gwlim / Fast-Path-LEDE-OpenWRT

PLEASE GO TO NEW OPENWRT TRUNK BASED SFE FIRMWARE ->
https://github.com/gwlim/openwrt-sfe-flowoffload
90 stars 22 forks source link

Request for new release 17.01.4 (with patches for KRACK vulnerability) #4

Closed bozhodimitrov closed 6 years ago

bozhodimitrov commented 6 years ago

Since there is a major patch because of the KRACK vulnerability. Is it possible for you to upload the new builds?

Thank you very much.

gwlim commented 6 years ago

Yes I know, but I am really busy this month so I am not able to commit. I can only resume end of next month. Sorry about that.

bozhodimitrov commented 6 years ago

It is understandable. I made an issue, because you are one of the few people that can make such release and you can be trusted. Also this is just a reminder, so feel free to close it, I guess that the client updates are more important than patching the APs itself.

miegl commented 6 years ago

If you are using the WiFi only as an AP, you are not affected. The KRACK vulnerability only affects client devices.

igr91 commented 6 years ago

@int3l You can update the offending modules to mitigate these vulnerabilities until there's a newer build. At least that was the advice in one support thread the night the issues were disclosed (that was fast), then we got 17.04.1 a week later.

According to that thread, you want to update hostapd-common and wpad or wpad-mini depending on what you use. Versions -5 and above of these packages are patched against KRACK, you'll get -6 now. You can now safely use the router as a client or repeater again. IIRC 17.04.1 also adds some patches for mac80211.

By the way, these builds rock! Fast path is more than felt on older routers like the 1043ND v1, it truly breathes new life into them while enjoying the benefits of LEDE. Thank you for your hard work @gwlim :)