v0.107.53
版本发布时间: 2024-10-03 20:46:45
AdguardTeam/AdGuardHome最新发布版本:v0.108.0-b.60(2024-11-07 00:46:35)
It's been a while since we postponed the next AdGuard Home update for a few months. But of course, we had a good reason for it: with the help of community members (we are very thankful to you! :pray:), we discovered two vulnerabilities and have been working on patching them. Testing the solutions took a bit longer than expected, but in the end, we believe in quality over speed.
Luckily, it's not all patching vulnerabilities and fixing bugs; we've made some improvements, too. For example, we've added support for 64-bit RISC-V architecture and Ecosia search engine to Safe Search. Find the complete changelog below.
Acknowledgments
A special thanks to our open-source contributor, @javabean, to @itz-d0dgy and @go-compile for reporting the vulnerabilities, our community moderators team, as well as to everyone who filed and inspected issues, added translations, and helped us test this release!
Full changelog
Security
-
Previous versions of AdGuard Home allowed users to add any system file it had access to as filters, exposing them to be world-readable. To prevent this, AdGuard Home now allows adding filtering-rule list files only from files matching the patterns enumerated in the
filtering.safe_fs_patterns
property in the configuration file.We thank @itz-d0dgy for reporting this vulnerability, designated CVE-2024-36814, to us.
-
Additionally, AdGuard Home will now try to change the permissions of its files and directories to more restrictive ones to prevent similar vulnerabilities as well as limit the access to the configuration.
We thank @go-compile for reporting this vulnerability, designated CVE-2024-36586, to us.
-
Go version has been updated to prevent the possibility of exploiting the Go vulnerabilities fixed in 1.23.2.
Added
- Support for 64-bit RISC-V architecture (#5704).
- Ecosia search engine is now supported in safe search (#5009).
Changed
- Upstream server URL domain names requirements has been relaxed and now follow the same rules as their domain specifications.
Configuration changes
In this release, the schema version has changed from 28 to 29.
- The new array
filtering.safe_fs_patterns
contains glob patterns for paths of files that can be added as local filtering-rule lists. The migration should add list files that have already been added, as well as the default value,$DATA_DIR/userfilters/*
.
Fixed
- Property
clients.runtime_sources.dhcp
in the configuration file not taking effect. - Stale Google safe search domains list (#7155).
- Bing safe search from Edge sidebar (#7154).
- Text overflow on the query log page (#7119).
Known issues
-
Due to the complexity of the Windows permissions architecture and poor support from the standard Go library, we have to postpone the proper automated Windows fix until the next release.
Temporary workaround: Set the permissions of the
AdGuardHome
directory to more restrictive ones manually. To do that:- Locate the
AdGuardHome
directory. - Right-click on it and navigate to Properties → Security → Advanced.
- (You might need to disable permission inheritance to make them more restricted.)
- Adjust to give the
Full control
access to only the user which runs AdGuard Home. Typically,Administrator
.
An example of a what a properly restricted configuration could look like:
- Locate the
1、 AdGuardHome_darwin_amd64.zip 10.28MB
2、 AdGuardHome_darwin_arm64.zip 9.78MB
3、 AdGuardHome_freebsd_386.tar.gz 9.66MB
4、 AdGuardHome_freebsd_amd64.tar.gz 10.09MB
5、 AdGuardHome_freebsd_arm64.tar.gz 9.36MB
6、 AdGuardHome_freebsd_armv5.tar.gz 9.77MB
7、 AdGuardHome_freebsd_armv6.tar.gz 9.5MB
8、 AdGuardHome_freebsd_armv7.tar.gz 9.49MB
9、 AdGuardHome_frontend.tar.gz 2.34MB
10、 AdGuardHome_linux_386.tar.gz 9.83MB
11、 AdGuardHome_linux_amd64.tar.gz 10.26MB
12、 AdGuardHome_linux_arm64.tar.gz 9.52MB
13、 AdGuardHome_linux_armv5.tar.gz 9.93MB
14、 AdGuardHome_linux_armv6.tar.gz 9.67MB
15、 AdGuardHome_linux_armv7.tar.gz 9.66MB
16、 AdGuardHome_linux_mips64le_softfloat.tar.gz 9.11MB
17、 AdGuardHome_linux_mips64_softfloat.tar.gz 9.18MB
18、 AdGuardHome_linux_mipsle_softfloat.tar.gz 9.5MB
19、 AdGuardHome_linux_mips_softfloat.tar.gz 9.56MB
20、 AdGuardHome_linux_ppc64le.tar.gz 9.49MB
21、 AdGuardHome_linux_riscv64.tar.gz 9.62MB
22、 AdGuardHome_openbsd_amd64.tar.gz 10.07MB
23、 AdGuardHome_openbsd_arm64.tar.gz 9.35MB
24、 AdGuardHome_windows_386.zip 9.51MB
25、 AdGuardHome_windows_amd64.zip 9.79MB
26、 AdGuardHome_windows_arm64.zip 9MB
27、 checksums.txt 2.56KB