Aug 20 2026
Fixed in the https://vyos.dev/T8329 for the rolling
https://github.com/vyos/vyos-build/pull/1249
https://github.com/vyos/vyos-1x/pull/5338
Aug 15 2026
I stumbled across the same issue and as far as i could debug it, its due to usb/hid devices being outosuspended by the current vyos kernel/config.
Aug 7 2026
Aug 4 2026
Jul 16 2026
Regarding (1) above: form-POST requests are preprocessed by overriding the route handler before delivery to the endpoint, hence managed by background operations as any JSON formatted request. Regarding (2), thanks for the offer to open a separate task; that would be helpful.
For clarification.
I have created a lab
Underlay: OSPF. The main function is to distribute Loopback IPs.
Overlay:
Control Plane: MP-iBGP. The main function is to distribute EVPN routes.
Data Plane: VXLAN
RR is a router reflector.
VTEP-1A and VTEP-1B contain the same ES via interface eth1
HOST-1 and HOST-2 are in the same network. 192.168.100.10/24 and 192.168.100.20/24 respectivly.
VTEP-1B is a DF router of these ES
Jul 14 2026
We hit a related but possibly distinct failure on VyOS 1.5 Circinus rolling (2026-07-06) and would like to confirm the scope of the background-operations fix (https://github.com/vyos/vyos-1x/pull/4953):
Jun 25 2026
May 21 2026
May 20 2026
Just bumped into the fact appearently this wasn't implemented for all groups, getting an "include is not valid" for a domain-group.
May 15 2026
May 13 2026
I found it with some help of claude ... It was a problem with conntrack in this setup. I could fix it on 1.4 only manual with this commands:
May 8 2026
Good to know 1.3.8 is not affected, so having been denied access to later versions saved me from this vulnerability - thanks @syncer !
BTW, please also check out Dirty Frag while you're at it, no CVE yet. Mitigation (disallow loading of modules: esp4, esp6, rxrpc) breaks ipsec.
May 2 2026
May 1 2026
Versions up to v1.3.8 are not affected. However, from v1.4.x onwards, including v1.5.0 and Rolling releases, all versions are affected.
Probably related:

