Release of the OPNsense 26.7 distribution for building firewalls

The release of the OPNsense 26.7 firewall distribution has been published. This project separated from pfSense in 2015 with the goal of developing a fully open distribution that could have commercial-level functionality for deploying firewalls and network gateways. Unlike pfSense, the project is positioned as independent of any single company, developed with direct community involvement, and has a completely transparent development process. It also allows the use of any of its developments in third-party products, including commercial ones. The source texts of the distribution components, as well as the tools used for assembly, are distributed under the BSD license. The builds are provided in the form of LiveCD and an image for writing to Flash drives (490 MB).

The distribution is based on the FreeBSD code. Among the features of OPNsense are: a fully open build toolset, support for package installation on top of regular FreeBSD, load balancing tools, a web interface for user network connection management (Captive portal), stateful firewall mechanisms based on pf, bandwidth limiting, traffic filtering, and more. VPN based on IPsec, OpenVPN, and PPTP, LDAP and RADIUS integration, DDNS (Dynamic DNS) support, and a system of visual reports and charts.

The distribution can be used to create high-availability configurations based on the CARP protocol, allowing the launch of a standby node alongside the main firewall that will automatically synchronize at the configuration level and take over the load in case of a primary node failure. A web interface for configuring the firewall is offered to the administrator, built using the Bootstrap web framework and Phalcon MVC.

Among the changes:

  • A transition to the FreeBSD 15.1 codebase has been made (previously used FreeBSD 14.3).
  • The interfaces for configuring firewall rules, assigning network interfaces (separating LAN and WAN), and managing gateway groups have been updated to use the MVC framework and are now additionally available through a Web API for automating network configuration management.
  • A wizard has been added to migrate address translation rules from the old Outbound NAT configuration format to the new format using Source NAT (SNAT) architecture.
  • The KEA DHCP configurator now supports DDNS (Dynamic) and automatic allocation of IPv6 prefixes (address blocks).
  • Support for IPv6 has been added to the Captive portal.
  • Updated versions of OpenVPN 2.7, PHP 8.5, and Python 3.13.
  • A critical vulnerability (CVE-2026-57155, severity 9.9 out of 10) has been fixed, which allowed an unprivileged user without shell access and with limited access to aliases (lists of network and host names) to execute code with root rights. The vulnerability was caused by the lack of proper checks when processing data from the GeoIP database regarding country bindings. IP addresses.

    The country code from the GeoIP database was inserted without verification when forming the filename, allowing any file on the system to be overwritten since the handler runs with root privileges. Through the Web API, an unprivileged user could specify their URL to upload a modified GeoIP database for aliases. To gain root rights, one of the entries in the database could contain "..\/..\/..\/..\/..\/..\/..\/..\/etc\/newsyslog.conf.d\/zzz_pwn" instead of the country code, which would lead to the creation of a configuration file for the log rotation system, in which commands can be defined to run with root privileges.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster