Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Frequency of security updates

    Scheduled Pinned Locked Moved General pfSense Questions
    16 Posts 8 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jarhead @DominikHoffmann
      last edited by

      @dominikhoffmann Security holes in what? It would depend on that.

      1 Reply Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @DominikHoffmann
        last edited by

        @dominikhoffmann depends on what the security threat is and how it impacts the security profile of a device. So for pfsense which CVE do you think is problematic and why?

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        D 1 Reply Last reply Reply Quote 0
        • AndyRHA
          AndyRH
          last edited by

          Have you looked at System_Patches? I believe this is where you would find single issue patches that have not been deemed critical.
          It is not uncommon for single use systems to require few patches. I have a number of systems at work that only need patching 1 or 2 times a year.

          o||||o
          7100-1u

          M 1 Reply Last reply Reply Quote 1
          • M
            michmoor LAYER 8 Rebel Alliance @AndyRH
            last edited by

            @andyrh yep. i will even go as far as saying the Palo Alto systems we have at work do not get updated frequently. There needs to be very specific mitigation solved with an update otherwise there is no downtime.
            Each org is different of course but regardless if there are a ton of updates available or there is none, it really all depends on what is the impact.
            Typically the reason ive been doing upgrades is that the OS version is no longer supported.

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            N 1 Reply Last reply Reply Quote 0
            • N
              nimrod @michmoor
              last edited by

              AFAIK there are no critical issues remaining in any current versions of pfSense. This is why we are jumping from v2.6.0 straight to v2.7.0.

              In the past, when critical CVE gets patched, version number gets updated as well. For example. We had pfSense v2.5.1 and v2.5.2 before major release of pfSense v2.6.0.

              1 Reply Last reply Reply Quote 0
              • D
                DominikHoffmann @michmoor
                last edited by

                @michmoor said in Frequency of security updates:

                So for pfsense which CVE do you think is problematic and why?

                None in particular. I was merely trying to get a sense of how often pfSense gets updated. I did not really know that since June there haven’t been any CVEs discovered in pfSense.

                1 Reply Last reply Reply Quote 0
                • joshgreyzJ
                  joshgreyz @DominikHoffmann
                  last edited by

                  @dominikhoffmann I have the same question since I see my pfSense CE 2.6.0 was released 1 year ago on Jan 31, 2022 and there have been 3 releases of pfSense Plus (23.0, 22.05.1, 22.05) in that time period [corresponding to May 2022 and January 2023).

                  S D 2 Replies Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @joshgreyz
                    last edited by

                    @joshgreyz 23.01 isn't out yet so if you're going to count that, you might as well count 2.7. 😉 It'll be out shortly afterward.

                    23.01 does have release notes which don't mention new security updates.

                    There is also https://www.netgate.com/security showing the last announced issue was over a year ago.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    joshgreyzJ 1 Reply Last reply Reply Quote 0
                    • joshgreyzJ
                      joshgreyz @SteveITS
                      last edited by

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • D
                        DominikHoffmann @joshgreyz
                        last edited by

                        @joshgreyz: Are you aware of the ability to upgrade your Community Edition to pfSense+?

                        joshgreyzJ 1 Reply Last reply Reply Quote 1
                        • joshgreyzJ
                          joshgreyz @DominikHoffmann
                          last edited by

                          @DominikHoffmann that doesn't negate the fact the CE has practicly been abandoned -- there's a new plus release 23.05 which just got released and crickets when it comes to CE 2.7.0...

                          AndyRHA 1 Reply Last reply Reply Quote 0
                          • AndyRHA
                            AndyRH @joshgreyz
                            last edited by

                            @joshgreyz When the split was announced I suspected this would happen.

                            I believe the intent was to keep CE and + more or less equally updated with a divergence in "advanced" features. At the time I guessed that the cost would make the CE updates occur slower over time.
                            I made the move to Netgate HW, in my case I got a deal on used HW.

                            o||||o
                            7100-1u

                            joshgreyzJ 1 Reply Last reply Reply Quote 0
                            • joshgreyzJ
                              joshgreyz @AndyRH
                              last edited by joshgreyz

                              @AndyRH Netgate maintains this list of security advisories against pfSense and we see that since CE 2.6.0 was released more than a year ago on Jan 31, 2022, that the following known security issues still exist in CE 2.6.0:

                              Advisory Name

                              Announced

                              Last Updated

                              pfSense-SA-23_07.kernel

                              2023-05-11

                              pfSense-SA-23_06.webgui

                              2023-05-11

                              pfSense-SA-23_05.sshguard

                              2023-02-15

                              pfSense-SA-23_04.webgui

                              2023-02-15

                              pfSense-SA-23_03.webgui

                              2023-02-15

                              pfSense-SA-23_02.webgui

                              2023-02-15

                              pfSense-SA-23_01.webgui

                              2023-02-15

                              pfSense-SA-22_05.webgui

                              2023-02-15

                              pfSense-SA-22_04.webgui

                              2022-01-25

                              2022-03-08

                              pfSense-SA-22_03.webgui

                              2022-01-13

                              2022-03-08

                              pfSense-SA-22_02.webgui

                              2022-01-12

                              2022-03-08

                              pfSense-SA-22_01.webgui

                              2022-01-12

                              2022-03-08

                              pfSense-SA-21_02.captiveportal

                              2021-04-22

                              2022-03-08

                              *** This is very concerning ***

                              S 1 Reply Last reply Reply Quote 0
                              • S
                                SteveITS Galactic Empire @joshgreyz
                                last edited by

                                @joshgreyz Patches that apply to 2.6 are available via the System Patches package.
                                https://docs.netgate.com/pfsense/en/latest/releases/23-05.html#security
                                b761856c-a65a-4e82-81ea-372178bc94bc-image.png

                                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                Upvote 👍 helpful posts!

                                1 Reply Last reply Reply Quote 4
                                • Dobby_D
                                  Dobby_
                                  last edited by

                                  For the system (OS) FreeBSD

                                  • it comes from the FreeBSD team
                                    fixes and updates or upgrades

                                  For the pfSense itself there will be more options;

                                  • pfSense-upgrade or option (13) in console
                                  • pkg update or upgrade
                                    for the entire pkg`s such snort, suricata,....
                                  • Patch system inside of pfSense
                                    Recommended or custom patches option
                                  • Package maintainers can fix something
                                    Available over the pkg system (updates)

                                  What more is needed or flat Who is offering
                                  more options? Or otherwise wich options are
                                  beloved to see or have here on top?

                                  pfSense 23.05 release (latest)
                                  123-23.05 release vuln. latest.jpg

                                  pfSense 2.7 Devel (latest)
                                  123-2.7 devel vuln. latest.jpg

                                  You see in 2.6 CE much patches are available and also recommended, but in 2.7 not anymore, because they are fleeting in that code of the
                                  new 2.7 CE version.

                                  In 23.05 Release where things also solved out
                                  and during the installation it was also updating / upgrading the squid & SquidGuard package I
                                  was reading something about, automatically!

                                  And by side it is not really a point to find a vuln.
                                  anywhere inside, it must be also able to use in the
                                  used or installed software and does then also affect things or functions where it can be used.
                                  This is not even present and able to use for others
                                  and the software. For sure it may be also a thing
                                  how things will be implemented, but if I personally trust not the coder of my firewall software, who should I trust then? And this is
                                  the other point on the other end of the line.

                                  #~. @Dobby

                                  Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                                  PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                                  PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.