OpenWrt update 24.10.6 and 25.12.1

A corrective release of the OpenWrt distribution 25.12.1 has been introduced, which is developed for networking devices such as routers, switches, and access points. OpenWrt supports over 2200 devices and offers a build system that simplifies cross-compilation and the creation of custom builds. Such builds allow for the formation of ready-made firmware with the desired set of pre-installed packages, optimized for specific tasks. Ready-made builds have been published for 41 target platforms (the previous branch supported 39 platforms).

Among the changes:

  • Support for Devolo Magic 2 WiFi next, MeshPoint.One, MeshPoint.One, and Cudy M3000 with the Motorcomm YT8821 PHY has been added.
  • Fixes have been made concerning the operation of platforms airoha (EN7581 PCIe), ath79 (TP-Link RE355 v1, RE450 v1/v2), ipq806x (AP3935), lantiq, mediatek (TP-Link BE450), microchipsw (Novarq Tactical 1000), ramips (Keenetic KN-1910), realtek (RTL838x), treewide (Linksys).
  • Support for firmware for the MT7990 controller used in the new MediaTek WiFi 7 chipset has been added to the mt76 driver.
  • The firewall4 package has been prioritized. The firewall package now uses the iptables implementation based on nftables by default (iptables-nft, ip6tables-nft).
  • The apk package manager has been updated to version 3.0.5. The option '--force-reinstall' has been added for reinstalling already installed packages without checking for version changes.
  • Updated versions of Linux kernel 6.12.74, jsonfilter 2026-03-16, libubox 2026-03-13, odhcpd, omcproxy 2026-03-07, procd 2026-03-14, umdns 2026-02-06, and ustream-ssl 2026-03-01.
  • Vulnerabilities have been addressed: two buffer overflows in umdns (CVE-2026-30871, CVE-2026-30872) occurring during the processing of DNS queries (PTR and IPv6 address resolution); memory content leakage in jsonpath (CVE-2026-30873); command execution organization through manipulation of the PATH environment variable in procd (CVE-2026-30874); cross-site scripting in the LuCI web interface; buffer overflows in odhcpd and procd; access to memory after it has been freed in ustream-ssl (OpenSSL variant).

Simultaneously, an update to the previous OpenWrt 24.10.6 branch has been created, which addresses vulnerabilities in umdns, jsonpath, LuCI, and procd, as well as fixes accumulated errors related to hardware support in the mediatek, airoha, ath79, imx, ipq40xx, lantiq, mt7620, ramips, and realtek platforms. Updated versions of Linux kernel 6.6.127, openssl 3.0.19, procd 2026-03-14, umdns 2026-02-06, and wireless-regdb 2026.02.04. The OpenWrt 24.10 branch will be supported until September 2026.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster