OpenWrt 25.12.5 Changelog

This changelog lists all commits done in OpenWrt since the v25.12.4 tag, grouped by subsystem. The changes are chronologically ordered from top to bottom and cover the Git repository history until the tagging of the 25.12.5 release.

See also the release notes that provide a more accessible overview of the main changes in 25.12.5.

78c88ce image: fix per device targz rootfs wrong suffix and redundant images (+5,-1)
e6c934d build: derive PKG_SOURCE_DATE_EPOCH from the unpacked source tree (+7,-8)
8e7ae1b build: set max-page-size linker flag to match target page size (+9)
79b008a build: fixup version.date creation for source archives (+2,-1)
ded2716 kernel: split nf-nathelper-extra into individual packages (+175,-33)

3b15a20 firmware-utils: update to Git HEAD (2026-03-05) (+3,-3)
46f373b tplink-safeloader: add support for TP-Link Archer AX21 v4.6 (+48)
7324b0b tplink-safeloader: fix segfault when partition name is NULL (+1,-1)
7593018 asusuimage: Cleanup code and fix typo (+36,-19)
caac8b1 tplink-safeloader: fix soft_ver for Archer AX21 (+1,-1)
c0d7de8 ptgen: fix bug caused by not completely correct reverts (+1,-1)
5b6ef84 ptgen: allow to specify index of gpt entries to be used (+40,-13)
4676852 ptgen: add an option to disable stub partition creation (+7,-3)
a2c06c3 ptgen: add long option support (+63,-5)
6a87eaf ptgen: add support for marking multiple partitions as bootable (+11,-3)
d37c4b8 tools: util-linux: update to 2.41.5 (+3,-3)

084cdac toolchain: musl: backport patches with CVE fixes (+481,-9)

797171a kernel: bump 6.12 to 6.12.88 (+26,-26)
ddcf755 kernel: bump 6.12 to 6.12.89 (+2,-2)
0eaee44 kernel: bump 6.12 to 6.12.90 (+58,-42)
9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)
949487e kernel: bump 6.12 to 6.12.92 (+16,-1.7K)
3f59bc0 kernel: bump 6.12 to 6.12.93 (+49,-103)
6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)
f191b85 leds: add "network" LED trigger (lan/wan/wlan) (+1.2K,-3)
11a2371 rtl8367b: fix RTL8367S-VB vlan mc memory handling (+6,-1)
ded2716 kernel: split nf-nathelper-extra into individual packages (+175,-33)

8e751e9 uboot-airoha: rename FIP_COMPRESS to LZMA_COMPRESS (+5,-5)
887f21e airoha: an7581: add uboot chainloader (+363,-4)
4729793 uboot-airoha: increase the size of reserved_bmt partition (+3,-3)
aa3a9d8 uboot-airoha: add ethernet node for an7581 dtsi (+53,-1)
fac5a81 uboot-airoha: add a label to the spi node (+21)
c01dc9c uboot-mediatek: comfast cf-wr632ax: sync with the main DTS (+9,-11)
42ea240 uboot-mediatek: comfast cf-wr632ax: reduce ram speed to 1866 MT/s (+3,-3)
44ee26c uboot-zynq: fix boot process on MMC (+1)
22bbb89 arm-trusted-firmware-mediatek: use MT/s as DDR speed unit (+15,-15)
168098b mediatek: filogic: Qihoo 360T7: fix DDR3 rate (+3,-3)
e39ca3f atf-mediatek: add mt7981 UBI DDR3-1866 build (+11)
e40ccd6 uboot-mediatek: add Qihoo 360T7 (UBI) support (+353)
102c072 mediatek: add support for Qihoo 360T7 (UBI layout) (+354,-220)
ed5611d uboot-mediatek: fix bl2 dependency for Qihoo 360T7 (+1,-1)
c484731 mediatek: add support for netis EAP930 V1 (+595,-1)
6b7fb8e uboot-airoha: update to U-Boot v2026.01 (+1.2K,-2.2K)
3f3f082 uboot-airoha: an7583: fix wrong bits for SPI and SLIC clock (+3,-3)
ba5b20a uboot-airoha: add switch node for an7581 dtsi (+34,-52)
471dd1b mvebu: add support for Zyxel NAS326 (+418,-1)
bf961cd uboot-envtools: mediatek_filogic: wavlink wl-wn536ax6 rev a: add config (+2,-1)
ac692d0 mediatek: filogic: add support for netis MEX605 (+29,-11)
eb8cd69 mediatek: creatlentem clt-r30b1: add all-in-UBI layout (+463,-16)
0def1dd ipq40xx: add support for Linksys MR9000 (+138,-2)
daaf5bc mediatek: add support for JioRouter AX6000 JIDU6101 (+393,-1)

54cced5 wifi-scripts: ucode: fix null dereference for 6GHz-only radios (+2)
2a8b27f base-files: move config_generate to preinit (+22,-14)
80d9abb backport: update dnsmasq to v2.93 from master (+22,-223)
c3fe332 umdns: update to Git HEAD (2026-05-22) (+3,-3)
bd7599d fix calloc_a size argument type (+3,-3)
b3da939 umdns: update to Git HEAD (2026-06-16) (+3,-3)
1b5e7bf cache: bound cache size and clamp hostile TTLs (+51,-2)
fda611d ead: fix integer underflow in handle_send_a() (+5,-2)
4c468d2 fritz-tools: fix out-of-bounds memset in TFFS segment expansion (+2,-2)
9c0c586 util-linux: update to 2.41.5 (+2,-2)
c957f27 openssl: update to 3.5.7 (+6,-6)
9243f9e package: make APK embedded help gzip reproducible (+11)
8be3ba9 package: nftables backport of reproducible builds patches (+196,-1)
f75c27e ca-certificates: update to 20260601 (+2,-2)
1c5daff hostapd: fix misplaced radar-detected ubus notification (+3,-3)
be3ea6b wifi-scripts: fix EAP STA support in supplicant config generation (+6,-1)
2218cb1 dropbear: backport some security fixes from 2026.90 (+1.0K,-4)
6dead28 dropbear: Add additional fixes from 2026.91 (+68,-1)

4c2cfec wireless-regdb: update to version 2026.05.30 (+2,-2)
fcfd34d ipq-wifi: update to Git HEAD (2026-02-13) (+3,-3)
114c519 ipq6018: add Netgear RBK350 BDF ()
296f8fd ipq8074: add Netgear RBK750 BDF ()
30241cb ipq8074: add Zyxel NWA110AX BDF ()
60e53ff ipq-wifi: update to Git HEAD (2026-02-17) (+3,-3)
97af8a2 ipq6018: add Link NN6000 BDF Link: https://github.com/openwrt/firmware_qca-wi... ()
4b7ccde ipq5018: add BDFs for CMCC MR3000D-CI ()
bbb36bb ipq-wifi: update to latest HEAD (+3,-3)
beaf466 ipq4019: add Huawei AP4050DN BDF ()
797f256 ipq-wifi: update to Git HEAD (2026-05-05) (+3,-3)
fc4cf48 qca9888: add TP-Link EAP225-Wall v2 BDF ()
bfdfff6 ipq-wifi: update to Git HEAD (2026-05-18) (+3,-3)
7d851ac ipq40xx: add Linksys MR9000 BDF Link: https://github.com/openwrt/firmware_qca... ()
903e049 ipq5018: Add BDF for Xiaomi Redmi AX5400 ()
e20f4c6 qcn9074: Add BDF for Xiaomi Redmi AX5400 ()
0def1dd ipq40xx: add support for Linksys MR9000 (+138,-2)

2a8b27f base-files: move config_generate to preinit (+22,-14)
bbce1ce scripts: dhcp/dhcpv6: handling of invalid client ID values (+27,-3)

bbce1ce scripts: dhcp/dhcpv6: handling of invalid client ID values (+27,-3)
041b2fd uclient: update to Git HEAD (2026-06-07) (+3,-3)
f227ab4 uclient: fix memory leak of url when backend alloc fails (+3,-1)
6452366 uclient: free proxy_url in uclient_free (+2)
53d2d11 uclient-http: fix NULL deref when digest WWW-Authenticate lacks params (+4)
0ba1b87 ucode: check calloc return in uc_uclient_new (+3)
5cb1946 uclient-fetch: reset redirect counter per request (+4,-3)
568c447 uclient-fetch: retry short writes and surface errors (+17,-4)
4c4a61a uclient-fetch: use strtoull to parse Content-Length (+1,-1)
440ca26 uclient-http: validate Content-Length and chunk sizes from the server (+23,-4)
8658324 uclient: cast to unsigned char before ctype classifications (+8,-8)
bf403fa uclient-fetch: reject CR in --header values (+2,-1)
ec47f41 uclient-fetch: always allocate auth_str and free it on exit (+7,-8)
391dacd uclient-http: fail digest auth when the cnonce cannot be randomized (+13,-7)
ba1f431 ucode: clamp read length to the size of the static buffer (+1,-1)
0ba47f3 uclient-fetch: advance to the next URL between requests (+1)
9dd0055 uclient: initialize *port for unknown address families (+2)
f816506 uclient-http: start digest nonce count at 1 (+1,-1)
⇒ + 20 more...
2cc8b56 odhcp6c: update to Git HEAD (2026-06-04) (+3,-3)
13805fc odhcp6c: reset res variable on INIT state (+1)
0f64e66 odhcp6c: fix "-S" usage (+1,-1)
02e783c dhcpv6: fix NA/PD=try when NA/PD aren't provided (+18,-5)
d99528f odhcp6c: avoid clearing CLIENT_ID (+5,-1)
9a4d6fe dhcpv6: use stable IAID for IA_NA (+14,-2)
48dbd38 dhcpv6: migrate dhcpv6_response_is_valid to switch case (+28,-10)
65f9ee2 dhcpv6: offload FQDN construction to init_dhcpv6 (+28,-14)
0bb93c2 dhcpv6: clarifying comments (+23,-11)
bfd7597 all: add log helpers (+108,-71)
610e4bd config: fix potential memory leaks in error paths (+15,-10)
2e6682b odhcp6c: do cleanup at exit (+22)
5e1ab3b ra: convert if block to switch (+40,-12)
988d5fb dhcpv6: dhcpv6_send: convert whitespaces to tabs (+2,-2)
8abb450 dhcpv6: omit IA_NA on Request (+30,-3)
591ce40 dhcpv6: replace hash_ifname() with MD5 implementation (+16,-5)
24485bb dhcpv6: add config for strict RFC7550 (+72,-19)
⇒ + 32 more...
13c493c odhcpd: update to Git openwrt-25.12 (2026-06-18) (+3,-3)
6907f28 dhcpv6: fix out-of-bounds read in self-loop detection memcmp (+3,-3)
f6571a4 dhcpv6: bound nested-relay recursion to HOP_COUNT_LIMIT (+17,-6)
8637f4c dhcpv6: reject undersized encapsulated DHCPv4 messages in 4o6 path (+13)
14a85c9 dhcpv4: honor Pad/End option encoding when iterating options (+13,-4)
1c461b0 ubus: drop spurious ntohl() of DHCPv4 lease IAID (+1,-1)
6644b46 dhcpv6-ia: avoid undefined shifts in assign_pd() (+10,-4)
41b476d netlink: avoid 32-bit-wide shift when computing /0 IPv4 netmask (+8,-2)
3553613 dhcpv4: never return NULL from dhcpv4_msg_to_string() (+6,-1)
9c78550 ndp: enforce RFC4861 §7.1.1 hop-limit and ICMP-code checks on NS (+9)
b1adea2 dhcpv6: validate minimum length in relay_client_request() (+8)
0721ab6 config: guard captive_portal_uri parsing against strdup() failure (+11,-2)
2db29c4 dhcpv4: copy ifname into arpreq without reading past the source (+5,-1)
2830047 statefiles: skip dn_expand() when no search domain is configured (+7,-1)
6545d3d dhcpv6: avoid unaligned uint16_t reads in ORO option parsing (+16,-5)
f2cfc8d config: invert ipv6_pxe_from_uci() return value (+4,-1)
909847c dhcpv6-pxe: free previous default entry on replacement (+5)
⇒ + 14 more...
7029a38 scripts: dhcpv6: harmonize IAID between IA_NA and IA_PD requests (+21,-2)
0fb3ed2 odhcp6c: update to Git HEAD (2026-06-20) (+3,-3)
07d324e odhcp6c: fix handling of RFC6603 Prefix Exclude Option (+33,-25)
b830633 wifi-scripts: fix disabled vif tracking using wrong dictionary key (+1,-1)
7e84cb6 odhcpd: update to Git openwrt-25.12 (2026-06-28) (+3,-3)
5d7be43 statefiles: escape client hostnames in the lease state file (+45,-2)
481e0a1 scripts: dhcpv6: don't report custom ip6class if default (+4)

c4c164e fstools: update to Git HEAD (2026-03-17) (+3,-3)
1bf2d49 libfstools: make get_var_from_file() reusable (+38,-38)
0b60224 mount_root: add kernel parameter to specify the overlay storage name (+11,-1)
e600d84 mount_root: add kernel parameter to specify the overlay fileystem type (+10)
526efdd fstools: update to Git HEAD (2026-05-23) (+3,-3)
7df1885 libfstools: enable f2fs overlay compression formatting (+22,-4)
16718b6 libfstools: mount f2fs overlay with zstd compression (+36,-12)
8aea6ef uhttpd: update to Git HEAD (2026-04-21) (+5,-8)
506e249 ubus: unregister ubus subscriber on HTTP client disconnect (+11)
e619cb0 client: use base-10 parsing for Content-Length header (+1,-1)
68e132e uhttpd: update to Git HEAD (2026-05-15) (+3,-3)
d255187 client: prevent transfer_chunked counter overflow (+2,-1)
07f0afb client: match Host and URL attributes exactly in tls_redirect_check (+2,-2)
05406f7 file: scan all entries when matching If-Match / If-None-Match (+23,-20)
81527e1 proc: restore default SIGPIPE disposition in spawned child (+2)
0df6257 ucode: initialize module search path only once (+2,-1)
05317bf proc: store CGI Status message per-client instead of in a shared buffer (+4,-5)
1781b6d utils, client: cast char to unsigned before passing to ctype functions (+7,-5)
4221eb8 file: respond 500 on uh_handle_alias OOM (+8,-1)
8e5b26f file: distinguish parse failure from epoch in date precondition checks (+16,-3)
ced7b15 utils: fix one-byte overflow in uh_urldecode (+8,-4)
53e7150 file: bail out of file_write_cb on read error (+3)
9343214 utils: remove unreachable return statement in uh_addr_rfc1918 (-2)
add5389 utils: fix off-by-one out-of-bounds read in uh_b64decode (+1,-1)
778ccbb main: fix daemonization stdio redirection and fd leak (+4,-2)
2c869c0 client: parse Content-Length safely (+8,-2)
9404e6c client: parse chunked transfer chunk size safely (+10,-5)
⇒ + 2 more...
66b0edb uhttpd: update to Git HEAD (2026-05-20) (+3,-3)
6ab9abb cgi, file: fix crash due to field_len type mismatch with libubox (+15,-1)
2dbcdf1 uhttpd: update to Git HEAD (2026-05-21) (+3,-3)
1b624f8 auth: classify $p$ lookups by account state (+36,-2)
ff52e19 uhttpd: update to Git HEAD (2026-06-16) (+3,-3)
ae015e0 client: reject unhandled Transfer-Encoding values (+9,-1)
b78f518 client: close connection on invalid chunk length (+5)
7b1bec4 ubus: close connection on POST body parse error (+6)
3bc312c rpcd: update to Git HEAD (2026-06-04) (+3,-3)
69b62b1 rpc-sys: packagelist: increase input buffer size (+3,-2)
e655a0d exec: defer async reply teardown to avoid use-after-free (+68,-10)
5b07867 optimize by reusing timeout member (+8,-30)
d005c88 session: clamp uloop timeout to avoid int overflow (+26,-2)
a545f00 ucode: add request.defer() for async method handling (+27,-1)
ab6549a file: avoid sending uninitialized stack memory for broken symlinks (+1,-1)
7af2dd8 main: prevent integer overflow when parsing -t timeout argument (+4,-2)
680705e plugin: use snprintf in ubus lookup callback to prevent buffer overflow (+6,-4)
fb0302d session: detect short read of /dev/urandom in rpc_random() (+7,-3)
dc091af rpc-sys: packagelist: check calloc() result for world array (+5)
4fbd485 rpc-sys: packagelist: avoid size_t underflow when stripping ABI version (+7,-2)
46fce7d ucode: fix off-by-one truncation of generated ubus object type name (+1,-1)
26dba52 exec: prevent double close() of exec pipe descriptors (+6)
af5d6f4 uci: prevent integer overflow of client supplied apply timeout (+7,-1)
d06d2a8 rc: fix memory leak of list request context (+1)
0de6668 rc: copy list "name" filter to avoid use-after-free (+6,-2)
⇒ + 9 more...
d96413c ubus: update to Git HEAD (2026-05-23) (+3,-3)
4b27405 libubus: fix NULL dereference on OOM in ubus_queue_msg (+6)
8b5be57 libubus-acl: fix dangling pointers on blob_memdup failure in acl_recv_cb (+7,-3)
9105ea2 ubusd_acl: fix NULL dereference on OOM in ubusd_acl_alloc_obj (+2)
07d7f34 ubusd_acl: handle allocation failures in ubusd_acl_init_client (+20,-2)
497321a ubusd_acl: fix NULL dereference on OOM in ubusd_acl_init (+2,-1)
f66d52b ubusd_event: fix OOM handling in ubusd_send_event_msg (+13,-7)
11ea1b3 ubusd_main: fix async-signal-unsafe SIGHUP handler (+42,-1)
0c09559 ubusd_proto: fix resource leaks and ID tree corruption in ubusd_proto_new_client (+7,-2)
f61695e ubusd_proto: fix NULL dereference for user/group in ubusd_handle_add_watch (+5,-1)
7ecacfa ubusd_proto: fix NULL dereference on OOM in ubusd_proto_init_retmsg (+2,-1)
3ab9d77 lua: fix inverted argument check in ubus_lua_add (+1,-1)
43051ca lua: fix unchecked calloc and memory leak in ubus_lua_load_object (+9,-2)
4ca0b14 ubusd_id: use getrandom(2) unconditionally on Linux (+22,-9)
7e4356d ubusd_monitor: fix NULL dereference on OOM in ubusd_monitor_message (+2)
5849870 libubus-req: fix file descriptor leaks in ubus_process_req_msg (+6,-3)
f29767f libubus: fix file descriptor leaks in ubus_process_msg (+5,-2)
⇒ + 11 more...
98134ee ubus: pin ABI version to old one (+3,-2)
7b8ce1e libubox: update to Git openwrt-25.12 (2026-06-19) (+4,-4)
8a28fbf blob: fix wrong type for realloc result in blob_buffer_grow() (+1,-1)
da9183d json_script: convert recursive __json_script_file_free() to iterative (+5,-7)
3c56643 usock: fix off-by-one in nanosecond normalization in poll_restart() (+1,-1)
e1dc23a uloop: usock: add error checking for fcntl and remove duplicate include (+30,-12)
ad15219 uloop: fix undefined behavior in signal bit operations for signals > 32 (+2,-2)
4811166 blobmsg: fix policy name length overflow and add bounds check in blobmsg_parse() (+14,-2)
9db2171 usock: fix integer overflow in timeout calculations (+13,-6)
3203222 udebug: fix double off-by-one in udebug_entry_vprintf() (+2,-2)
afc0fa8 blobmsg_json: fix integer overflow in blobmsg_puts() (+6,-6)
6f01162 blobmsg_json: floor strbuf size and tighten the post-format guard (+17,-3)
6f6c861 blobmsg: fix unsigned integer overflow in blobmsg_alloc_string_buffer() (+2)
5286808 blobmsg: use correct byte-order macro when setting BLOB_ATTR_EXTENDED (+1,-1)
3bbf83c blobmsg_json: fix double format string to avoid truncation and data loss (+9,-9)
1d80ee2 jshn: fix integer overflow and type confusion in jshn_parse_file (+10,-2)
b4a718b blob: fix integer overflow in buffer growth functions (+14,-2)
315e0af blob: use size_t for blob_memdup() length (+1,-1)
⇒ + 8 more...
2d8259f ubus: update to Git HEAD (2026-06-28) (+3,-3)
24864e7 ubusd_id: use GRND_INSECURE to avoid blocking boot on getrandom() (+10,-1)

3bd046e airoha: an7581: move internal PHY interrupt to specific device DTS (-4)
887f21e airoha: an7581: add uboot chainloader (+363,-4)
feda355 airoha: an7581: enable fitblk driver (+1)
e4c15eb airoha: an7581: add ubi nvmem driver (+1)
8dff4c9 airoha: backport net upstream fixes (+771,-23)
9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)
949487e kernel: bump 6.12 to 6.12.92 (+16,-1.7K)
6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)
c992691 airoha: disable afe by default for an7581 (+5)
ebae538 airoha: add pending patch for additional GPIO pins for PHY LED0 (+101)

6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)

9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)
949487e kernel: bump 6.12 to 6.12.92 (+16,-1.7K)
3f59bc0 kernel: bump 6.12 to 6.12.93 (+49,-103)
a8aef63 ath79: mikrotik: also compile AG71XX_LEGACY as a module (+2,-1)
6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)

797171a kernel: bump 6.12 to 6.12.88 (+26,-26)
9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)
949487e kernel: bump 6.12 to 6.12.92 (+16,-1.7K)
3f59bc0 kernel: bump 6.12 to 6.12.93 (+49,-103)
6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)
f191b85 leds: add "network" LED trigger (lan/wan/wlan) (+1.2K,-3)

9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)
3f59bc0 kernel: bump 6.12 to 6.12.93 (+49,-103)
0def1dd ipq40xx: add support for Linksys MR9000 (+138,-2)

b495124 ipq806x: ap3935: disable hibernation on LAN1 (+1)

9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)

13ff225 mediatek: don't let devfreq power-off the CPU (+294)
42ea240 uboot-mediatek: comfast cf-wr632ax: reduce ram speed to 1866 MT/s (+3,-3)
949487e kernel: bump 6.12 to 6.12.92 (+16,-1.7K)
22bbb89 arm-trusted-firmware-mediatek: use MT/s as DDR speed unit (+15,-15)
168098b mediatek: filogic: Qihoo 360T7: fix DDR3 rate (+3,-3)
432586f mediatek: filogic: fix wrong dts file permission ()
102c072 mediatek: add support for Qihoo 360T7 (UBI layout) (+354,-220)
1421649 mediatek: add GL.iNET GL-MT3600BE support (+314)
c484731 mediatek: add support for netis EAP930 V1 (+595,-1)
6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)
bcdbfd7 mediatek: wavlink wl-wn536ax6 rev a: enable nmbm bad block management (+4)
2b664d4 mediatek: wavlink wl-wn536ax6 rev a: set SPI drive strength 4mA (+2,-2)
7ae998c mediatek: wavlink wl-wn536ax6 rev a: change nvmem layout for MAC addresses (+11,-15)
333ff2d mediatek: wavlink wl-wn536ax6 rev a: fix WLAN 5GHz MAC address (+9,-5)
5cff888 mediatek: wavlink wl-wn536ax6 rev a: add "network" LED trigger (+4,-2)
c670f1a mediatek: wavlink wl-wn536ax6 rev a: remove old WLAN LED default (-1)
12a3f9f mediatek: filogic: add support for TP-Link F65 (+218,-3)
ef74760 mediatek: add Huasifei WH3000R NAND support (+311,-1)
38ea322 mediatek: filogic: Add new Router model ZBT-Z8106AX-S (+39,-2)
d34a54f kernel/mediatek: fix null dereference in dynamic calibration patch (+10,-7)
ac692d0 mediatek: filogic: add support for netis MEX605 (+29,-11)
eb8cd69 mediatek: creatlentem clt-r30b1: add all-in-UBI layout (+463,-16)
daaf5bc mediatek: add support for JioRouter AX6000 JIDU6101 (+393,-1)
24151ba mediatek: add WD-R3000N-G2A as ALT device for Bazis AX3000WM (+2)
f5dae5e mediatek: acer-predator-w6x: add LED boot status support (+4)

6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)

f521e16 mvebu: move FitImage recipe to generic image Makefile (+6,-6)
f5a53f3 mvebu: cortex-a53: uDPU/eDPU: cleanup recipe a bit (+4,-11)
fbf01b4 mvebu: cortexa53: uDPU/eDPU convert to dual firmware (A/B) (+146,-245)
601e067 mvebu: cortexa53: uDPU/eDPU: update active bootscript as well (+43)
6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)
471dd1b mvebu: add support for Zyxel NAS326 (+418,-1)

9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)

6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)

9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)
73079fa ramips: pax1800-lite: fix label-mac-device (+1,-1)
d14d194 ramips: pax1800-lite: do not attach both ubi partitions on boot (-2)
1da8e25 ramips: mt76x8: cudy-lt300-v3: fix backup partition offset (+1,-1)
ad84313 ramips: mt76x8: add support for Cudy WR300 v1 (+157)
82d7ed7 ramips: add support for I-O DATA WN-AX2033GR2 (+46)

949487e kernel: bump 6.12 to 6.12.92 (+16,-1.7K)
3f59bc0 kernel: bump 6.12 to 6.12.93 (+49,-103)
6bad5f2 kernel: bump 6.12 to 6.12.94 (+43,-98)

0eaee44 kernel: bump 6.12 to 6.12.90 (+58,-42)
9cf794c kernel: bump 6.12 to 6.12.91 (+2.0K,-494)

3f59bc0 kernel: bump 6.12 to 6.12.93 (+49,-103)

#23709

Description: Reprodubility of libnftables in x86/64 images
Link: https://github.com/openwrt/openwrt/issues/23709
Commits:
8be3ba9 package: nftables backport of reproducible builds patches (+196,-1)

#23739

Description: OpenWRT 25.12.4 breaks Atheros AR8216/AR8236/AR8316 switch bringup on boot for some Mikrotik devices
Link: https://github.com/openwrt/openwrt/issues/23739
Commits:
a8aef63 ath79: mikrotik: also compile AG71XX_LEGACY as a module (+2,-1)

CVE-2019-6111

Description: An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6111
Commits:
2218cb1 dropbear: backport some security fixes from 2026.90 (+1.0K,-4)

CVE-2026-6042

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6042
Commits:
084cdac toolchain: musl: backport patches with CVE fixes (+481,-9)

CVE-2026-7383

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-9076

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-34180

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-34181

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-34182

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-34183

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-35385

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35385
Commits:
2218cb1 dropbear: backport some security fixes from 2026.90 (+1.0K,-4)

CVE-2026-40200

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40200
Commits:
084cdac toolchain: musl: backport patches with CVE fixes (+481,-9)

CVE-2026-42764

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-42766

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-42767

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-42768

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-42769

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-42770

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-45445

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-45446

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-45447

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447
Commits:
c957f27 openssl: update to 3.5.7 (+6,-6)

CVE-2026-53918

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53918
Commits:
13c493c odhcpd: update to Git openwrt-25.12 (2026-06-18) (+3,-3)
6907f28 dhcpv6: fix out-of-bounds read in self-loop detection memcmp (+3,-3)
f6571a4 dhcpv6: bound nested-relay recursion to HOP_COUNT_LIMIT (+17,-6)
8637f4c dhcpv6: reject undersized encapsulated DHCPv4 messages in 4o6 path (+13)
14a85c9 dhcpv4: honor Pad/End option encoding when iterating options (+13,-4)
1c461b0 ubus: drop spurious ntohl() of DHCPv4 lease IAID (+1,-1)
6644b46 dhcpv6-ia: avoid undefined shifts in assign_pd() (+10,-4)
41b476d netlink: avoid 32-bit-wide shift when computing /0 IPv4 netmask (+8,-2)
3553613 dhcpv4: never return NULL from dhcpv4_msg_to_string() (+6,-1)
9c78550 ndp: enforce RFC4861 §7.1.1 hop-limit and ICMP-code checks on NS (+9)
b1adea2 dhcpv6: validate minimum length in relay_client_request() (+8)
0721ab6 config: guard captive_portal_uri parsing against strdup() failure (+11,-2)
2db29c4 dhcpv4: copy ifname into arpreq without reading past the source (+5,-1)
2830047 statefiles: skip dn_expand() when no search domain is configured (+7,-1)
6545d3d dhcpv6: avoid unaligned uint16_t reads in ORO option parsing (+16,-5)
f2cfc8d config: invert ipv6_pxe_from_uci() return value (+4,-1)
909847c dhcpv6-pxe: free previous default entry on replacement (+5)
⇒ + 14 more...

CVE-2026-53921

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53921
Commits:
13c493c odhcpd: update to Git openwrt-25.12 (2026-06-18) (+3,-3)
6907f28 dhcpv6: fix out-of-bounds read in self-loop detection memcmp (+3,-3)
f6571a4 dhcpv6: bound nested-relay recursion to HOP_COUNT_LIMIT (+17,-6)
8637f4c dhcpv6: reject undersized encapsulated DHCPv4 messages in 4o6 path (+13)
14a85c9 dhcpv4: honor Pad/End option encoding when iterating options (+13,-4)
1c461b0 ubus: drop spurious ntohl() of DHCPv4 lease IAID (+1,-1)
6644b46 dhcpv6-ia: avoid undefined shifts in assign_pd() (+10,-4)
41b476d netlink: avoid 32-bit-wide shift when computing /0 IPv4 netmask (+8,-2)
3553613 dhcpv4: never return NULL from dhcpv4_msg_to_string() (+6,-1)
9c78550 ndp: enforce RFC4861 §7.1.1 hop-limit and ICMP-code checks on NS (+9)
b1adea2 dhcpv6: validate minimum length in relay_client_request() (+8)
0721ab6 config: guard captive_portal_uri parsing against strdup() failure (+11,-2)
2db29c4 dhcpv4: copy ifname into arpreq without reading past the source (+5,-1)
2830047 statefiles: skip dn_expand() when no search domain is configured (+7,-1)
6545d3d dhcpv6: avoid unaligned uint16_t reads in ORO option parsing (+16,-5)
f2cfc8d config: invert ipv6_pxe_from_uci() return value (+4,-1)
909847c dhcpv6-pxe: free previous default entry on replacement (+5)
⇒ + 14 more...

CVE-2026-53922

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53922
Commits:
13c493c odhcpd: update to Git openwrt-25.12 (2026-06-18) (+3,-3)
6907f28 dhcpv6: fix out-of-bounds read in self-loop detection memcmp (+3,-3)
f6571a4 dhcpv6: bound nested-relay recursion to HOP_COUNT_LIMIT (+17,-6)
8637f4c dhcpv6: reject undersized encapsulated DHCPv4 messages in 4o6 path (+13)
14a85c9 dhcpv4: honor Pad/End option encoding when iterating options (+13,-4)
1c461b0 ubus: drop spurious ntohl() of DHCPv4 lease IAID (+1,-1)
6644b46 dhcpv6-ia: avoid undefined shifts in assign_pd() (+10,-4)
41b476d netlink: avoid 32-bit-wide shift when computing /0 IPv4 netmask (+8,-2)
3553613 dhcpv4: never return NULL from dhcpv4_msg_to_string() (+6,-1)
9c78550 ndp: enforce RFC4861 §7.1.1 hop-limit and ICMP-code checks on NS (+9)
b1adea2 dhcpv6: validate minimum length in relay_client_request() (+8)
0721ab6 config: guard captive_portal_uri parsing against strdup() failure (+11,-2)
2db29c4 dhcpv4: copy ifname into arpreq without reading past the source (+5,-1)
2830047 statefiles: skip dn_expand() when no search domain is configured (+7,-1)
6545d3d dhcpv6: avoid unaligned uint16_t reads in ORO option parsing (+16,-5)
f2cfc8d config: invert ipv6_pxe_from_uci() return value (+4,-1)
909847c dhcpv6-pxe: free previous default entry on replacement (+5)
⇒ + 14 more...

This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.More information about cookies
  • Last modified: 2026/06/29 22:50
  • by hauke