Release of the distribution kit for creating firewalls OPNsense 26.7

The release of the distribution for creating firewalls OPNsense 26.7 has been published. In 2015, it separated from the pfSense project with the goal of developing a completely open distribution that could have the functionality of commercial solutions for deploying firewalls and network gateways. Unlike pfSense, the project is positioned as not controlled by a single company, developed with the direct participation of the community and having a completely transparent development process, as well as providing the ability to use any of its developments in third-party products, including commercial ones. The source code of the distribution components, as well as the tools used for assembly, are distributed under the BSD license. The assemblies are prepared in the form of LiveCD and a system image for recording on Flash drives (490 MB).

The distribution's core is based on FreeBSD code. OPNsense features include: a fully open source build toolchain, support for installation as packages on top of regular FreeBSD, load balancing tools, a web interface for organizing user connections to the network (Captive portal), connection state tracking mechanisms (stateful firewall based on pf), a bandwidth limiting system, traffic filtering, and creation VPN based on IPsec, OpenVPN and PPTP, integration with LDAP and RADIUS, DDNS (Dynamic DNS) support, a system of visual reports and graphs.

The distribution can be used to create fault-tolerant configurations based on the CARP protocol and allowing a backup node to be launched in addition to the main firewall, which will be automatically synchronized at the configuration level and will take over the load in the event of a failure of the primary node. The administrator is offered a web interface for configuring the firewall, built using the Bootstrap web framework and Phalcon MVC.

Among the changes:

  • The transition to the FreeBSD 15.1 code base has been completed (previously FreeBSD 14.3 was used).
  • Interfaces for configuring firewall rules, assigning network interfaces (separating between LAN and WAN), and managing gateway groups have been migrated to use the MVC framework and are now additionally accessible via the Web API for automating network configuration management.
  • Added a wizard for migrating address translation rules from the old Outbound NAT configuration format to the new format using the Source NAT (SNAT) architecture.
  • Support for DDNS (Dynamic) and automatic allocation of IPv6 prefixes (address blocks) has been added to the KEA DHCP configurator.
  • IPv6 support has been added to the Captive portal.
  • Updated versions OpenVPN 2.7, PHP 8.5, Python 3.13.
  • A critical vulnerability (CVE-2026-57155, severity level 9.9 out of 10) has been fixed. This vulnerability allows an unprivileged user without shell access and limited access to aliases (lists of network and host names) to execute code with root privileges. The vulnerability is caused by a lack of proper checks when processing data from the GeoIP database with country bindings. IP addresses.

    The country code from the GeoIP database was substituted without verification when generating the file name being written, allowing any file in the system to be overwritten, as the handler runs with root privileges. An unprivileged user could use the Web API to specify a URL to download a modified GeoIP database for aliases. To obtain root privileges, one could specify "../../../../../../../../etc/newsyslog.conf.d/zzz_pwn" instead of the country code in one of the database entries. This would create a configuration file for the log rotation system, which could define commands run with root privileges.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster