{"id":12,"date":"2026-05-31T17:53:53","date_gmt":"2026-05-31T09:53:53","guid":{"rendered":"http:\/\/tantan.ink\/?p=12"},"modified":"2026-05-31T17:53:53","modified_gmt":"2026-05-31T09:53:53","slug":"openwrt-25-12-4-release","status":"publish","type":"post","link":"https:\/\/www.tantan.ink\/index.php\/2026\/05\/31\/openwrt-25-12-4-release\/","title":{"rendered":"OpenWrt 25.12.4 \u53d1\u5e03\uff1a\u4e00\u6b21\u503c\u5f97\u5173\u6ce8\u7684\u300c\u5b89\u5168\u8865\u4e01\u7ea7\u300d\u66f4\u65b0"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">dnsmasq \u4e00\u6b21\u6027\u4fee\u4e86\u516d\u4e2a CVE<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u6b21\u6700\u503c\u5f97\u5173\u6ce8\u7684\u4fee\u6539\u662f dnsmasq 2.91 \u7684\u516d\u4e2a CVE \u8865\u4e01\u3002dnsmasq \u662f OpenWrt \u9ed8\u8ba4\u7684 DNS \u8f6c\u53d1\u548c DHCP \u670d\u52a1\u5668\uff0c\u51e0\u4e4e\u6240\u6709 OpenWrt \u8bbe\u5907\u90fd\u5728\u7528\u3002\u8fd9\u516d\u4e2a\u6f0f\u6d1e\u6db5\u76d6\u4e86\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE-2026-2291<\/strong>\uff1a\u57df\u540d\u89e3\u6790\u8fc7\u7a0b\u4e2d\u7684\u5806\u7f13\u51b2\u533a\u6ea2\u51fa\u3002\u653b\u51fb\u8005\u901a\u8fc7\u6784\u9020\u7279\u6b8a DNS \u54cd\u5e94\u53ef\u80fd\u89e6\u53d1\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u3002<\/li>\n<li><strong>CVE-2026-4890 \/ 4891<\/strong>\uff1aDNSSEC \u65b9\u5411\uff0c\u901a\u8fc7\u7cbe\u5fc3\u6784\u9020\u7684 NSEC bitmap \u6216 RRSIG \u5305\u5bfc\u81f4 dnsmasq \u5d29\u6e83\u3002\u5982\u679c\u4f60\u5f00\u542f\u4e86 DNSSEC \u9a8c\u8bc1\uff0c\u9700\u8981\u91cd\u70b9\u5173\u6ce8\u3002<\/li>\n<li><strong>CVE-2026-4892<\/strong>\uff1aDHCPv6 \u65b9\u5411\uff0c\u5f53\u542f\u7528\u4e86 <code>--dhcp-script<\/code> \u9009\u9879\u65f6\uff0c\u8d85\u957f\u7684 DHCPv6 CLID \u53ef\u89e6\u53d1\u7f13\u51b2\u533a\u6ea2\u51fa\u3002<\/li>\n<li><strong>CVE-2026-4893<\/strong>\uff1aEDNS Client Subnet \u9a8c\u8bc1\u903b\u8f91\u635f\u574f\u3002<\/li>\n<li><strong>CVE-2026-5172<\/strong>\uff1a<code>extract_addresses()<\/code> \u5728\u5904\u7406\u6076\u610f DNS \u8d44\u6e90\u8bb0\u5f55\u65f6\u7684\u7f13\u51b2\u533a\u6ea2\u51fa\u3002<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e00\u53e5\u8bdd\u603b\u7ed3\uff1a\u53ea\u8981\u4f60\u7684 OpenWrt \u8bbe\u5907\u66b4\u9732\u5728\u516c\u7f51\u6216\u8005\u5c40\u57df\u7f51\u5185\u6709\u4e0d\u53d7\u4fe1\u8bbe\u5907\uff0c\u8fd9\u516d\u4e2a\u6f0f\u6d1e\u90fd\u5e94\u8be5\u901a\u8fc7\u5347\u7ea7\u6765\u5835\u4e0a\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u5185\u6838 Dirty Frag\uff1a\u540d\u5b57\u552c\u4eba\uff0c\u5f71\u54cd\u9762\u6709\u9650<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Linux \u5185\u6838\u4e5f\u4fee\u4e86\u4e00\u4e2a <strong>CVE-2026-43284<\/strong>\uff0c\u53eb &#8220;Dirty Frag&#8221;\u3002\u8fd9\u662f\u4e00\u4e2a IPsec ESP \u8def\u5f84\u4e0a\u7684\u672c\u5730\u63d0\u6743\u6f0f\u6d1e\uff0c\u901a\u8fc7\u5185\u6838\u4ece 6.12.85 \u5347\u7ea7\u5230 6.12.87 \u4fee\u590d\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u9700\u8981\u6ce8\u610f\u7684\u662f\uff1a\u8fd9\u4e2a\u6f0f\u6d1e\u53ea\u5728\u52a0\u8f7d\u4e86 <code>kmod-ipsec<\/code> \u5185\u6838\u6a21\u5757\u7684\u8bbe\u5907\u4e0a\u53ef\u5229\u7528\u3002\u5927\u591a\u6570\u5bb6\u5ead OpenWrt \u8def\u7531\u5668\u4e0d\u4f1a\u5f00 IPsec\u3002\u5982\u679c\u4f60\u53ea\u662f\u5728\u7528 WireGuard \u6216 OpenVPN\uff0c\u8fd9\u4e2a\u6f0f\u6d1e\u8ddf\u4f60\u5173\u7cfb\u4e0d\u5927\uff0c\u4f46\u5347\u7ea7\u603b\u6ca1\u9519\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u5176\u4ed6\u66f4\u65b0\uff1aWiFi\u3001\u65b0\u8bbe\u5907\u3001mac80211<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">WiFi \u65b9\u9762\uff0cmac80211 backports \u4ece 6.18.7 \u66f4\u65b0\u5230\u4e86 6.18.26\uff0c\u4e3b\u8981\u662f\u7a33\u5b9a\u6027\u6539\u8fdb\uff0c\u8de8\u5ea6\u4e0d\u5c0f\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8bbe\u5907\u652f\u6301\u65b0\u589e\uff1aMikroTik RouterBOARD 960PGS\uff08hEX PoE \/ PowerBox Pro\uff09\u52a0\u5165 ath79 \u76ee\u6807\uff0cCudy WR3000E\/H\/P\/S \u7684 ubootmod \u53d8\u4f53\u4e5f\u6b63\u5f0f\u652f\u6301\u4e86\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd8\u6709\u4e00\u4e9b\u8bbe\u5907\u4fee\u590d\uff1aCudy WR3000 \u7cfb\u5217\u7684 NAND \u6784\u5efa\u4e4b\u524d\u9519\u8bef\u542f\u7528\u4e86 NMBM\uff0c\u8fd9\u4e2a\u7248\u672c\u4fee\u4e86\uff1bPakedge WR-1 \u6062\u590d\u4e86 WLAN LED \u6807\u7b7e\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u5347\u7ea7\u524d\u9700\u8981\u6ce8\u610f\u7684\u51e0\u4e2a\u5751<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u90e8\u5206\u6bd4\u66f4\u65b0\u5185\u5bb9\u672c\u8eab\u66f4\u91cd\u8981\u3002\u6bcf\u6b21 OpenWrt \u5347\u7ea7\u90fd\u6709\u4e00\u4e9b\u5df2\u77e5\u95ee\u9898\u548c\u7279\u6b8a\u6d41\u7a0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>SQM CAKE MQ \u541e\u5410\u91cf\u5f02\u5e38<\/strong>\uff1a\u8fd9\u4e2a\u7248\u672c\u7684\u8c03\u5ea6\u5668\u4fee\u590d\u53ef\u80fd\u5bfc\u81f4 cake_mq \u5728\u67d0\u4e9b\u914d\u7f6e\u4e0b\u541e\u5410\u91cf\u5f02\u5e38\u964d\u4f4e\uff08issue #22344\uff09\u3002\u5982\u679c\u4f60\u5728\u7528 SQM QoS \u7684 cake_mq \u7b97\u6cd5\u505a\u6d41\u63a7\uff0c\u5347\u7ea7\u540e\u5efa\u8bae\u8dd1\u6d4b\u901f\u9a8c\u8bc1\u3002<\/li>\n<li><strong>TP-Link RE355\/RE450 \u9700 force \u5347\u7ea7<\/strong>\uff1a\u8fd9\u51e0\u4e2a\u578b\u53f7\u9700\u8981 <code>sysupgrade -F<\/code> \u5f3a\u5236\u5237\u5165\uff0c\u955c\u50cf\u4e0d\u8d85\u8fc7 5.875 MB\u3002<\/li>\n<li><strong>WPA3 + 802.11r \u517c\u5bb9\u95ee\u9898<\/strong>\uff1a\u540c\u65f6\u5f00 WPA3 \u548c 802.11r Fast Transition\uff0c\u5df2\u77e5\u6709\u4e9b\u5ba2\u6237\u7aef\u8fde\u4e0d\u4e0a\uff08issue #22200\uff09\u3002Pixel 10 \u8fde WPA3 \u4fdd\u62a4\u7684 WiFi 6 AP \u4e5f\u6709\u95ee\u9898\uff08issue #21486\uff09\u3002<\/li>\n<li><strong>Meraki MX60 \u7279\u6b8a\u6d41\u7a0b<\/strong>\uff1a\u9700\u8981\u5148\u6539 <code>meraki_loadaddr<\/code>\u3002<\/li>\n<li><strong>Bananapi BPI-R4 \u63a5\u53e3\u66f4\u540d<\/strong>\uff1aeth1\u2192sfp-lan\/lan4\uff0ceth2\u2192sfp-wan\uff0c\u5347\u7ea7\u65f6\u4e0d\u80fd\u4fdd\u7559\u914d\u7f6e\u3002<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u5347\u7ea7\u5efa\u8bae<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u6700\u7b80\u5355\u7684\u5347\u7ea7\u65b9\u5f0f\u662f\u7528 Attended Sysupgrade\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>auc -b 25.12 -r 25.12.4<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u6216\u76f4\u63a5\u53bb <a href=\"https:\/\/firmware-selector.openwrt.org\/?version=25.12.4\">Firmware Selector<\/a> \u4e0b\u8f7d\u5bf9\u5e94\u578b\u53f7\u7684\u955c\u50cf\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u4e4b\u524d\u4ece 24.10 \u5347\u5230 25.12 \u4e00\u5207\u6b63\u5e38\uff0c25.12.3 \u5230 25.12.4 \u57fa\u672c\u5c31\u662f\u5e73\u6ed1\u5347\u7ea7\uff0c\u4fdd\u7559\u914d\u7f6e\u5373\u53ef\u3002\u8fd8\u5728 23.05 \u6216\u66f4\u65e9\u7684\u9700\u8981\u5148\u8fc7 24.10\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u6211\u7684\u5224\u65ad<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u6b21\u66f4\u65b0\u7684\u6838\u5fc3\u4ef7\u503c\u5728\u5b89\u5168\u4fee\u590d\u3002dnsmasq \u7684\u516d\u4e2a CVE \u8986\u76d6\u4e86 DNS \u548c DHCP \u4e24\u4e2a\u6838\u5fc3\u670d\u52a1\u65b9\u5411\u3002\u5982\u679c\u8bbe\u5907\u66b4\u9732\u5728\u516c\u7f51\uff0c\u6216\u8005\u5c40\u57df\u7f51\u91cc\u8bbe\u5907\u6bd4\u8f83\u591a\u3001\u4e0d\u53d7\u63a7\u8bbe\u5907\u7684\u5b58\u5728\u53ef\u80fd\u6027\u8f83\u9ad8\uff0c\u5efa\u8bae\u5c3d\u5feb\u5347\u7ea7\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dirty Frag \u867d\u7136\u540d\u5b57\u552c\u4eba\uff0c\u4f46\u5bf9\u5bb6\u5ead\u7528\u6237\u5f71\u54cd\u6709\u9650\u2014\u2014\u4e0d\u5f00 IPsec \u5c31\u4e0d\u53d7\u5f71\u54cd\u3002\u5012\u662f SQM CAKE MQ \u7684\u5df2\u77e5\u95ee\u9898\u66f4\u503c\u5f97\u5b9e\u9645\u9a8c\u8bc1\uff0c\u6bd5\u7adf\u56fd\u5185\u5bbd\u5e26\u73af\u5883\u4e0b\u5f00 QoS \u7684\u4eba\u4e0d\u5c11\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u540e\u9762\u5b9e\u9645\u8dd1\u4e00\u6bb5\u65f6\u95f4\u53d1\u73b0\u4e86\u4ec0\u4e48\u95ee\u9898\uff0c\u6211\u518d\u66f4\u65b0\u3002\u81f3\u5c11\u5148\u628a dnsmasq \u7684\u6d1e\u5835\u4e0a\u662f\u7a33\u7684\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>\u53c2\u8003\uff1a<a href=\"https:\/\/github.com\/openwrt\/openwrt\/releases\/tag\/v25.12.4\">OpenWrt 25.12.4 Release Notes<\/a> | <a href=\"https:\/\/openwrt.org\/releases\/25.12\/changelog-25.12.4\">\u5b8c\u6574 Changelog<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>OpenWrt 25.12.4 \u53d1\u5e03\u4e86\uff0c\u8fd9\u6b21\u4e3b\u8981\u662f\u5b89\u5168\u4fee\u590d\uff1adnsmasq \u516d\u4e2a CVE\u3001\u5185\u6838 Dirty Frag \u6f0f\u6d1e\u4fee\u590d\u3001mac80211 \u66f4\u65b0\u3002\u770b\u770b\u5347\u7ea7\u524d\u9700\u8981\u6ce8\u610f\u54ea\u4e9b\u5751\u3002<\/p>\n","protected":false},"author":1,"featured_media":105,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-12","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/posts\/12","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/comments?post=12"}],"version-history":[{"count":0,"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/posts\/12\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/media\/105"}],"wp:attachment":[{"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/media?parent=12"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/categories?post=12"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tantan.ink\/index.php\/wp-json\/wp\/v2\/tags?post=12"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}