OpenWrt 25.12.3

On May 7, OpenWrt 25.12.3 was released – an operating system based on the Linux kernel designed for embedded devices.

Security fixes:

  • Linux kernel: vulnerability fixed CVE-2026-31431 ("Copy Fail"). In previous releases, this affected only users of the StarFive platform and those who had the kmod-crypto-user module installed.
  • mbedtls: updated to version 3.6.6 (fixes for several CVEs).
  • OpenSSL: updated to version 3.5.6 (fixes for several CVEs).
  • wolfSSL: updated to version 5.9.1 (fixes for several CVEs).

Support for new devices:

  • MediaTek Filogic
    • ASUS RT-AX52 PRO
    • D-Link AQUILA PRO AI E30
    • Huasifei WH3000 Pro (NAND variant)
    • Keenetic KAP-630 / Netcraze NAP-630
    • Zbtlink ZBT-Z8106AX-T
    • Zyxel WX5600-T0
  • ramips
    • mt7621: EDUP EP-RT2983
    • mt76x8: Cudy LT300 v3
  • x86
    • DFI ADN553
    • DFI ASL553

Update of core components:

  • Linux kernel: updated from 6.12.74 to 6.12.85.
  • ca-certificates: updated from 20250419 to 20260223.
  • linux-firmware: updated from 20251125 to 20260221.
  • mbedtls: updated from 3.6.5 to 3.6.6.
  • OpenSSL: updated from 3.5.5 to 3.5.6.
  • wireless-regdb: updated from 2026.02.04 to 2026.03.18.
  • wolfSSL: updated from 5.8.4 to 5.9.1.
  • xdp-tools: updated from 1.4.3 to 1.6.3.

Known issues:

  • Zyxel EX5601-T0: WAN interface was renamed from eth1 to wan – please check and update your network settings after the update.
  • Issues are observed when connecting to Wi-Fi 6 access points with WPA3 protection using Pixel 10.
  • 802.11r Fast Transition (FT): causes connection issues for some Wi-Fi clients when using WPA3.
  • SQM CAKE MQ (cake_mq): throughput may be unexpectedly low in some configurations after scheduler fixes in this release.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster