Release Notes CSG 7.2.48

Collax Security Gateway
09.09.2026

Installation Notes

Update Instructions

To install this update please follow the following steps:

Procedure

  1. It is highly recommended to backup of all server data with the Collax backup system before proceeding. Check that the backup was successful before proceeding with the update (this can be done within the backup information email).
  2. In the administration interface go to Menu → Software → System Update and press Get Package List. This will download the listed update packages. If successful the message Done! will be displayed on the screen.
  3. Click Get Packages to download the update packages.
  4. Click Install. This installs the update. The end of this process is indicated by the message Done!.
  5. A new kernel will now be installed. The system will reboot automatically after installing the update. An appropriate note will be shown if the update process is completed.

New in this version

Toolbox: Checking Emails and Files

A new form for checking emails and files is now available in the Toolbox. Suspicious emails can be uploaded. A result is then displayed for each scanner; email containers are unpacked and their attachments are checked individually, including not only the standard email format but also winmail.dat and Outlook messages in .msg format.

Firewall: Enable or Disable Port Forwarding with a Right-Click

In the port forwarding overview, you can now enable or disable individual rules directly with a right-click. Previously, you had to go through the details view each time to do this.

System Management: Daily License Check

The license status is now checked daily instead of weekly. This means that the automatic switch from expiring Avira licenses to Collax Virus Protection takes effect more quickly.

Issues fixed in this version

System Management: Linux Kernel 6.6.156

This update upgrades the Linux kernel to version 6.6.156.

A critical security vulnerability in the Linux kernel that allowed locally logged-in users to gain root privileges has been patched. As a general rule, no user should be granted SSH access to the server.

Security: Red Team Assessment of the Collax Security Gateway

The Collax Security Gateway was assessed as part of a red team assessment conducted by the external security service provider turingpoint GmbH from Hamburg. The vulnerabilities reported during this assessment have been addressed in this update. The fixes apply to shared components and therefore affect all Collax products.

Security: Login and Privilege Wrappers

The login process for the administration interface has been revised. Login credentials can no longer be read by scripts in the browser, and the previous login path used to access the interface has been removed. In addition, the privilege wrappers (suwrap) for the administration interface have been hardened.

Security: ClamAV 1.4.5

The ClamAV virus scanner has been updated to the current LTS version, 1.4.5. Version 1.0.x, which was previously in use, is no longer supported by the developers, which is why the warning “Your ClamAV installation is OUTDATED!” appeared in the log. This warning no longer appears; detection itself was not affected by this issue.

Security: ProFTPD

Security vulnerabilities that had been reported for the ProFTPD FTP server have been patched.

DHCP: Address Assignment from a Different Pool

Under certain circumstances, the DHCP server might have assigned an address from a different pool to a computer. This issue has been resolved.

Please note: If a pool is exhausted, addresses from another pool will no longer be assigned to the affected computers. They will then remain without an address.

System Management: Minibus on Processors Without AVX2

On older processors without AVX2 support, the Minibus service would not start and was reported as an error in the monitoring system. This has now been fixed.

Mail: REDIRECT Rules in the Mail Filter

In the mail filter, REDIRECT rules pointing to an address within the organization’s own mail domain resulted in a bounce with the message “User unknown in virtual alias table.” The addresses are now resolved correctly.

Certificates: Error Messages from Let’s Encrypt

If the issuance of a Let’s Encrypt certificate failed, the process previously resulted in a generic timeout. The job log now includes the affected domain and the reason reported by Let’s Encrypt.

Proxy: Collax URL Filter

The URL filtering functionality of the Collax URL Filter in the web proxy has been revised.

Notes

Additional software: Bitdefender - pattern update after commissioning

After starting up the Collax Antivirus powered by Bitdefender module, it may take a few minutes for the current virus patterns to be downloaded. If you click on Update Bitdefender in the virus scanner form during this time, you will receive an error message “Error connecting to server at /opt/lib/bitdefender//bdamsocket: -3”, because the background process has not yet been fully executed.

GUI: Sporadic hangs during running jobs

The progress of configuration jobs is displayed in the top right-hand corner of the web administration. In the case of extensive changes in the network area, especially with country locks (geo-ip), it can happen in rare cases that the job display hangs during activation. As of release 7.2.28, you will now receive the message “Network connection has been interrupted: Messages may be lost until the connection can be re-established.” informs you about such situations.

VPN: Fix for IKEv2 with Microsoft Windows crashes after 7.6 hours

VPN connections with IKEv2 and the on-board tools of Microsoft Windows are interrupted after interrupted after exactly 7.6 hours. The error occurs because Microsoft Windows proposes different algorithms during the IKE re-encryption than during the first connection. The problem can be solved with a registry fix by the value “NegotiateDH2048_AES256” under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters to 1 is set.

Under the following link you will find a REG file (registry entry) that adds the registry key. Collax accepts no liability for system errors resulting from this.