ETA on Suricata 7.0.6 ?
-
Suricata 7.0.6 was released on June 27 and contains fixes for several CVE's rated high and critical.
https://suricata.io/2024/06/27/suricata-7-0-6-and-6-0-20-released/
CVE-2024-37151: CRITICAL (7.0.5 and 6.0.19)
CVE-2024-38536: HIGH (7.0.5)
CVE-2024-38534: HIGH (7.0.5)
CVE-2024-38535: CRITICAL (7.0.5) / MODERATE (6.0.19)How far off is an update to 7.0.6 ?
-
This post is deleted! -
I have posted Pull Requests containing the update for the Netgate team to review and merge:
https://github.com/pfsense/FreeBSD-ports/pull/1375
https://github.com/pfsense/FreeBSD-ports/pull/1376You can follow the progress at the two GitHub links provided above (one is for the binary portion and the other for the GUI portion of the package).
-
@bmeeks Thanks!
-
Why has this update which contain HIGH and CRITICAL fixes in both 7.0.5 and 7.0.6 not been published to repos yet ?
-
@btspce
Maybe you can find a hint here: -
@NRgia Thanks. Does not sound good at all. Created a ticket with Netgate Support about this.
-
@btspce said in ETA on Suricata 7.0.6 ?:
@NRgia Thanks. Does not sound good at all. Created a ticket with Netgate Support about this.
Please do share, at least on private, on Support's answer. I am using a pfSense+ free license, so no tickets for me. Thank you also.
-
The update I posted for Suricata 7.0.6 will build successfully on the Netgate package builders (at least it does for me). It's a relatively simple matter for their developers with pfSense FreeBSD-ports repo access to pull in and merge the update so the new packages will build.
Perhaps the guy that normally does the merging has been away on vacation for a bit ???
I sent him an email the same time I posted the update Pull Request notifying him of its presence.
-
@bmeeks Thanks!
I really hope there is atleast two developers who can fill in for each other at Netgate. -
@btspce said in ETA on Suricata 7.0.6 ?:
I really hope there is atleast two developers who can fill in for each other at Netgate.
There are, but I think only one or maybe two guys handle the merging of the third-party volunteer package updates. Referring to the link posted earlier by @NRgia you will note in that discussion that the majority of the available pfSense packages are/were maintained by volunteers who are not affiliated with Netgate. As volunteers, they do not have "merge" permissions on the GitHub repos either.
In my time maintaining Snort and Suricata, I've worked with only three Netgate developers who merged updates I submitted. Of those three, one has not been with Netgate for many years, the second moved over to TNSR support, and so that leaves me with just the one contact whose email I currently have.
-
Just received a reply to my original email. They will be merging the 7.0.6 update today, so look for new packages soon.
-
@bmeeks Great and thanks for everything you do.
I really hope Netgate fixes this situation with merging and communication and realizes the importance of these packages to the end product that is pfsense.
We would not be using Netgate firewalls without them.
-
@bmeeks said in ETA on Suricata 7.0.6 ?:
Just received a reply to my original email. They will be merging the 7.0.6 update today, so look for new packages soon.
Thank you
-
The updates for the binary and GUI have been merged and the new v7.0.6 package is available.