26.07 New Features and Changes¶
This is a regularly scheduled software release including new features and bug fixes.
Tip
Review the Upgrade Guide before performing any upgrade of pfSense software.
Netgate Nexus¶
This release contains new features exclusive to Netgate Nexus: CoreDNS, ThreatGate, and Snort 3.
- CoreDNS
CoreDNS is an integrated component of Netgate Nexus which handles DNS-based tasks with extremely high performance. This component is based on the CoreDNS Project, but the functionality in Netgate Nexus is primarily focused on a new and exclusive CoreDNS plugin created by Netgate called rexdns.
- ThreatGate
ThreatGate is an integrated component of Netgate Nexus which manages bulk lists of addresses and domains for use with firewall rules, aliases, and CoreDNS groups with high performance. ThreatGate collects addresses from internal and remote feeds and can block them entirely or allow administrators to build their own rules based on the content.
ThreatGate and CoreDNS were designed to integrate together and this allows them to quickly process and utilize huge lists of addresses even on small devices with low resources.
- Snort 3
Snort version 3 is a new version of the popular open-source intrusion prevention system (IPS). It features a GUI redesigned from the ground-up, multi-threading support, and a faster rule syntax. Snort 3 is now available exclusively via the new Netgate Nexus controller GUI.
Security / Errata¶
pfSense Software¶
pfSense-SA-26_06.webgui - Potential authenticated command execution via CR/LF in System Proxy settings #16898
pfSense-SA-26_07.webgui - Potential command execution via CR/LF in OpenVPN settings #16899
pfSense-SA-26_08.webgui - Potential stored XSS in
browser.phpused bydiag_edit.php#16918pfSense-SA-26_09.packages Potential stored XSS in
status_monitoring.phpvia saved views #16920pfSense-SA-26_10.webgui - Potential XSS via inline Firewall Log rule descriptions #16923
pfSense-SA-26_11.webgui - Potential stored XSS via Firewall Schedules #16924
pfSense-SA-26_12.webgui - Potential XSS in DHCPv4 Pool Descriptions #16940
pfSense-SA-26_13.webgui - Potential XSS in DHCPv6 Pool Descriptions #16941
pfSense-SA-26_14.webgui - Potential XSS via IPsec Phase 1 descriptions while editing Phase 2 entries #16942
pfSense-SA-26_15.webgui - Potential XSS in PPP instance Provider and Plan fields #16943
pfSense-SA-26_16.webgui - Potential XSS in Dynamic DNS widget display of Custom and RFC2136 entries #16944
pfSense-SA-26_17.webgui - Potential XSS via URL Table Ports Alias content #16945
pfSense-SA-26_18.webgui - Potential Local File Include vulnerability via Dashboard widget sequence data #16947
pfSense-SA-26_19.webgui - Potential information disclosure during configuration encryption and decryption operations #16958
pfSense-SA-26_20.webgui - Potential authenticated arbitrary command execution via Kea custom JSON configuration #16960
pfSense-SA-26_21.webgui - Potential XSS in Traffic Graphs Display option #16976 #16979
Upstream¶
Several security and errata fixes were merged from FreeBSD, including fixes for vulnerabilities discovered in WireGuard.
Several base system packages were updated to address various upstream security issues.
pfSense Plus¶
Changes in this version of pfSense Plus software.
Aliases / Tables¶
Captive Portal¶
Fixed: Captive Portal authentication failures from usernames containing special characters or long strings can cause ambiguous or confusing log messages #16922
Configuration Backend¶
Changed: Improve handling of OpenSSL encryption passphrase #16958
DHCP (IPv4)¶
Added: Option to control Kea log level #16230
Changed: Kea attempts DNS Registration when Unbound is disabled #16865
Fixed: Daemon configuration manipulation via CR/LF in ISC DHCP settings #16900
Fixed: Potential XSS in DHCPv4 Pool Descriptions #16940
Added: Kea Custom Configuration JSON privilege #16960
Fixed: Daemon configuration manipulation via CR/LF in ISC DHCP numbered option settings #16962
DHCP (IPv6)¶
Fixed: Potential XSS in DHCPv6 Pool Descriptions #16941
DHCP Relay¶
Fixed: DHCP relay does not respect configured CARP VIP status #15017
DNS Resolver¶
Fixed: Unbound configuration may be generated with duplicate interface bindings #16906
Dashboard¶
Diagnostics¶
Dynamic DNS¶
Gateway Monitoring¶
Changed: Improve gateway status consistency #16707
Gateways¶
IPsec¶
IPv6 Router Advertisements (radvd/rtsold)¶
Fixed: IPv6 Track Interfaces ignores the
DisabledRouter Advertisements mode #16925
Interfaces¶
Logging¶
Fixed: Potential XSS via inline Firewall Log rule descriptions #16923
OpenVPN¶
Operating System¶
PPP Interfaces¶
Fixed: Potential XSS in PPP instance Provider and Plan fields #16943
Package System¶
Fixed: Error updating repository metadata at boot with certain packages installed #16784
RRD Graphs¶
Fixed: Multiple
updaterrd.shprocesses #16927
Rules / NAT¶
Fixed: Cannot add Port Forward with an unassociated filter rule #15346
Fixed: Same port forward on multiple WANs can generate a PF error due to Pure NAT mode NAT reflection #16783
Changed: Retain a copy of the failed ruleset when a filter reload fails #16796
Fixed: Potential stored XSS via Firewall Schedules #16924
Fixed: Filter rules created as part of NAT rules can have an invalid protocol value #16954
SNMP¶
System Logs¶
Changed: Exclude nginx logs from
system.log#16826
Traffic Graphs¶
Traffic Shaper (ALTQ)¶
Fixed: Traffic Shaper Wizard duplicates all firewall rules when no shaping options are enabled #16866
Wake on LAN¶
Changed: “Wake All” functionality on
services_wol.phpshould only use POST #16961
Web Interface¶
Fixed: Potential command execution via CR/LF in System Proxy settings #16898
Wireless¶
Fixed: Interfaces Status shows an invalid SSID value for Wi-Fi interfaces #16769