From 6cedb8b6aa0ad08b8d55f6bc44dadc9c622f17f7 Mon Sep 17 00:00:00 2001 From: Shizuo Fujita Date: Tue, 29 Sep 2026 11:28:57 +0900 Subject: [PATCH] Add Fluentd v1.19.4 and Fluent Package v6.0.5 Signed-off-by: Shizuo Fujita --- ...fluent-package-v6.0.5-has-been-released.md | 123 ++++++++++++++++++ ...60929_fluentd-v1.19.4-has-been-released.md | 110 ++++++++++++++++ content/blog/tag/announcement | 4 +- content/blog/tag/fluent-package | 3 +- content/blog/tag/fluentd | 4 +- 5 files changed, 241 insertions(+), 3 deletions(-) create mode 100644 content/blog/20260929_fluent-package-v6.0.5-has-been-released.md create mode 100644 content/blog/20260929_fluentd-v1.19.4-has-been-released.md diff --git a/content/blog/20260929_fluent-package-v6.0.5-has-been-released.md b/content/blog/20260929_fluent-package-v6.0.5-has-been-released.md new file mode 100644 index 00000000..d597a3d6 --- /dev/null +++ b/content/blog/20260929_fluent-package-v6.0.5-has-been-released.md @@ -0,0 +1,123 @@ +# fluent-package v6.0.5 has been released + +Hi users! + +We have released fluent-package [v6.0.5](https://github.com/fluent/fluent-package-builder/releases/tag/v6.0.5) on 2026-09-29. +Fluent Package is a stable distribution package of Fluentd. (successor of td-agent) + +This is a maintenance release of v6.0.x LTS series. + + + +## Fluent Package v6.0.5 + +Fluent Package v6.0.5 includes the following improvements: + +* Updated bundled Fluentd to v1.19.4 which fixes some vulnerabilities +* Updated bundled Ruby to 3.4.11 +* Updated bundled gems which fix vulnerabilities and crashes (`oj`, `json`) +* msi: Fixed a broken link to enterprise services on the popup window of the Windows installer +* rpm: Kept compatibility with older RHEL 9.x and 10.x +* deb rpm: Reduced build time by disabling LTO on RHEL 10 and Ubuntu + +This article explains the changes in Fluent Package v6.0.5. + +## Changes + +### Updated bundled Fluentd to v1.19.4 which fixes some vulnerabilities + +In this release, some critical vulnerabilities were fixed. + +* [Incomplete Fix for CVE-2026-44024: Path Traversal Bypass via Bare `..` Tag in Output Plugins](https://github.com/fluent/fluentd/security/advisories/GHSA-5hq3-r276-rfr5) + * CVE ID pending (this page will be updated once assigned) + * CVSS v3 score: 7.5/10 (High) + * Workarounds: Restrict network access, allow connection within a closed, trusted network. Run fluentd as non-root user. Do not use the `${tag}` placeholder in the path parameter of output plugins. Filter incoming untrusted tags. +* [Out-of-Memory DoS via Object Allocation Amplification in `in_http` ndjson parsing](https://github.com/fluent/fluentd/security/advisories/GHSA-g69w-f42r-xp35) + * CVE ID pending (this page will be updated once assigned) + * CVSS v3 score: 7.5/10 (High) + * Workarounds: Restrict network access for `in_http`, allow connection within a closed, trusted network. Implement reverse proxy limits with forcing strict rate limiting and request size limits at the proxy layer to drop anomalous requests before they reach the Fluentd worker. +* [Out-of-Memory DoS via Unbounded TCP/TLS Connection Buffer in `in_syslog`](https://github.com/fluent/fluentd/security/advisories/GHSA-h3xv-5jpx-r4j2) + * CVE ID pending (this page will be updated once assigned) + * CVSS v3 score: 7.5/10 (High) + * Workarounds: Restrict network access for `in_syslog`, allow connection within a closed, trusted network. Switch to UDP Transport for a while. Implement reverse proxy limits with strict client connection timeout and buffer size limits to terminate anomalous, non-delimited streams before they overwhelm Fluentd. +* [Incomplete Fix for CVE-2026-44160: DoS via Unbounded Decompression in Buffer Chunk Streaming](https://github.com/fluent/fluentd/security/advisories/GHSA-x455-r5cg-h9p9) + * CVE ID pending (this page will be updated once assigned) + * CVSS v3 score: 2.9/10 (Low) + * Workarounds: Disable buffer compression. Disable automatic chunk backup with `disable_chunk_backup true`. Restrict incoming data only within a closed, trusted network. + +The above vulnerabilities affects to older than v1.19.4, thus the following packages also will be affected. + +* fluent-package LTS v6.0.4 or earlier +* fluent-package Standard edition v6.0.0 (NOTE: no patched version planned yet, please consider to use LTS) +* fluent-package LTS v5.0.9 or earlier (NOTE: v5.0.x already reached EOL, no patched updates anymore) +* fluent-package Standard edition v5.2.0 or earlier (NOTE: v5.x already reached EOL, no patched updates anymore) +* All of td-agent (NOTE: td-agent already reached EOL, no patched updates anymore) + +We recommend upgrading fluent-package to v6.0.5. + +If you can't upgrade it immediately, there is a case that mitigation method is explained in above advisory. +Please check each advisory and take care of it. + +Fluentd v1.19.4 also contains many bug fixes. See [the release announcement of Fluentd v1.19.4](/blog/fluentd-v1.19.4-has-been-released) for details. + +### Updated bundled Ruby to 3.4.11 + +Ruby 3.4.11 is a maintenance release. Compared to Ruby 3.4.9 which was bundled in the previous version, it includes the following security fixes in bundled gems: + +* `net-imap`: [CVE-2026-47240](https://github.com/advisories/GHSA-8p34-64r3-mwg8), [CVE-2026-47241](https://github.com/advisories/GHSA-c4fp-cxrr-mj66), [CVE-2026-47242](https://github.com/advisories/GHSA-46q3-7gv7-qmgg) (fixed in Ruby 3.4.10) +* `resolv`: [CVE-2026-80212 and CVE-2026-80213](https://www.ruby-lang.org/en/news/2026/08/27/multiple-vulnerabilities-in-resolv/) (fixed in Ruby 3.4.11) + +For details, please see the [Ruby 3.4.10](https://www.ruby-lang.org/en/news/2026/06/30/ruby-3-4-10-released/) and [Ruby 3.4.11](https://www.ruby-lang.org/en/news/2026/09/23/ruby-3-4-11-released/) release notes. + +### msi: fixed a broken link to enterprise services on popup window + +The link to the enterprise services page on the popup window of the Windows installer was broken. +It has been fixed in this release. ([#1079](https://github.com/fluent/fluent-package-builder/pull/1079)) + +### rpm: keep compatibility with older RHEL 9.x and 10.x + +The packages for RHEL 9.x and 10.x were built on the latest minor version of each series. +As a result, the built binaries required newer symbols such as `GLIBC_2.35` or `OPENSSL_3.4.0`, +and they did not work on older minor versions like RHEL 9.6 or RHEL 10.1. + +To keep the ABI compatible in the whole 9.x and 10.x series, the build environment is now pinned to +RHEL 9.2 and RHEL 10.0. ([#1089](https://github.com/fluent/fluent-package-builder/pull/1089), [#1090](https://github.com/fluent/fluent-package-builder/pull/1090)) + +This issue was fixed and shipped as 6.0.4-2 on above platforms which had been implemented in advance, has now been officially released. + +### rpm deb: disable LTO for RHEL 10 and Ubuntu + +RPM 4.19 (AlmaLinux 10) and `dpkg-buildflags` on Ubuntu export LTO (Link Time Optimization) flags +(`-flto=auto -ffat-lto-objects`) into the build process. These flags leaked into jemalloc, Ruby and +native gem extensions, and made the build much slower. For example, the total build time on AlmaLinux 10 +grew extraordinaly. + +Since the bundled Ruby uses its own optimization settings, LTO gives no measurable benefit here. +So we removed the LTO flags and the annobin plugin from the build environment. +The hardening flags such as stack protection, control flow protection and `FORTIFY_SOURCE` are kept as before. + +This change also means that native extensions which users build with `fluent-gem install` no longer +inherit the LTO overhead. ([#1102](https://github.com/fluent/fluent-package-builder/pull/1102)) + +## Download + +Please visit [the download page](/download/fluent_package). + +## Announcement + +### About next LTS schedule + +We plan to release the next LTS version of fluent-package v6.0.6 at Dec 2026. +The content of updates are still TBD. + +### Follow us on X + +We have been posting information about Fluentd in Japanese on [@fluentd_jp](https://x.com/fluentd_jp). +We would appreciate it if you followed the X account. + +TAG: Fluentd fluent-package Announcement +AUTHOR: clearcode diff --git a/content/blog/20260929_fluentd-v1.19.4-has-been-released.md b/content/blog/20260929_fluentd-v1.19.4-has-been-released.md new file mode 100644 index 00000000..bb55eb0c --- /dev/null +++ b/content/blog/20260929_fluentd-v1.19.4-has-been-released.md @@ -0,0 +1,110 @@ +# Fluentd v1.19.4 has been released + +Hi users! + +We have released v1.19.4 on 2026-09-29. +ChangeLog is [here](https://github.com/fluent/fluentd/blob/v1.19/CHANGELOG.md#release-v1194---20260929). + +This release is a maintenance release of v1.19 series. + + + +This release will be bundled for `fluent-package` LTS version v6.0.5! + +## Security Fixes + +Many vulnerabilities were fixed in this release. + +* [Incomplete Fix for CVE-2026-44024: Path Traversal Bypass via Bare `..` Tag in Output Plugins](https://github.com/fluent/fluentd/security/advisories/GHSA-5hq3-r276-rfr5) + * CVE ID pending (this page will be updated once assigned) + * CVSS v3 score: 7.5/10 (High) + * Workarounds: Restrict network access, allow connection within a closed, trusted network. Run fluentd as non-root user. Do not use the `${tag}` placeholder in the path parameter of output plugins. Filter incoming untrusted tags. +* [Out-of-Memory DoS via Object Allocation Amplification in `in_http` ndjson parsing](https://github.com/fluent/fluentd/security/advisories/GHSA-g69w-f42r-xp35) + * CVE ID pending (this page will be updated once assigned) + * CVSS v3 score: 7.5/10 (High) + * Workarounds: Restrict network access for `in_http`, allow connection within a closed, trusted network. Implement reverse proxy limits with forcing strict rate limiting and request size limits at the proxy layer to drop anomalous requests before they reach the Fluentd worker. +* [Out-of-Memory DoS via Unbounded TCP/TLS Connection Buffer in `in_syslog`](https://github.com/fluent/fluentd/security/advisories/GHSA-h3xv-5jpx-r4j2) + * CVE ID pending (this page will be updated once assigned) + * CVSS v3 score: 7.5/10 (High) + * Workarounds: Restrict network access for `in_syslog`, allow connection within a closed, trusted network. Switch to UDP Transport for a while. Implement reverse proxy limits with strict client connection timeout and buffer size limits to terminate anomalous, non-delimited streams before they overwhelm Fluentd. +* [Incomplete Fix for CVE-2026-44160: DoS via Unbounded Decompression in Buffer Chunk Streaming](https://github.com/fluent/fluentd/security/advisories/GHSA-x455-r5cg-h9p9) + * CVE ID pending (this page will be updated once assigned) + * CVSS v3 score: 2.9/10 (Low) + * Workarounds: Disable buffer compression. Disable automatic chunk backup with `disable_chunk_backup true`. Restrict incoming data only within a closed, trusted network. + +In most cases, there is no problem using deployed Fluentd within a closed, trusted network. +If you could not update Fluentd immediately, consider to take advised mitigation in above advisories. + +## Bug Fixes + +Many bugs were also fixed in this release. + +* `output`: fix JSON::GeneratorError as unrecoverable error. ([#5423](https://github.com/fluent/fluentd/pull/5423)) + * Failure for content reasons (e.g. non-UTF-8 bytes, NaN/Infinity), is treated as a bad chunk. +* Set `allow_duplicate_key` parameter for `JSON.parse`. It accept duplicate keys silently + (last value wins) on every path. It keeps compatibility with older versions even though + newer `json` gem is used. ([#5430](https://github.com/fluent/fluentd/pull/5430)) +* Set `allow_comments` parameter for `JSON.parse`. It accepts JSON with comments. + It keeps compatibility with older versions even though newer `json` gem is used. ([#5432](https://github.com/fluent/fluentd/pull/5432)) +* Accept a bare scalar for an array option in YAML syntax ([#5433](https://github.com/fluent/fluentd/pull/5433)) +* `parser_syslog`: Optimize RFC5424 structured data parsing ([#5444](https://github.com/fluent/fluentd/pull/5444)) + * It avoids excessive backtracking when parsing malformed RFC5424 structured data. +* `out_forward`: drop keepalive sockets with failed or mismatched acks ([#5445](https://github.com/fluent/fluentd/pull/5445)) + * It stops the endless "ack in response and chunk id in sent data are different" warning storm by + discarding (instead of reusing) a keepalive socket. +* `buffer`: fix `stage_byte_size` leak when a staged chunk is unstaged ([#5456](https://github.com/fluent/fluentd/pull/5456)) + * There was a possibility that it could eventually raise spurious `BufferOverflowError`. + It affects plugins which implementing `#format`. +* `plugin base`: bound the number of worker lock files by hashing the path into a fixed set of buckets. ([#5471](https://github.com/fluent/fluentd/pull/5471)) +* `supervisor`: reduce memory usage of `cleanup_lock_dir` with huge number of lock files ([#5472](https://github.com/fluent/fluentd/pull/5472)) +* `config`: accept empty lines in quoted strings ([#5478](https://github.com/fluent/fluentd/pull/5478)) +* `chunk`: ensure to close the Tempfile for decompressed data ([#5486](https://github.com/fluent/fluentd/pull/5486)) +* `buffer`: fix spurious `BufferOverflowError` caused by queue_size leaking when a chunk purge fails ([#5487](https://github.com/fluent/fluentd/pull/5487)) +* `buffer`: clamp exported buffer size metrics to non-negative values ([#5488](https://github.com/fluent/fluentd/pull/5488)) +* Support json gem v3.x ([#5493](https://github.com/fluent/fluentd/pull/5493)) +* `parser_syslog`: fix NameError when RFC3164 timestamp has repeated spaces ([#5497](https://github.com/fluent/fluentd/pull/5497)) +* `parser_syslog`: fix NameError when RFC5424 timestamp has repeated spaces ([#5500](https://github.com/fluent/fluentd/pull/5500)) + +### Accept a bare scalar for an array option in YAML syntax + +In the previous versions, a single scalar value for an array option is rejected in YAML config syntax. + +Since v1.19.4, it accepts the following example. + +``` +config: + - match: + $tag: "**" + $type: http + retryable_response_codes: 503 +``` + +### plugin base: bound the number of worker lock files by hashing the path into a fixed set of buckets + +When `workers > 1`, `out_file` (with `append`) and +`out_secondary_file` take an inter-worker lock per output path, and +`get_lock_path` derives one lock file per path: +`/tmp/fluentd-lock-*/fluentd-.lock`. + +In the previous versions, a lock file is never removed while fluentd +is running; the only cleanup is `cleanup_lock_dir` at a graceful +shutdown. So the number of lock files grows with the number of unique +output paths, and with a date or a tag placeholder in `path` that set +is effectively unbounded over time. + +In this release, the number of lock files is now bounded by a constant +instead of by the number of unique paths. The accumulation, the mass +deletion at shutdown, and the dependence on an external tmp cleaner +all disappear structurally rather than being mitigated. + +Enjoy logging! + +### Follow us on X + +We have been posting information about Fluentd in Japanese on [@fluentd_jp](https://x.com/fluentd_jp). +We would appreciate it if you followed the X account. + +TAG: Fluentd Announcement +AUTHOR: clearcode diff --git a/content/blog/tag/announcement b/content/blog/tag/announcement index 268d9008..7c8a34cf 100644 --- a/content/blog/tag/announcement +++ b/content/blog/tag/announcement @@ -163,4 +163,6 @@ /blog/20260327_fluent-package-v6.0.3-has-been-released /blog/20260625_fluentd-v1.19.3-has-been-released /blog/20260626_fluent-package-v6.0.4-has-been-released -/blog/20260814_fluent-package-v7-scheduled-lifecycle \ No newline at end of file +/blog/20260814_fluent-package-v7-scheduled-lifecycle +/blog/20260929_fluent-package-v6.0.5-has-been-released +/blog/20260929_fluentd-v1.19.4-has-been-released \ No newline at end of file diff --git a/content/blog/tag/fluent-package b/content/blog/tag/fluent-package index 0aa44b9f..491efd56 100644 --- a/content/blog/tag/fluent-package +++ b/content/blog/tag/fluent-package @@ -18,4 +18,5 @@ /blog/20260227_fluent-package-v6.0.2-has-been-released /blog/20260327_fluent-package-v6.0.3-has-been-released /blog/20260626_fluent-package-v6.0.4-has-been-released -/blog/20260814_fluent-package-v7-scheduled-lifecycle \ No newline at end of file +/blog/20260814_fluent-package-v7-scheduled-lifecycle +/blog/20260929_fluent-package-v6.0.5-has-been-released \ No newline at end of file diff --git a/content/blog/tag/fluentd b/content/blog/tag/fluentd index 997319c8..710b714e 100644 --- a/content/blog/tag/fluentd +++ b/content/blog/tag/fluentd @@ -172,4 +172,6 @@ /blog/20260327_fluent-package-v6.0.3-has-been-released /blog/20260625_fluentd-v1.19.3-has-been-released /blog/20260626_fluent-package-v6.0.4-has-been-released -/blog/20260814_fluent-package-v7-scheduled-lifecycle \ No newline at end of file +/blog/20260814_fluent-package-v7-scheduled-lifecycle +/blog/20260929_fluent-package-v6.0.5-has-been-released +/blog/20260929_fluentd-v1.19.4-has-been-released \ No newline at end of file