Latest IPFire Update Boosts Firewall Security in Version 2.29 Core 194

Latest IPFire Update Boosts Firewall Security in Version 2.29 Core 194

IPFire 2.29 Core Update 194 Redefines Firewall Security with Smarter Performance and Critical Fixes

The IPFire team has rolled out Core Update 194 for its flagship version 2.29, introducing a new wave of intelligent security reinforcements and optimized network behavior to its trusted open-source firewall platform.

Released on March 17, 2025, this update reinforces IPFire’s role as a go-to security solution for businesses and institutions that demand both performance and reliability in complex network environments.

Leading this release is the integration of Linux kernel 6.12.23, bringing refined stability and a reinforced security foundation. With this kernel, IPFire leverages previously introduced improvements in AES-GCM encryption, delivering up to 162% faster processing on compatible Intel and AMD systems—translating directly into better IPsec VPN performance for encrypted traffic.

This version also neutralizes multiple high-priority vulnerabilities:

  • Expat 2.7.1 addresses CVE-2024-8176, patching a flaw in XML parsing that could otherwise open the door to denial-of-service or memory corruption exploits.
  • The xz 5.8.1 package eliminates CVE-2025-31115, closing off a vector that could allow arbitrary code execution via compromised archive files.

Beyond security patches, IPFire 2.29 Core 194 reshapes how outbound traffic is handled. A long-standing NAT behavior—where Alias IP traffic defaulted to the RED interface’s main address—has been redesigned. Now, outbound connections retain their original alias IP, improving transparency, routing consistency, and traffic diagnostics in multi-IP deployments.

This update affirms IPFire’s mission: to empower users with a firewall that evolves not just in defense, but in intelligence.

Improvement AreaDetails
Kernel UpgradeIntegrated Linux 6.12.23, delivering key enhancements in security and system stability.
Security Patches AppliedResolved critical issues: CVE-2024-8176 in expat and CVE-2025-31115 in xz, mitigating potential exploits.
Modernized IDN HandlingSwitched to libidn2 for more secure and standards-compliant international domain name resolution.
Improved NAT BehaviorAlias IP addresses now retain original identity during outbound NAT, boosting transparency and control in routing.
IPsec Cert Renewal LogicEnhanced process ensures seamless, secure VPN connectivity with timely certificate updates.
Package Ecosystem RefreshBroad security updates applied across core system and optional add-on modules.
Pakfire UI EnhancementsSmarter interface design helps prevent configuration errors and improves usability for admins.

Core System Enhancements in IPFire 2.29 Core Update 194: Smarter, Safer, and More Streamlined

In a strategic move to future-proof its infrastructure, IPFire has transitioned from libidn to libidn2 across the entire platform. This upgrade not only aligns the project with the IDNA 2008 standard, but also boosts protection against spoofing and improves domain name handling in multilingual environments—an essential evolution for global and secure networking.

Pakfire, IPFire’s native package and update manager, has undergone a thoughtful interface redesign. With contributions from developer Stephen Cuka, the latest enhancements streamline the user experience, reduce ambiguity in update workflows, and deliver more accurate translations for international users—making system maintenance smoother for administrators worldwide.

Monitoring capabilities have also been enhanced with an upgrade to Zabbix 7.0.11 LTS. This version introduces critical bug fixes and refinements, though users should be aware that it breaks compatibility with earlier 6.x Zabbix Server setups—prompting necessary alignment for those using external monitoring systems.

A broad range of system components have been refreshed, ensuring stronger security and improved compatibility:

  • BIND 9.20.8 – updated for more resilient DNS resolution
  • ca-certificates 20250317 – keeps trust chains current
  • dbus 1.16.2 – strengthens IPC across services
  • Numerous underlying libraries and essential tools have also received important updates.

For extended functionality, a suite of widely used add-ons has been upgraded:

  • Bacula 15.0.2 – enhanced backup reliability
  • FFmpeg 7.1.1 – improved media handling performance
  • Git 2.49.0 – brings better version control efficiency
  • Samba 4.22.0 – stronger interoperability and security in file sharing

The IPFire team strongly encourages users to upgrade promptly to take full advantage of these enhancements. As always, it’s recommended to back up your configurations and validate new deployments in staging environments before applying changes in production.

More Articles & Posts