v0.6.3: russh 0.61 security bump (CVE batch) + bergshamra 0.5 + axum 0.8
Security-driven dependency release.
- russh =0.55.0 (pinned) -> 0.61.2: closes the advisory batch reachable
from our SFTP *client* path — unbounded/allocation-first packet
parsing (CVE-2026-48110, CVE-2026-46702, CVE-2026-46673, HIGH) plus
CVE-2026-48107 in client auth. A malicious or compromised SFTP server
an operator pointed us at could previously OOM the PXE server. Also
drops mlock on non-secret buffers (~21% SSH throughput upstream) —
directly in the remote-share ISO streaming path. ring backend kept;
zero code changes needed in sftp_share.rs.
- bergshamra 0.4 -> 0.5.1: the pin's blocking condition (stable
RustCrypto generation, pkcs8 0.11) is now met upstream, so the
=0.55.0 pin is deleted and its comment rewritten as history. 0.5 is
secure-by-default for DSig (flags we already set explicitly) and
fixes an XML-Enc DerivedKey fallthrough.
- axum 0.7 -> 0.8.9: route captures /:id -> {id} across the router and
the /api/docs listing; ConnectInfo optional extraction moves to the
Result form. Gains the HEAD content-length fix (iPXE/sanboot clients
probe with HEAD before Range requests) and puts us back on the
maintained line.
Validation: clippy clean, fmt clean, all 272 workspace tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
5da05a519d
commit
7f25bb681c
+12
-17
@@ -12,7 +12,7 @@ members = [
|
||||
]
|
||||
|
||||
[workspace.package]
|
||||
version = "0.6.2"
|
||||
version = "0.6.3"
|
||||
edition = "2021"
|
||||
rust-version = "1.95"
|
||||
license = "MIT OR Apache-2.0"
|
||||
@@ -33,7 +33,7 @@ dhcproto = "0.15"
|
||||
socket2 = { version = "0.6", features = ["all"] }
|
||||
bytes = "1.7"
|
||||
|
||||
axum = { version = "0.7", features = ["macros", "multipart", "http2"] }
|
||||
axum = { version = "0.8", features = ["macros", "multipart", "http2"] }
|
||||
tower = "0.5"
|
||||
tower-http = { version = "0.6", features = ["fs", "trace", "cors", "limit"] }
|
||||
hyper = "1.9"
|
||||
@@ -80,7 +80,7 @@ lettre = { version = "0.11", default-features = false, features = ["smtp-transpo
|
||||
# C deps), so the static musl binary stays OpenSSL-free — samael was
|
||||
# rejected precisely because it hard-requires OpenSSL. We build the thin
|
||||
# SP layer (AuthnRequest, metadata parse, SAMLResponse semantics) on top.
|
||||
bergshamra = "0.4"
|
||||
bergshamra = "0.5"
|
||||
roxmltree = "0.21"
|
||||
quick-xml = "0.40"
|
||||
x509-parser = "0.18"
|
||||
@@ -99,24 +99,19 @@ base64 = "0.22"
|
||||
# binary via rustls + bergshamra — so SFTP adds ZERO new C/crypto deps
|
||||
# and the static-musl build stays OpenSSL-free.
|
||||
#
|
||||
# CRITICAL #2 — pinned to EXACTLY 0.55.0, the newest russh that
|
||||
# coexists with bergshamra-crypto (our SAML core). The RustCrypto
|
||||
# ecosystem is mid-transition: bergshamra-crypto pins a constellation of
|
||||
# release-CANDIDATE crates (`pkcs8 =0.11.0-rc.11` and its matching
|
||||
# pkcs5/spki RCs) that are API-incompatible with the STABLE versions of
|
||||
# the same crates in the same semver bucket. russh 0.56+ pulls those
|
||||
# stable crates (`pkcs5 0.8`), which silently replaces bergshamra's RC
|
||||
# copies and breaks compilation. russh ≤0.55 stays on the previous stable
|
||||
# generation (`pkcs5 0.7`, `ssh-key 0.6`), which unifies with bergshamra's
|
||||
# *stable* deps and leaves the RC bucket untouched — verified to compile.
|
||||
# 0.55 still has the merged `russh::keys` API (keys merged at 0.50).
|
||||
# IMPORTANT: do NOT bump russh past 0.55 until bergshamra-crypto adopts
|
||||
# the stable RustCrypto generation; 0.56+ will not compile in this tree.
|
||||
# CRITICAL #2 — history: this was pinned to =0.55.0 from v0.5.5 until
|
||||
# v0.6.3 because bergshamra-crypto pinned release-candidate RustCrypto
|
||||
# crates that conflicted with the stable generation russh 0.56+ pulls.
|
||||
# bergshamra 0.5 (2026-06) moved to the stable generation (pkcs8 0.11),
|
||||
# lifting the pin. v0.6.3 bumps to 0.61+, which also closes a batch of
|
||||
# RUSTSEC advisories reachable from the SFTP *client* path (unbounded
|
||||
# allocations in packet parsing — CVE-2026-48110/-46702/-46673 et al.)
|
||||
# and drops mlock on non-secret buffers (~21% SSH throughput upstream).
|
||||
#
|
||||
# SCP was deliberately rejected: the protocol is sequential-only (no
|
||||
# random access → no HTTP Range, unlike SFTP/NFS) and the mature SCP
|
||||
# crates wrap libssh2 (C + OpenSSL), which would break this build.
|
||||
russh = { version = "=0.55.0", default-features = false, features = ["ring"] }
|
||||
russh = { version = "0.61", default-features = false, features = ["ring"] }
|
||||
russh-sftp = "2.3"
|
||||
|
||||
openpxe-core = { path = "crates/core" }
|
||||
|
||||
Reference in New Issue
Block a user