From hauke at hauke-m.de Mon May 1 14:45:46 2023 From: hauke at hauke-m.de (Hauke Mehrtens) Date: Mon, 1 May 2023 23:45:46 +0200 Subject: OpenWrt 21.02.7 seventh service release Message-ID: Hi, The OpenWrt community is proud to announce the newest stable release of the OpenWrt 21.02 stable version series. It fixes security issues and brings a bug fix. Download firmware images using the OpenWrt Firmware Selector: * https://firmware-selector.openwrt.org/?version=21.02.7 Download firmware images directly from our download servers: * https://downloads.openwrt.org/releases/21.02.7/targets/ The OpenWrt 21.02 stable series is now end of life following the OpenWrt Security support guidelines. We encourage all users of the OpenWrt 21.02 stable series to upgrade to OpenWrt 22.03. We will not fix any security problems, even severe ones in the OpenWrt 21.02 release branch any more. https://openwrt.org/docs/guide-developer/security#support_status Main changes between OpenWrt 21.02.6 and OpenWrt 21.02.7: ======================================================== Security fixes ============== * CVE-2023-0464: openssl: Excessive Resource Usage Verifying X.509 Policy Constraints * CVE-2023-0465: openssl: Invalid certificate policies in leaf certificates are silently ignored Device support ============== * None Various fixes and improvements ============================== * Fix UBI (Unsorted Block Images) bug which prevented some devices from booting Core components =============== * Update uclient from 2021-05-14 to 2023-04-13 ----------------- Full release notes and upgrade instructions are available at https://openwrt.org/releases/21.02/notes-21.02.7 In particular, make sure to read the regressions and known issues before upgrading: https://openwrt.org/releases/21.02/notes-21.02.7#known_issues For a detailed list of all changes since 21.02.6, refer to https://openwrt.org/releases/21.02/changelog-21.02.7 To download the 21.02.7 images, navigate to: https://downloads.openwrt.org/releases/21.02.7/targets/ Use OpenWrt Firmware Selector to download: https://firmware-selector.openwrt.org/?version=21.02.7 As always, a big thank you goes to all our active package maintainers, testers, documenters and supporters. Have fun! The OpenWrt Community --- To stay informed of new OpenWrt releases and security advisories, there are new channels available: * a low-volume mailing list for important announcements: https://lists.openwrt.org/mailman/listinfo/openwrt-announce * a dedicated "announcements" section in the forum: https://forum.openwrt.org/c/announcements/14 * other announcement channels (such as RSS feeds) might be added in the future, they will be listed at https://openwrt.org/contact -------------- next part -------------- A non-text attachment was scrubbed... Name: OpenPGP_0x93DD20630910B515.asc Type: application/pgp-keys Size: 15497 bytes Desc: OpenPGP public key URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: OpenPGP_signature Type: application/pgp-signature Size: 488 bytes Desc: OpenPGP digital signature URL: From hauke at hauke-m.de Mon May 1 14:46:07 2023 From: hauke at hauke-m.de (Hauke Mehrtens) Date: Mon, 1 May 2023 23:46:07 +0200 Subject: OpenWrt 22.03.5 fifth service release Message-ID: <798ea680-b640-e101-171d-aa63d3f251e0@hauke-m.de> Hi, The OpenWrt community is proud to announce the newest stable release of the OpenWrt 22.03 stable version series. It fixes security issues, improves device support, and brings a few bug fixes. Download firmware images using the OpenWrt Firmware Selector: * https://firmware-selector.openwrt.org/?version=22.03.5 Download firmware images directly from our download servers: * https://downloads.openwrt.org/releases/22.03.5/targets/ Main changes between OpenWrt 22.03.4 and OpenWrt 22.03.5: ======================================================== Security fixes ============== * CVE-2023-0464: openssl: Excessive Resource Usage Verifying X.509 Policy Constraints * CVE-2023-0465: openssl: Invalid certificate policies in leaf certificates are silently ignored Device support ============== * Archer AX23 / MR70X: Reduce SPI-frequency * Aruba AP-105: Create APBoot compatible image * Buffalo WSR-600DHP: Fix boot loop Various fixes and improvements ============================== * Fix UBI (Unsorted Block Images) bug which prevented some devices from booting * Fix ccache compile with GCC 13 Core components update ====================== * Update uclient from 2021-05-14 to 2023-04-13 ----------------- Full release notes and upgrade instructions are available at https://openwrt.org/releases/22.03/notes-22.03.5 In particular, make sure to read the regressions and known issues before upgrading: https://openwrt.org/releases/22.03/notes-22.03.5#known_issues For a detailed list of all changes since 22.03.4, refer to https://openwrt.org/releases/22.03/changelog-22.03.5 To download the 22.03.5 images, navigate to: https://downloads.openwrt.org/releases/22.03.5/targets/ Use OpenWrt Firmware Selector to download: https://firmware-selector.openwrt.org/?version=22.03.5 As always, a big thank you goes to all our active package maintainers, testers, documenters and supporters. Have fun! The OpenWrt Community --- To stay informed of new OpenWrt releases and security advisories, there are new channels available: * a low-volume mailing list for important announcements: https://lists.openwrt.org/mailman/listinfo/openwrt-announce * a dedicated "announcements" section in the forum: https://forum.openwrt.org/c/announcements/14 * other announcement channels (such as RSS feeds) might be added in the future, they will be listed at https://openwrt.org/contact -------------- next part -------------- A non-text attachment was scrubbed... Name: OpenPGP_0x93DD20630910B515.asc Type: application/pgp-keys Size: 15497 bytes Desc: OpenPGP public key URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: OpenPGP_signature Type: application/pgp-signature Size: 488 bytes Desc: OpenPGP digital signature URL: