All Episodes

February 6, 2025 6 mins

We're back with our first monthly update for 2025! 

@SPXLabs is here breaking down all the latest news, including:

  • Unraid 7 Stable Release: See what's new!
  • Unraid 6.12.15 Release
  • A Coordinated Vulnerability Disclosure. All users are strongly encouraged to update to Unraid 7.0.0 or 6.12.15. Learn More 
  • New Unraid Patch Plugin: This official Unraid plugin will help protect your server by keeping the OS updated with the latest patches. Learn More:
    https://forums.unraid.net/topic/185560-unraid-patch-plugin/
  • New E-Commerce Developer Hire! 
  • New Monthly App Spotlight: ZFS Master Plugin

    And much more!  Check it all out in written form here.

    Thanks for tuning in.

Send us a text

Other Ways to Connect with the Uncast Show


Mark as Played
Transcript

Episode Transcript

Available transcripts are automatically generated. Complete accuracy is not guaranteed.
Speaker 1 (00:00):
Welcome to the Unraid January Digest.
I'm your host, stefano Partita,and we will discuss everything
that's happened in January of2025.
Let's get started.
I'm not sure how anyone wouldmiss it, because it's been

(00:20):
posted all over social media onevery website that you could
possibly imagine, because it'sbeen posted all over social
media on every website that youcould possibly imagine.
But Unraid 7 stable is here,which is great news because it
adds some features thateveryone's been waiting for, as
well as some other maybe unknownadditions that you haven't been
tracking so far, such as someDocker features like the
Tailscale integration, whichallows you to seamlessly
integrate Tailscale into Dockercontainers for more secure

(00:42):
remote access.
Fork bomb prevention, whichallows you to set PID limits to
prevent resource exhaustion andoverlay to support, which allows
for optimizing Docker storageon ZFS volumes.
There's also been networkingupgrades, like the Tailscale
plugin, which uses Tailscalecertificates to secure web UI
access and easily share Dockercontainers.

(01:04):
There's been IPv6 enhancements,which were added for dynamic
support for changing IPv4 andIPv6 addresses, and NFS
improvements for full supportfor NFS 4.1 and 4.2 protocols,
and new settings added forbetter performance.
Speaking of NFS, mac users cannow rejoice because
compatibility issues with TimeMachine and Samba shares has now

(01:26):
been fixed, so you can now usethat without any worry.
Furthermore, there have beenimprovements to the handling of
predefined shares, and foranyone that doesn't know what a
predefined share is, think ofapp data and system shares that
are pre-created for you.
So there's been enhancementsfor Docker and VMs, so that way,
if a share predefined sharedoes not exist, that will now be
created for you.
So there's been enhancementsfor Docker and VMs, so that way,
if a share predefined sharedoes not exist, that would now

(01:46):
be created for you.
And there's a lot moretechnical stuff to it than that,
but we're not going to get intothe technicality for this video
.
Other improvements includethose, as such, as dashboard
updates, where you can now viewVM usage stats, server time,
enhanced Docker RAM usagevisualization and much, much
more.
There's also a new favoritespage, which allows you to

(02:07):
quickly access frequently usedtools and settings.
And finally, there's also powermodes, which allow you to
optimize for performance,balanced operation or power
efficiency.
For anyone running olderversions of Unraid 6.12, be sure
to update to Unraid 6.12.15 soyou can take advantage of some
of the bug fixes andimprovements made to that
version, with one of the majorbug fixes being a memory leak

(02:30):
that was affecting the dashboardpage as well as the VM manager
and Docker manager pages.
There are other bug fixes andimprovements, such as the
restoration of the JavaScriptconsole logging functionality
that was available on the web UIand several others that you can
see listed here.
If bug fixes and otherimprovements aren't enough to
motivate you to update to Unraid7 or 6.12.15, then you should

(02:53):
definitely consider updating forsome of the security fixes and
patches that have been made.
There have been fourvulnerabilities that have been
identified and fixed in Unraid 7and 6.12.15.
The first vulnerabilityidentified was for cross-site
scripting, which allowedpotential attackers to inject
JavaScript via URL parametersinto the Unraid web interface,

(03:15):
and a stop gap that you can doif you are unable to upgrade to
Unraid 7 or Unraid 6.12.15 is toinstall the Unraid patch plugin
.
But remember, the Unraid pluginis only a stopgap and not a
long-term mitigation or solutionto this vulnerability.
Another vulnerability found wascross-site request forgery,

(03:35):
which allows remote attackers toinitiate authenticated Git
requests to the Unraid webinterface through top-level
navigation via the Unraidauthentication cookies.
Lacks same-site policy.
The third vulnerabilityidentified was
stored-across-site scripting,which is a low-risk
vulnerability that allowedattackers with authenticated

(03:56):
access to inject JavaScriptpayloads, which could persist in
various web interface fields.
The fourth vulnerabilityidentified was that of the
community applicationsrepository, where GitHub
repositories used by thecommunity applications app feed
could be transferred to anotherowner, opening the possibility
of hijacking the applicationtemplates.

(04:17):
If you're perhaps interested inknowing more about these
vulnerabilities, you can, ofcourse, check out the
Coordinated VulnerabilityDisclosure blog post for
yourself to get the full ins andouts of the vulnerabilities
that were discovered andrecently patched or fixed in the
latest releases.
Whoa, whoa, whoa, whoa, whoa.
Unraid patch plugin.
That's not in my notes.
We've never talked about thisbefore.

(04:38):
What do you mean?
Okay, so apparently the Unraidpatch plugin will allow Unraid
to push some security fixes aswell as other minor updates to
existing Unraid operatingsystems, so that could be pretty
useful for those of you thatare on older versions of Unraid

(04:58):
who haven't updated to thelatest and greatest versions
quite yet.
Finer details of the patchplugin can also be found on the
forum if you are at all curiousto know more information about
it.
Earlier this year, we hadannounced that Unraid had hired
a new e-commerce developer, andnow we know who this person is,
and their name is Craig Null.
For 2025, unraid would like tostart producing more content for

(05:20):
the Uncast show, and part ofthat new content is a segment
that is called the monthly appspotlight, where plugins or
applications will be featured invideo format where you can get
some new ideas or alsoinformation about said
application or plugin.
The first video is availabletoday and it's the ZFS master

(05:40):
plugin, and Space Invader 1 hascreated that video, so if you're
interested in checking that out, be sure to go to the NCAST
show and watch that video.
Video and speaking of things tocome in 2025 from an existing
partnership, there may be ahardware refresh coming that
you'll be interested in, sodefinitely keep your eyes peeled
for any announcements on theunraid website or on the uncast

(06:01):
show itself.
Finally, from community contentaround the web, you'll find
some very sweet videos that Iwould highly suggest checking
out some or all of on the UnraidJanuary Digest webpage.
You can find links for thoseYouTube videos there and I
definitely recommend checkingall of those out and, as always,
thank you for watching.
Be sure to like and getsubscribed and I will see you on

(06:21):
the next Unraid Digest.
Advertise With Us

Popular Podcasts

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

24/7 News: The Latest

24/7 News: The Latest

The latest news in 4 minutes updated every hour, every day.

Therapy Gecko

Therapy Gecko

An unlicensed lizard psychologist travels the universe talking to strangers about absolutely nothing. TO CALL THE GECKO: follow me on https://www.twitch.tv/lyleforever to get a notification for when I am taking calls. I am usually live Mondays, Wednesdays, and Fridays but lately a lot of other times too. I am a gecko.

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.