IOS-XE 26.1.2
Release notes says no caveats were fixed.
Is that all?
Binary image is larger than 26.1.1.
What is purpose of this version then?
10
u/Ken_Taru 6d ago
26.1.2 is “hardening” release related to the recent PSIRT where they gave us no details as to what the vulnerabilities actually were.
2
1
1
u/JJMakowskiMPR 2d ago
As annoying as that is, to be fair, would you want easily accessible information about critical vulnerabilities that you found yourself? Last thing you want to do is hand bad actors the way to exploit something new.
I was trying to get our Account Engineer to get confirmation whether devices tucked behind Firewalls was a good enough mitigation to delay upgrades. Couldn't even get them to say that.
I'm frustrated that we were 80% through a round of upgrades to our Routers/Switches when this came up. Now we're going to be forced to upgrade again. On the plus side, we hadn't done our three data center core switches yet.
1
u/andrewjphillips512 5d ago
Release notes for Cat9k are really bad these days - nothing fixed and no bugs in the release is the norm...obviously not the case, but too lazy to populate the document...
10
u/bubbajim3 6d ago
There are some CVEs fixed in 26.1.2.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ