IPFire Linux Firewall Introduces Experimental Btrfs Support and Intel RFDS Mitigations

The IPFire Project recently announced a new update to their robust open-source GNU/Linux distribution, commonly used as a router or firewall. Known as IPFire 2.29 Core Update 186, this release incorporates various changes, introduces experimental support for the Btrfs file system, and updates multiple components.

The IPFire 2.29 Core Update 186 features an upgraded kernel based on Linux 6.6.30 LTS. This includes fixes for the latest Register File Data Sampling (RFDS) vulnerability, also known as CVE-2023-28746, which affects Intel processors. The update also provides CPU frequency scaling support for the Raspberry Pi and enhances CPU graph support for processors with some virtual cores offline.

Additionally, IPFire 2.29 Core Update 186 includes Spamhaus EDROP support in place of Alienvault, integrates Linux Landlock capability in the Suricata open-source network analysis and threat detection software to safeguard IPFire installations from unauthorized file system access due to exploits, and introduces experimental support for the Btrfs file system.

“Currently this has been implemented to test out what benefits IPFire could draw from this new design of a filesystem. It enables compression of all data it holds and allows to create snapshots which might become useful for the development process and enable easier rollbacks,” said IPFire developer Michael Tremer.

Other noteworthy changes in the IPFire 2.29 Core Update 186 release include a patched Unbound/DHCP Leases bridge to avoid unnecessary reloads of the Unbound DNS resolver, a quieter boot process by removing unnecessary warnings, as well as the removal of broken sslh add-on and the Icinga open-source computer system and network monitoring application as there’s no interest in it from IPFire users.

Under the hood, IPFire 2.29 Core Update 186 comes with various updated packages, including Apache2 2.4.59, BIND 9.16.49, kmod 32, libhtp 0.5.48, SQLite 3.45.3, squid 6.9, strongSwan 5.9.14, Suricata 7.0.5, Bacula 13.0.4, dnsdist 1.9.3, Lynis 3.1.1, mympd 14.1.2, Tor 0.4.8.11, and tzdata 2024a.

Check out the release announcement page for more details about the changes included in IPFire 2.29 Core Update 186, which you can download right now for x86_64 (Intel/AMD 64-bit) and AArch64 (ARM64) architectures from the official website as ISO and USB images.

Image credits: The IPFire Project (edited by Marius Nestor)

Last updated 7 hours ago