Hi!

This update addresses a few security issues in third party software, but take note that libxml2 is currently stuck in an old release in FreeBSD ports that was decided not to be fixed there for the time being.

Dnsmasq receives more improvements as you all explore the limits of the current implementation and what the software can still offer beyond that. Thank you for all the good feedback on this front!

The FreeBSD kernel was updated with a number of upstream stable commits while we get closer to evaulating the jump to a newer FreeBSD release for 25.7.

Lastly, we are preparing for a historic moment: offering privilege separation for the GUI meaning the web server can stop running as a root user. This may still be optional in the next major version, but it makes fixing the remaining incompatibilities much easier.

Here are the full patch notes:

A hotfix release was issued as 25.1.8_1:


Stay safe,
Your OPNsense team