• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

ETA on Suricata 7.0.6 ?

Scheduled Pinned Locked Moved IDS/IPS
15 Posts 3 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    btspce
    last edited by Jul 1, 2024, 4:29 PM

    Suricata 7.0.6 was released on June 27 and contains fixes for several CVE's rated high and critical.

    https://suricata.io/2024/06/27/suricata-7-0-6-and-6-0-20-released/

    CVE-2024-37151: CRITICAL (7.0.5 and 6.0.19)
    CVE-2024-38536: HIGH (7.0.5)
    CVE-2024-38534: HIGH (7.0.5)
    CVE-2024-38535: CRITICAL (7.0.5) / MODERATE (6.0.19)

    How far off is an update to 7.0.6 ?

    1 Reply Last reply Reply Quote 2
    • N
      NRgia
      last edited by NRgia Jul 5, 2024, 2:49 PM Jul 5, 2024, 2:48 PM

      This post is deleted!
      1 Reply Last reply Reply Quote 0
      • B
        bmeeks
        last edited by Jul 6, 2024, 10:52 PM

        I have posted Pull Requests containing the update for the Netgate team to review and merge:

        https://github.com/pfsense/FreeBSD-ports/pull/1375
        https://github.com/pfsense/FreeBSD-ports/pull/1376

        You can follow the progress at the two GitHub links provided above (one is for the binary portion and the other for the GUI portion of the package).

        B 1 Reply Last reply Jul 7, 2024, 4:42 PM Reply Quote 1
        • B
          btspce @bmeeks
          last edited by Jul 7, 2024, 4:42 PM

          @bmeeks Thanks!

          1 Reply Last reply Reply Quote 0
          • B
            btspce
            last edited by Jul 17, 2024, 7:16 AM

            Why has this update which contain HIGH and CRITICAL fixes in both 7.0.5 and 7.0.6 not been published to repos yet ?

            N 1 Reply Last reply Jul 17, 2024, 4:30 PM Reply Quote 0
            • N
              NRgia @btspce
              last edited by Jul 17, 2024, 4:30 PM

              @btspce
              Maybe you can find a hint here:

              https://forum.netgate.com/topic/182134/suricata-7-0-0-package-update-for-devel-snapshots-release-notes/11?_=1721233141154

              1 Reply Last reply Reply Quote 0
              • B
                btspce
                last edited by Jul 17, 2024, 5:14 PM

                @NRgia Thanks. Does not sound good at all. Created a ticket with Netgate Support about this.

                N 1 Reply Last reply Jul 17, 2024, 6:03 PM Reply Quote 0
                • N
                  NRgia @btspce
                  last edited by Jul 17, 2024, 6:03 PM

                  @btspce said in ETA on Suricata 7.0.6 ?:

                  @NRgia Thanks. Does not sound good at all. Created a ticket with Netgate Support about this.

                  Please do share, at least on private, on Support's answer. I am using a pfSense+ free license, so no tickets for me. Thank you also.

                  1 Reply Last reply Reply Quote 0
                  • B
                    bmeeks
                    last edited by Jul 17, 2024, 6:09 PM

                    The update I posted for Suricata 7.0.6 will build successfully on the Netgate package builders (at least it does for me). It's a relatively simple matter for their developers with pfSense FreeBSD-ports repo access to pull in and merge the update so the new packages will build.

                    Perhaps the guy that normally does the merging has been away on vacation for a bit ???

                    I sent him an email the same time I posted the update Pull Request notifying him of its presence.

                    B 1 Reply Last reply Jul 17, 2024, 6:16 PM Reply Quote 0
                    • B
                      btspce @bmeeks
                      last edited by Jul 17, 2024, 6:16 PM

                      @bmeeks Thanks!
                      I really hope there is atleast two developers who can fill in for each other at Netgate.

                      B 1 Reply Last reply Jul 17, 2024, 6:22 PM Reply Quote 0
                      • B
                        bmeeks @btspce
                        last edited by Jul 17, 2024, 6:22 PM

                        @btspce said in ETA on Suricata 7.0.6 ?:

                        I really hope there is atleast two developers who can fill in for each other at Netgate.

                        There are, but I think only one or maybe two guys handle the merging of the third-party volunteer package updates. Referring to the link posted earlier by @NRgia you will note in that discussion that the majority of the available pfSense packages are/were maintained by volunteers who are not affiliated with Netgate. As volunteers, they do not have "merge" permissions on the GitHub repos either.

                        In my time maintaining Snort and Suricata, I've worked with only three Netgate developers who merged updates I submitted. Of those three, one has not been with Netgate for many years, the second moved over to TNSR support, and so that leaves me with just the one contact whose email I currently have.

                        1 Reply Last reply Reply Quote 0
                        • B
                          bmeeks
                          last edited by Jul 17, 2024, 6:25 PM

                          Just received a reply to my original email. They will be merging the 7.0.6 update today, so look for new packages soon.

                          B N 2 Replies Last reply Jul 17, 2024, 6:41 PM Reply Quote 0
                          • B
                            btspce @bmeeks
                            last edited by Jul 17, 2024, 6:41 PM

                            @bmeeks Great and thanks for everything you do.

                            I really hope Netgate fixes this situation with merging and communication and realizes the importance of these packages to the end product that is pfsense.

                            We would not be using Netgate firewalls without them.

                            1 Reply Last reply Reply Quote 0
                            • N
                              NRgia @bmeeks
                              last edited by Jul 17, 2024, 6:41 PM

                              @bmeeks said in ETA on Suricata 7.0.6 ?:

                              Just received a reply to my original email. They will be merging the 7.0.6 update today, so look for new packages soon.

                              Thank you

                              1 Reply Last reply Reply Quote 0
                              • B
                                bmeeks
                                last edited by Jul 17, 2024, 11:28 PM

                                The updates for the binary and GUI have been merged and the new v7.0.6 package is available.

                                1 Reply Last reply Reply Quote 1
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                  This community forum collects and processes your personal information.
                                  consent.not_received