Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
123 changes: 123 additions & 0 deletions content/blog/20260929_fluent-package-v6.0.5-has-been-released.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,123 @@
# fluent-package v6.0.5 has been released

Hi users!

We have released fluent-package [v6.0.5](https://github.com/fluent/fluent-package-builder/releases/tag/v6.0.5) on 2026-09-29.
Fluent Package is a stable distribution package of Fluentd. (successor of td-agent)

This is a maintenance release of v6.0.x LTS series.

<div markdown="span" class="alert alert-danger" role="alert">
This release fixes some vulnerabilities which were resolved in Fluentd v1.19.4, and also in the bundled oj and json gems.
As fluentd will be deployed to internal/trusted networks usually, so they will not affect you,
but we recommend to upgrade to v6.0.5.
</div>

## Fluent Package v6.0.5

Fluent Package v6.0.5 includes the following improvements:

* Updated bundled Fluentd to v1.19.4 which fixes some vulnerabilities
* Updated bundled Ruby to 3.4.11
* Updated bundled gems which fix vulnerabilities and crashes (`oj`, `json`)
* msi: Fixed a broken link to enterprise services on the popup window of the Windows installer
* rpm: Kept compatibility with older RHEL 9.x and 10.x
* deb rpm: Reduced build time by disabling LTO on RHEL 10 and Ubuntu

This article explains the changes in Fluent Package v6.0.5.

## Changes

### Updated bundled Fluentd to v1.19.4 which fixes some vulnerabilities

In this release, some critical vulnerabilities were fixed.

* [Incomplete Fix for CVE-2026-44024: Path Traversal Bypass via Bare `..` Tag in Output Plugins](https://github.com/fluent/fluentd/security/advisories/GHSA-5hq3-r276-rfr5)
* CVE ID pending (this page will be updated once assigned)
* CVSS v3 score: 7.5/10 (High)
* Workarounds: Restrict network access, allow connection within a closed, trusted network. Run fluentd as non-root user. Do not use the `${tag}` placeholder in the path parameter of output plugins. Filter incoming untrusted tags.
* [Out-of-Memory DoS via Object Allocation Amplification in `in_http` ndjson parsing](https://github.com/fluent/fluentd/security/advisories/GHSA-g69w-f42r-xp35)
* CVE ID pending (this page will be updated once assigned)
* CVSS v3 score: 7.5/10 (High)
* Workarounds: Restrict network access for `in_http`, allow connection within a closed, trusted network. Implement reverse proxy limits with forcing strict rate limiting and request size limits at the proxy layer to drop anomalous requests before they reach the Fluentd worker.
* [Out-of-Memory DoS via Unbounded TCP/TLS Connection Buffer in `in_syslog`](https://github.com/fluent/fluentd/security/advisories/GHSA-h3xv-5jpx-r4j2)
* CVE ID pending (this page will be updated once assigned)
* CVSS v3 score: 7.5/10 (High)
* Workarounds: Restrict network access for `in_syslog`, allow connection within a closed, trusted network. Switch to UDP Transport for a while. Implement reverse proxy limits with strict client connection timeout and buffer size limits to terminate anomalous, non-delimited streams before they overwhelm Fluentd.
* [Incomplete Fix for CVE-2026-44160: DoS via Unbounded Decompression in Buffer Chunk Streaming](https://github.com/fluent/fluentd/security/advisories/GHSA-x455-r5cg-h9p9)
* CVE ID pending (this page will be updated once assigned)
* CVSS v3 score: 2.9/10 (Low)
* Workarounds: Disable buffer compression. Disable automatic chunk backup with `disable_chunk_backup true`. Restrict incoming data only within a closed, trusted network.

The above vulnerabilities affects to older than v1.19.4, thus the following packages also will be affected.

* fluent-package LTS v6.0.4 or earlier
* fluent-package Standard edition v6.0.0 (NOTE: no patched version planned yet, please consider to use LTS)
* fluent-package LTS v5.0.9 or earlier (NOTE: v5.0.x already reached EOL, no patched updates anymore)
* fluent-package Standard edition v5.2.0 or earlier (NOTE: v5.x already reached EOL, no patched updates anymore)
* All of td-agent (NOTE: td-agent already reached EOL, no patched updates anymore)

We recommend upgrading fluent-package to v6.0.5.

If you can't upgrade it immediately, there is a case that mitigation method is explained in above advisory.
Please check each advisory and take care of it.

Fluentd v1.19.4 also contains many bug fixes. See [the release announcement of Fluentd v1.19.4](/blog/fluentd-v1.19.4-has-been-released) for details.

### Updated bundled Ruby to 3.4.11

Ruby 3.4.11 is a maintenance release. Compared to Ruby 3.4.9 which was bundled in the previous version, it includes the following security fixes in bundled gems:

* `net-imap`: [CVE-2026-47240](https://github.com/advisories/GHSA-8p34-64r3-mwg8), [CVE-2026-47241](https://github.com/advisories/GHSA-c4fp-cxrr-mj66), [CVE-2026-47242](https://github.com/advisories/GHSA-46q3-7gv7-qmgg) (fixed in Ruby 3.4.10)
* `resolv`: [CVE-2026-80212 and CVE-2026-80213](https://www.ruby-lang.org/en/news/2026/08/27/multiple-vulnerabilities-in-resolv/) (fixed in Ruby 3.4.11)

For details, please see the [Ruby 3.4.10](https://www.ruby-lang.org/en/news/2026/06/30/ruby-3-4-10-released/) and [Ruby 3.4.11](https://www.ruby-lang.org/en/news/2026/09/23/ruby-3-4-11-released/) release notes.

### msi: fixed a broken link to enterprise services on popup window

The link to the enterprise services page on the popup window of the Windows installer was broken.
It has been fixed in this release. ([#1079](https://github.com/fluent/fluent-package-builder/pull/1079))

### rpm: keep compatibility with older RHEL 9.x and 10.x

The packages for RHEL 9.x and 10.x were built on the latest minor version of each series.
As a result, the built binaries required newer symbols such as `GLIBC_2.35` or `OPENSSL_3.4.0`,
and they did not work on older minor versions like RHEL 9.6 or RHEL 10.1.

To keep the ABI compatible in the whole 9.x and 10.x series, the build environment is now pinned to
RHEL 9.2 and RHEL 10.0. ([#1089](https://github.com/fluent/fluent-package-builder/pull/1089), [#1090](https://github.com/fluent/fluent-package-builder/pull/1090))

This issue was fixed and shipped as 6.0.4-2 on above platforms which had been implemented in advance, has now been officially released.

### rpm deb: disable LTO for RHEL 10 and Ubuntu

RPM 4.19 (AlmaLinux 10) and `dpkg-buildflags` on Ubuntu export LTO (Link Time Optimization) flags
(`-flto=auto -ffat-lto-objects`) into the build process. These flags leaked into jemalloc, Ruby and
native gem extensions, and made the build much slower. For example, the total build time on AlmaLinux 10
grew extraordinaly.

Since the bundled Ruby uses its own optimization settings, LTO gives no measurable benefit here.
So we removed the LTO flags and the annobin plugin from the build environment.
The hardening flags such as stack protection, control flow protection and `FORTIFY_SOURCE` are kept as before.

This change also means that native extensions which users build with `fluent-gem install` no longer
inherit the LTO overhead. ([#1102](https://github.com/fluent/fluent-package-builder/pull/1102))

## Download

Please visit [the download page](/download/fluent_package).

## Announcement

### About next LTS schedule

We plan to release the next LTS version of fluent-package v6.0.6 at Dec 2026.
The content of updates are still TBD.

### Follow us on X

We have been posting information about Fluentd in Japanese on [@fluentd_jp](https://x.com/fluentd_jp).
We would appreciate it if you followed the X account.

TAG: Fluentd fluent-package Announcement
AUTHOR: clearcode
110 changes: 110 additions & 0 deletions content/blog/20260929_fluentd-v1.19.4-has-been-released.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,110 @@
# Fluentd v1.19.4 has been released

Hi users!

We have released v1.19.4 on 2026-09-29.
ChangeLog is [here](https://github.com/fluent/fluentd/blob/v1.19/CHANGELOG.md#release-v1194---20260929).

This release is a maintenance release of v1.19 series.

<div markdown="span" class="alert alert-danger" role="alert">
This release fixes some vulnerabilities which were incomplete fixes in the previous version Fluentd v1.19.3.
</div>

This release will be bundled for `fluent-package` LTS version v6.0.5!

## Security Fixes

Many vulnerabilities were fixed in this release.

* [Incomplete Fix for CVE-2026-44024: Path Traversal Bypass via Bare `..` Tag in Output Plugins](https://github.com/fluent/fluentd/security/advisories/GHSA-5hq3-r276-rfr5)
* CVE ID pending (this page will be updated once assigned)
* CVSS v3 score: 7.5/10 (High)
* Workarounds: Restrict network access, allow connection within a closed, trusted network. Run fluentd as non-root user. Do not use the `${tag}` placeholder in the path parameter of output plugins. Filter incoming untrusted tags.
* [Out-of-Memory DoS via Object Allocation Amplification in `in_http` ndjson parsing](https://github.com/fluent/fluentd/security/advisories/GHSA-g69w-f42r-xp35)
* CVE ID pending (this page will be updated once assigned)
* CVSS v3 score: 7.5/10 (High)
* Workarounds: Restrict network access for `in_http`, allow connection within a closed, trusted network. Implement reverse proxy limits with forcing strict rate limiting and request size limits at the proxy layer to drop anomalous requests before they reach the Fluentd worker.
* [Out-of-Memory DoS via Unbounded TCP/TLS Connection Buffer in `in_syslog`](https://github.com/fluent/fluentd/security/advisories/GHSA-h3xv-5jpx-r4j2)
* CVE ID pending (this page will be updated once assigned)
* CVSS v3 score: 7.5/10 (High)
* Workarounds: Restrict network access for `in_syslog`, allow connection within a closed, trusted network. Switch to UDP Transport for a while. Implement reverse proxy limits with strict client connection timeout and buffer size limits to terminate anomalous, non-delimited streams before they overwhelm Fluentd.
* [Incomplete Fix for CVE-2026-44160: DoS via Unbounded Decompression in Buffer Chunk Streaming](https://github.com/fluent/fluentd/security/advisories/GHSA-x455-r5cg-h9p9)
* CVE ID pending (this page will be updated once assigned)
* CVSS v3 score: 2.9/10 (Low)
* Workarounds: Disable buffer compression. Disable automatic chunk backup with `disable_chunk_backup true`. Restrict incoming data only within a closed, trusted network.

In most cases, there is no problem using deployed Fluentd within a closed, trusted network.
If you could not update Fluentd immediately, consider to take advised mitigation in above advisories.

## Bug Fixes

Many bugs were also fixed in this release.

* `output`: fix JSON::GeneratorError as unrecoverable error. ([#5423](https://github.com/fluent/fluentd/pull/5423))
* Failure for content reasons (e.g. non-UTF-8 bytes, NaN/Infinity), is treated as a bad chunk.
* Set `allow_duplicate_key` parameter for `JSON.parse`. It accept duplicate keys silently
(last value wins) on every path. It keeps compatibility with older versions even though
newer `json` gem is used. ([#5430](https://github.com/fluent/fluentd/pull/5430))
* Set `allow_comments` parameter for `JSON.parse`. It accepts JSON with comments.
It keeps compatibility with older versions even though newer `json` gem is used. ([#5432](https://github.com/fluent/fluentd/pull/5432))
* Accept a bare scalar for an array option in YAML syntax ([#5433](https://github.com/fluent/fluentd/pull/5433))
* `parser_syslog`: Optimize RFC5424 structured data parsing ([#5444](https://github.com/fluent/fluentd/pull/5444))
* It avoids excessive backtracking when parsing malformed RFC5424 structured data.
* `out_forward`: drop keepalive sockets with failed or mismatched acks ([#5445](https://github.com/fluent/fluentd/pull/5445))
* It stops the endless "ack in response and chunk id in sent data are different" warning storm by
discarding (instead of reusing) a keepalive socket.
* `buffer`: fix `stage_byte_size` leak when a staged chunk is unstaged ([#5456](https://github.com/fluent/fluentd/pull/5456))
* There was a possibility that it could eventually raise spurious `BufferOverflowError`.
It affects plugins which implementing `#format`.
* `plugin base`: bound the number of worker lock files by hashing the path into a fixed set of buckets. ([#5471](https://github.com/fluent/fluentd/pull/5471))
* `supervisor`: reduce memory usage of `cleanup_lock_dir` with huge number of lock files ([#5472](https://github.com/fluent/fluentd/pull/5472))
* `config`: accept empty lines in quoted strings ([#5478](https://github.com/fluent/fluentd/pull/5478))
* `chunk`: ensure to close the Tempfile for decompressed data ([#5486](https://github.com/fluent/fluentd/pull/5486))
* `buffer`: fix spurious `BufferOverflowError` caused by queue_size leaking when a chunk purge fails ([#5487](https://github.com/fluent/fluentd/pull/5487))
* `buffer`: clamp exported buffer size metrics to non-negative values ([#5488](https://github.com/fluent/fluentd/pull/5488))
* Support json gem v3.x ([#5493](https://github.com/fluent/fluentd/pull/5493))
* `parser_syslog`: fix NameError when RFC3164 timestamp has repeated spaces ([#5497](https://github.com/fluent/fluentd/pull/5497))
* `parser_syslog`: fix NameError when RFC5424 timestamp has repeated spaces ([#5500](https://github.com/fluent/fluentd/pull/5500))

### Accept a bare scalar for an array option in YAML syntax

In the previous versions, a single scalar value for an array option is rejected in YAML config syntax.

Since v1.19.4, it accepts the following example.

```
config:
- match:
$tag: "**"
$type: http
retryable_response_codes: 503
```

### plugin base: bound the number of worker lock files by hashing the path into a fixed set of buckets

When `workers > 1`, `out_file` (with `append`) and
`out_secondary_file` take an inter-worker lock per output path, and
`get_lock_path` derives one lock file per path:
`/tmp/fluentd-lock-*/fluentd-<sanitized path>.lock`.

In the previous versions, a lock file is never removed while fluentd
is running; the only cleanup is `cleanup_lock_dir` at a graceful
shutdown. So the number of lock files grows with the number of unique
output paths, and with a date or a tag placeholder in `path` that set
is effectively unbounded over time.

In this release, the number of lock files is now bounded by a constant
instead of by the number of unique paths. The accumulation, the mass
deletion at shutdown, and the dependence on an external tmp cleaner
all disappear structurally rather than being mitigated.

Enjoy logging!

### Follow us on X

We have been posting information about Fluentd in Japanese on [@fluentd_jp](https://x.com/fluentd_jp).
We would appreciate it if you followed the X account.

TAG: Fluentd Announcement
AUTHOR: clearcode
4 changes: 3 additions & 1 deletion content/blog/tag/announcement
Original file line number Diff line number Diff line change
Expand Up @@ -163,4 +163,6 @@
/blog/20260327_fluent-package-v6.0.3-has-been-released
/blog/20260625_fluentd-v1.19.3-has-been-released
/blog/20260626_fluent-package-v6.0.4-has-been-released
/blog/20260814_fluent-package-v7-scheduled-lifecycle
/blog/20260814_fluent-package-v7-scheduled-lifecycle
/blog/20260929_fluent-package-v6.0.5-has-been-released
/blog/20260929_fluentd-v1.19.4-has-been-released
3 changes: 2 additions & 1 deletion content/blog/tag/fluent-package
Original file line number Diff line number Diff line change
Expand Up @@ -18,4 +18,5 @@
/blog/20260227_fluent-package-v6.0.2-has-been-released
/blog/20260327_fluent-package-v6.0.3-has-been-released
/blog/20260626_fluent-package-v6.0.4-has-been-released
/blog/20260814_fluent-package-v7-scheduled-lifecycle
/blog/20260814_fluent-package-v7-scheduled-lifecycle
/blog/20260929_fluent-package-v6.0.5-has-been-released
4 changes: 3 additions & 1 deletion content/blog/tag/fluentd
Original file line number Diff line number Diff line change
Expand Up @@ -172,4 +172,6 @@
/blog/20260327_fluent-package-v6.0.3-has-been-released
/blog/20260625_fluentd-v1.19.3-has-been-released
/blog/20260626_fluent-package-v6.0.4-has-been-released
/blog/20260814_fluent-package-v7-scheduled-lifecycle
/blog/20260814_fluent-package-v7-scheduled-lifecycle
/blog/20260929_fluent-package-v6.0.5-has-been-released
/blog/20260929_fluentd-v1.19.4-has-been-released
Loading