# Bro 2.6.1 release

**URL:** <https://community.zeek.org/t/bro-2-6-1-release/5565>\
**Category:** Zeek\
**Created:** [December 19, 2018, 6:24pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565 "2018-12-19T18:24:28Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jon\_Siwek](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Post date:** [December 19, 2018, 6:24pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/1 "2018-12-19T18:24:28Z")

</div>

Bro v2.6.1 is available for download:

&nbsp;&nbsp;&nbsp;&nbsp;[https://www.zeek.org/download/index.html](https://www.zeek.org/download/index.html)  
&nbsp;&nbsp;&nbsp;&nbsp;[https://www.zeek.org/downloads/bro-2.6.1.tar.gz](https://www.zeek.org/downloads/bro-2.6.1.tar.gz)

This release updates the embedded SQLite to version 3.26.0 to  
address the "Magellan" remote code execution vulnerability. The  
stock Bro configuration/scripts don't use SQLite by default, but  
custom user scripts/packages may.

This release also updates Broker to v1.1.2, which includes a  
minor bug fix in its Python bindings and improved support for  
building it as a static library.

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [December 19, 2018, 7:37pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/2 "2018-12-19T19:37:23Z")

</div>

And the first casualty:

bro-af\_packet-plugin

fatal error in /usr/local/bro/share/bro/base/init-bare.bro, line 1: cannot load plugin library /usr/local/bro/lib/bro/plugins/packages/bro-af\_packet-plugin//lib/Bro-AF\_Packet.linux-x86\_64.so: /usr/local/bro/lib/bro/plugins/packages/bro-af\_packet-plugin//lib/Bro-AF\_Packet.linux-x86\_64.so: undefined symbol: bro\_version\_2\_6\_plugin\_6

bro-pkg upgrade bro-af\_packet-plugin  
All packages already up-to-date.

Now what 🙂

James

---

<div class="post-metadata">

**Author:** ![Michael\_Shirk](https://avatars.discourse-cdn.com/v4/letter/m/aeb1de/32.png) [@Michael\_Shirk](https://community.zeek.org/u/Michael_Shirk)\
**Post date:** [December 19, 2018, 8:06pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/3 "2018-12-19T20:06:00Z")

</div>

You need to rebuild the package/plugin, I think this was just added to  
the zeek package manager...or will be soon

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [December 19, 2018, 8:11pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/4 "2018-12-19T20:11:18Z")

</div>

Ok...so...this was installed using the spiffy bro-pkg, so "rebuilding" isn't an option if I intend to stick with bro-pkg. If plugins aren't going to keep in sync with the core app proper then that might be an issue (especially in my case it looks like).

James

---

<div class="post-metadata">

**Author:** ![Jon\_Siwek](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Post date:** [December 19, 2018, 8:17pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/5 "2018-12-19T20:17:58Z")

</div>

Try re-compiling/installing the plugin/package.

Plugins currently get compiled such that they reference a specific Bro  
(plugin API) version and only linking against that version of Bro  
provides it. i.e. once compiled, the plugin only works against a  
specific Bro version

- Jon

---

<div class="post-metadata">

**Author:** ![dopheide](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@dopheide](https://community.zeek.org/u/dopheide)\
**Post date:** [December 19, 2018, 8:35pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/6 "2018-12-19T20:35:53Z")

</div>

Installing a bro-pkg that is a plugin does rebuild it. They aren’t distributed as binaries.

-Dop

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [December 19, 2018, 8:42pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/7 "2018-12-19T20:42:28Z")

</div>

> Installing a bro-pkg that is a plugin does rebuild it. They aren't  
> distributed as binaries.
> 
> -Dop

Ah....I did not know that. So in the future for folks (I've already git cloned and compiled) a bro-pkg remove/bro-pkg install does the trick...good to know thank you.

James

---

<div class="post-metadata">

**Author:** ![Jon\_Siwek](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Post date:** [December 19, 2018, 8:47pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/8 "2018-12-19T20:47:31Z")

</div>

Why is it not an option? There isn't a "rebuild" command (yet), but  
the alternative given at [1] should be equivalent AFAIK, just in two  
separate commands:

&nbsp;&nbsp;&nbsp;&nbsp;bro-pkg bundle my.bundle && bro-pkg unbundle my.bundle

- Jon

[1] [https://github.com/zeek/package-manager/issues/38](https://github.com/zeek/package-manager/issues/38)

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [December 19, 2018, 9:10pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/9 "2018-12-19T21:10:25Z")

</div>

Bleh...lemme start a new thread for this thanks all.

James

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/bro-2-6-1-release/5565/10 "2022-05-06T15:46:15Z")

</div>


