazi kupapasho loqobo Kule khonkco ilandelayo.

Khuphela inguqulelo entsha ye-OpenWrt 23.05

Ukwakhiwa kwale nguqulo intsha kulungiselelwe amaqonga ama-36 ahlukeneyo, anokufumana kuwo iiphakheji zokuhlaziya kwikhonkco elingezantsi.


Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Inoxanduva lwedatha: I-AB Internet Networks 2008 SL
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.