Skip to content

pi-hole

v6.4.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Privacy & Ad-blocking
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ad-blocker blocker cloud web dhcp dhcp-server
+5 more
dns dnsmasq pi-hole raspberry-pi shell

Summary

AI summary

Security advisory GHSA-6w8x-p785-6pm4 fixed.

Full changelog

What's Changed

  • Wipe version file before creating a new one by @yubiuser in https://github.com/pi-hole/pi-hole/pull/6538
  • Fix ownership permissions for containing directories in fix_owner_per… by @PromoFaux in https://github.com/pi-hole/pi-hole/pull/6589
  • Remove reference to /usr/local/bin/COL_TABLE by @darkexplosiveqwx in https://github.com/pi-hole/pi-hole/pull/6594
  • Skip apt cache update when pihole-meta is current by @PromoFaux in https://github.com/pi-hole/pi-hole/pull/6581
  • Set versions in /etc/pihole/versions to null if script fails by @yubiuser in https://github.com/pi-hole/pi-hole/pull/6550
  • Remove redundant touching of logfiles from systemd Service by @yubiuser in https://github.com/pi-hole/pi-hole/pull/6601
  • Loosen requirements for local file access for gravity by @yubiuser in https://github.com/pi-hole/pi-hole/pull/6430
  • Fix permission for *.etag files after gravity run by @yubiuser in https://github.com/pi-hole/pi-hole/pull/6353
  • add logrotate to DEB and RPM dependencies by @darkexplosiveqwx in https://github.com/pi-hole/pi-hole/pull/6524
  • Improve gravity error message including curl exit code and errormsg by @rdwebdesign in https://github.com/pi-hole/pi-hole/pull/6605

Security advisories

  • https://github.com/pi-hole/pi-hole/security/advisories/GHSA-6w8x-p785-6pm4
    • Fixed with : https://github.com/pi-hole/pi-hole/commit/7ccb8ddfb085479fa96e801886eb1cdbeaf3a720 and https://github.com/pi-hole/FTL/commit/88c569aa026d905d0066135bb71f36a13acf4bf4

Full Changelog: https://github.com/pi-hole/pi-hole/compare/v6.4.1...v6.4.2

Security Fixes

  • GHSA-6w8x-p785-6pm4

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track pi-hole

Get notified when new releases ship.

Sign up free

About pi-hole

A black hole for Internet advertisements

All releases →

Beta — feedback welcome: [email protected]