Skip to content

Bump OpenWrt to 19.07.8#31

Open
gaby wants to merge 1 commit into
oofnikj:masterfrom
gaby:bump-version
Open

Bump OpenWrt to 19.07.8#31
gaby wants to merge 1 commit into
oofnikj:masterfrom
gaby:bump-version

Conversation

@gaby
Copy link
Copy Markdown

@gaby gaby commented Oct 23, 2021

  • Update OpenWrt to latest 19.07 release
  • Merge some of the layers in the Docker image.

Major security fixes with this release:

Security fixes

  • Fix FragAttacks (fragmentation and aggregation attacks) vulnerabilities in cfg80211, mac80211, ath10k and ath10k-ct
  • We are not sure if some closed source firmware files are still affected by these problems.
  • Security Advisory 2021-08-01-1 - XSS via missing input validation of host names displayed (CVE-2021-32019) 19
  • Security Advisory 2021-08-01-2 - Stored XSS in hostname UCI variable (CVE-2021-33425) 9
  • Security Advisory 2021-08-01-3 - luci-app-ddns: Multiple authenticated RCEs (CVE-2021-28961) 11

Release notes: https://forum.openwrt.org/t/openwrt-19-07-8-service-release/103208

@gaby
Copy link
Copy Markdown
Author

gaby commented Oct 23, 2021

@oofnikj Friendly bump

@gaby
Copy link
Copy Markdown
Author

gaby commented Oct 23, 2021

Once this PR is merge, a separate PR can be created to upgrade to 21.02.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant