Jump to content

Firmware release notes 4.8.3

From SpinetiX Wiki
Release name: "Stecknadelhorn" 4.8.3. Release date: May 2nd, 2024.
Applies to HMP400, HMP400W, iBX410, iBX410W, iBX440, HMP350, HMP300, DiVA, and third-party players.
Firmware version number: 4.8.3-1.0.0-45ef4dae
Note Note:
For other versions, see the DSOS release notes page.

Improvements

  • Display power schedule changes no longer require a reboot to be applied.
  • Recovery console is updated to version 2.18.2.
  • It is now possible to configure web page layers to run in secure context, as if they were loaded via HTTPS; this is controlled by the new spx:secureContext attribute, which defaults to false for backwards compatibility. Running in a secure context allows access to some restricted HTML APIs, like audio and video capture, but disables loading of content from HTTP sources


Applies to iBX440 only.

  • Multi-output configurations now support individual rotation of each display, using per output attributes; no particular Feature Set is required for using the rotation, but the resulting display layout should be compatible with the Feature Set activated on the player.

Fixes

  • The buffer size used for streaming was too small for high resolutions streams with bursty bitrates, and could cause lost video frames from streaming sources.
  • Configuring SNMP as "open to everybody" after having configured it to be open for only some IP addresses resulted in SNMP still being partially restricted to those IP addresses.
  • The power_state indicator in the display-info did not always reflect the true value of the display power state set by the player.
  • The Control Center wizard did not clear the previous display configuration before applying the new one, which could result in mixed display configurations.
  • When disabling a display power schedule not all the related services were disabled, the serial port part remained active.


Applies to iBX440 only.

  • Images downloaded from remote servers were downscaled to 4K resolution although decoding 8K images is supported, they are now downscaled to 8K on these players.


Applies to iBX410 and third-party players using Elkhart Lake Intel CPUs


Applies to HMP400, HMP400W, iBX410, iBX440, and third-party players

  • The unused grub components removed from DSOS in 4.8.2 were not removed during firmware updates, only on newly installed DSOS.
  • Spurious error messages related to the "wlan-cfg" network interface from various network daemons appeared when resetting a device to factory default settings.


Applies to HMP300, HMP350, and DiVA

  • A spurious "failed to run licensecheck" error message appeared in the system log, but these player models do not need any license check.

Security

Updated base libraries and components, the main changes are as follows:

  • binutils: fixed CVE-2022-47007, CVE-2022-47008, CVE-2022-47010, CVE-2022-47011, CVE-2022-48063 and CVE-2022-47695, none of which affected DSOS.
  • curl: fixed CVE-2023-46218, which affected DSOS.
  • gnutls: fixed CVE-2023-5981 and CVE-2024-0553, both if which may have affected DSOS.
  • httpd: update from version 2.4.57 to 2.4.58, which fixes CVE-2023-31122 and CVE-2023-43622, none of which affected DSOS.
  • libxml2: fixed CVE-2023-45322, which affected DSOS.
  • ncurses: fixed CVE-2023-29491, which did not affect DSOS.
  • openssh: fixed CVE-2023-48795 and CVE-2023-51385, none of which affected DSOS.
  • sqlite3: fixed CVE-2023-7104, which may have affected DSOS.
  • tzdata: updated from version 2023c to 2024a, affecting Ittoqqortoormiit, Vostok, Casey, Palestine, Kazakhstan.


Applies to HMP400, HMP400W, iBX410, iBX440, and third-party players.

Updated Linux kernel from version 5.15.133 to 5.15.137, which fixes the following vulnerabilities.

  • That affected DSOS: CVE-2023-42754, CVE-2023-52501, CVE-2023-52580, CVE-2023-52527, CVE-2023-52523, CVE-2023-52522, CVE-2023-52531, CVE-2023-52477, CVE-2023-52504, CVE-2023-52476 and CVE-2023-5717.
  • That did not affect DSOS: CVE-2023-52574, CVE-2023-52484, CVE-2023-4563, CVE-2023-52500, CVE-2023-52482, CVE-2023-52511, CVE-2023-52516, CVE-2023-4244, CVE-2023-52517, CVE-2023-52563, CVE-2023-52578, CVE-2023-5197, CVE-2023-52566, CVE-2023-52573, CVE-2023-34324, CVE-2023-52519, CVE-2024-0641, CVE-2023-31085, CVE-2023-52479, CVE-2023-52513, CVE-2023-52529, CVE-2023-52528, CVE-2023-5158, CVE-2023-52475, CVE-2023-52559, CVE-2023-52509, CVE-2023-52510, CVE-2023-52520, CVE-2023-52507, CVE-2023-52515, CVE-2023-52478, CVE-2023-52503, CVE-2023-52502, CVE-2023-35827, CVE-2023-52499, CVE-2023-46343, CVE-2023-52483 and CVE-2023-46813.
  • bluez: fixed CVE-2023-45866, which did not affect DSOS.
  • flac: fixed CVE-2021-0561, which may have affected DSOS.
  • linux-firmware: updated to version 20231030
We use only essential cookies for site functionality.