From 0b59d5e80e2456b0d0df51681f5b928c940a6a0e Mon Sep 17 00:00:00 2001 From: Sebastiaan van Stijn Date: Thu, 3 Sep 2026 01:55:01 +0200 Subject: [PATCH 1/2] vendor: golang.org/x/crypto v0.56.0 full diff: https://github.com/golang/crypto/compare/v0.55.0...v0.56.0 We have tagged version v0.56.0 of golang.org/x/crypto in order to address the following security issues: - ssh: prevent DoS on deadlocked established channel Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking. Thanks to Will Mortensen for reporting this issue. This is CVE-2026-56855 and Go issue https://go.dev/issue/81317. - ssh: prevent DoS on deadlocked undecided channel Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection. Thanks to Will Mortensen for reporting this issue. This is CVE-2026-78662 and Go issue https://go.dev/issue/81316. Signed-off-by: Sebastiaan van Stijn (cherry picked from commit 9bc4fca69f50a29ce0b54d0023a10920d7e23161) Signed-off-by: Sebastiaan van Stijn --- go.mod | 2 +- go.sum | 4 +-- vendor/golang.org/x/crypto/ssh/certs.go | 38 +++++++++------------ vendor/golang.org/x/crypto/ssh/channel.go | 20 ++++++++++- vendor/golang.org/x/crypto/ssh/transport.go | 12 +++++-- vendor/modules.txt | 4 +-- 6 files changed, 50 insertions(+), 30 deletions(-) diff --git a/go.mod b/go.mod index 7f8aba175b44..15b4c8c43f28 100644 --- a/go.mod +++ b/go.mod @@ -60,7 +60,7 @@ require ( go.opentelemetry.io/otel/sdk v1.45.0 go.opentelemetry.io/otel/trace v1.45.0 go.yaml.in/yaml/v3 v3.0.5 - golang.org/x/crypto v0.55.0 + golang.org/x/crypto v0.56.0 golang.org/x/mod v0.40.0 golang.org/x/sync v0.22.0 golang.org/x/sys v0.47.0 diff --git a/go.sum b/go.sum index 6c3a5b710ff3..674ef2cf1710 100644 --- a/go.sum +++ b/go.sum @@ -634,8 +634,8 @@ go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw= go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg= go.yaml.in/yaml/v4 v4.0.0-rc.4 h1:UP4+v6fFrBIb1l934bDl//mmnoIZEDK0idg1+AIvX5U= go.yaml.in/yaml/v4 v4.0.0-rc.4/go.mod h1:aZqd9kCMsGL7AuUv/m/PvWLdg5sjJsZ4oHDEnfPPfY0= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs= golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE= golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= diff --git a/vendor/golang.org/x/crypto/ssh/certs.go b/vendor/golang.org/x/crypto/ssh/certs.go index fa848f51a5f9..a3b802e4b8bf 100644 --- a/vendor/golang.org/x/crypto/ssh/certs.go +++ b/vendor/golang.org/x/crypto/ssh/certs.go @@ -10,6 +10,7 @@ import ( "fmt" "io" "net" + "slices" "sort" "time" ) @@ -305,8 +306,11 @@ const sourceAddressCriticalOption = "source-address" // minimally, the IsAuthority callback should be set. type CertChecker struct { // SupportedCriticalOptions lists the CriticalOptions that the - // server application layer understands. These are only used - // for user certificates. + // application layer understands. A certificate carrying a critical + // option that is not listed here is rejected. + // CertChecker.Authenticate additionally accepts the source-address + // option, which the server enforces on the Permissions that + // Authenticate returns. SupportedCriticalOptions []string // IsUserAuthority should return true if the key is recognized as an @@ -369,8 +373,9 @@ func (c *CertChecker) CheckHostKey(addr string, remote net.Addr, key PublicKey) return c.CheckCert(hostname, cert) } -// Authenticate checks a user certificate. Authenticate can be used as -// a value for ServerConfig.PublicKeyCallback. +// Authenticate checks a user certificate. Authenticate can be used as a value +// for ServerConfig.PublicKeyCallback. The source-address critical option is +// allowed, as it will be enforced by the server. func (c *CertChecker) Authenticate(conn ConnMetadata, pubKey PublicKey) (*Permissions, error) { cert, ok := pubKey.(*Certificate) if !ok { @@ -389,8 +394,11 @@ func (c *CertChecker) Authenticate(conn ConnMetadata, pubKey PublicKey) (*Permis if !c.IsUserAuthority(cert.SignatureKey) { return nil, fmt.Errorf("ssh: certificate signed by unrecognized authority") } - - if err := c.CheckCert(conn.User(), cert); err != nil { + // The source-address critical option is enforced by serverAuthenticate, + // so it is supported regardless of SupportedCriticalOptions + cc := *c + cc.SupportedCriticalOptions = append(slices.Clip(cc.SupportedCriticalOptions), sourceAddressCriticalOption) + if err := cc.CheckCert(conn.User(), cert); err != nil { return nil, err } @@ -398,27 +406,15 @@ func (c *CertChecker) Authenticate(conn ConnMetadata, pubKey PublicKey) (*Permis } // CheckCert checks CriticalOptions, ValidPrincipals, revocation, timestamp and -// the signature of the certificate. +// the signature of the certificate. Critical options that are not listed in +// SupportedCriticalOptions are rejected. func (c *CertChecker) CheckCert(principal string, cert *Certificate) error { if c.IsRevoked != nil && c.IsRevoked(cert) { return fmt.Errorf("ssh: certificate serial %d revoked", cert.Serial) } for opt := range cert.CriticalOptions { - // sourceAddressCriticalOption will be enforced by - // serverAuthenticate - if opt == sourceAddressCriticalOption { - continue - } - - found := false - for _, supp := range c.SupportedCriticalOptions { - if supp == opt { - found = true - break - } - } - if !found { + if !slices.Contains(c.SupportedCriticalOptions, opt) { return fmt.Errorf("ssh: unsupported critical option %q in certificate", opt) } } diff --git a/vendor/golang.org/x/crypto/ssh/channel.go b/vendor/golang.org/x/crypto/ssh/channel.go index ba3279e91d68..d6010fd77b99 100644 --- a/vendor/golang.org/x/crypto/ssh/channel.go +++ b/vendor/golang.org/x/crypto/ssh/channel.go @@ -173,6 +173,12 @@ type channel struct { // (for outbound channels) or received (for inbound channels). decided bool + // established is set to true once the channel is open and may carry normal + // channel traffic: for an outbound channel when the peer's open + // confirmation is received, for an inbound channel when the local side + // accepts it. It is set and read from different goroutines. + established atomic.Bool + // direction contains either channelOutbound, for channels created // locally, or channelInbound, for channels created by the peer. direction channelDirection @@ -434,10 +440,20 @@ func (ch *channel) responseMessageReceived() error { return errors.New("ssh: duplicate response received for channel") } ch.decided = true + ch.established.Store(true) return nil } func (ch *channel) handlePacket(packet []byte) error { + // Only the open response is expected before the channel is established. + if !ch.established.Load() { + switch packet[0] { + case msgChannelOpenConfirm, msgChannelOpenFailure: + default: + return nil + } + } + switch packet[0] { case msgChannelData, msgChannelExtendedData: return ch.handleData(packet) @@ -503,7 +519,8 @@ func (ch *channel) handlePacket(packet []byte) error { default: } default: - ch.msg <- msg + // No other message type is expected on an established channel. + return fmt.Errorf("ssh: unexpected message type %d on channel %d", packet[0], ch.localId) } return nil } @@ -554,6 +571,7 @@ func (ch *channel) Accept() (Channel, <-chan *Request, error) { MaxPacketSize: ch.maxIncomingPayload, } ch.decided = true + ch.established.Store(true) if err := ch.sendMessage(confirm); err != nil { return nil, nil, err } diff --git a/vendor/golang.org/x/crypto/ssh/transport.go b/vendor/golang.org/x/crypto/ssh/transport.go index fa3dd6a4299b..540865dfc823 100644 --- a/vendor/golang.org/x/crypto/ssh/transport.go +++ b/vendor/golang.org/x/crypto/ssh/transport.go @@ -331,13 +331,19 @@ func exchangeVersions(rw io.ReadWriter, versionLine []byte) (them []byte, err er // chars const maxVersionStringBytes = 255 +// maxPreVersionLines is the maximum number of lines sent by the peer +// before the version string. Each of these lines is limited to a maximum +// of maxVersionStringBytes chars. Lines sent before the version string +// are silently ignored. +const maxPreVersionLines = 1024 + // Read version string as specified by RFC 4253, section 4.2. func readVersion(r io.Reader) ([]byte, error) { versionString := make([]byte, 0, 64) var ok bool var buf [1]byte - for length := 0; length < maxVersionStringBytes; length++ { + for lines := 0; len(versionString) < maxVersionStringBytes && lines < maxPreVersionLines; { _, err := io.ReadFull(r, buf[:]) if err != nil { return nil, err @@ -347,9 +353,9 @@ func readVersion(r io.Reader) ([]byte, error) { if buf[0] == '\n' { if !bytes.HasPrefix(versionString, []byte("SSH-")) { // RFC 4253 says we need to ignore all version string lines - // except the one containing the SSH version (provided that - // all the lines do not exceed 255 bytes in total). + // except the one containing the SSH version. versionString = versionString[:0] + lines++ continue } ok = true diff --git a/vendor/modules.txt b/vendor/modules.txt index b17bfbeef39b..36eaff2f29d9 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -1273,8 +1273,8 @@ go.yaml.in/yaml/v3 ## explicit; go 1.18 go.yaml.in/yaml/v4 go.yaml.in/yaml/v4/internal/libyaml -# golang.org/x/crypto v0.55.0 -## explicit; go 1.25.0 +# golang.org/x/crypto v0.56.0 +## explicit; go 1.26.0 golang.org/x/crypto/argon2 golang.org/x/crypto/bcrypt golang.org/x/crypto/blake2b From 21fec83a493f2dc78579781e1cba4bd514a20e9d Mon Sep 17 00:00:00 2001 From: Sebastiaan van Stijn Date: Sat, 5 Sep 2026 02:27:42 +0200 Subject: [PATCH 2/2] vendor: github.com/containerd/containerd/v2 v2.3.5 full diff: https://github.com/containerd/containerd/compare/v2.3.4...v2.3.5 Security Updates - [**CVE-2026-53495**](https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv) - [**GHSA-rp3h-jf77-q9p4**](https://github.com/containerd/containerd/security/advisories/GHSA-rp3h-jf77-q9p4) Image Distribution - Apply hardening to strip sensitive authentication headers when fetching descriptor URLs Runtime - Avoid hangs and data races when streaming container standard I/O in CRI - Fix missing error messages in OpenTelemetry trace attributes - Fix user and group lookup failures in container rootfs containing symlinked /etc/passwd or /etc/group - Fix configuration loading error when drop-in configuration files have a higher version than the root configuration - Avoid containerd startup hangs when loading shims - Add context to error when shim delete times out - Fix Windows Server 2022 container compatibility on host builds newer than the latest LTSC Snapshotters - Fix unpack failure for EROFS images containing the erofs OS feature Signed-off-by: Sebastiaan van Stijn (cherry picked from commit 86d1b72323fb1819f9ddc1154180835ed874af8b) Signed-off-by: Sebastiaan van Stijn --- go.mod | 2 +- go.sum | 4 +- .../v2/core/remotes/docker/fetcher.go | 38 ++++++++++++++++++- .../containerd/v2/pkg/tracing/helpers.go | 6 ++- .../containerd/v2/version/version.go | 2 +- vendor/modules.txt | 2 +- 6 files changed, 46 insertions(+), 8 deletions(-) diff --git a/go.mod b/go.mod index 15b4c8c43f28..2ed8005ab073 100644 --- a/go.mod +++ b/go.mod @@ -9,7 +9,7 @@ require ( github.com/aws/aws-sdk-go-v2/config v1.32.39 github.com/compose-spec/compose-go/v2 v2.14.0 github.com/containerd/console v1.0.5 - github.com/containerd/containerd/v2 v2.3.4 + github.com/containerd/containerd/v2 v2.3.5 github.com/containerd/continuity v0.5.0 github.com/containerd/errdefs v1.0.0 github.com/containerd/log v0.1.0 diff --git a/go.sum b/go.sum index 674ef2cf1710..e4b03368b3c0 100644 --- a/go.sum +++ b/go.sum @@ -118,8 +118,8 @@ github.com/containerd/console v1.0.5 h1:R0ymNeydRqH2DmakFNdmjR2k0t7UPuiOV/N/27/q github.com/containerd/console v1.0.5/go.mod h1:YynlIjWYF8myEu6sdkwKIvGQq+cOckRm6So2avqoYAk= github.com/containerd/containerd/api v1.11.1 h1:h8nfoDW9+fNsC/9TwiAHj8B1GzXKtR4eFtkhi/X5RLU= github.com/containerd/containerd/api v1.11.1/go.mod h1:CaQFRu+N1MtbgL6JDOJLUB1hCKESU1lD6MuTJhgtdlw= -github.com/containerd/containerd/v2 v2.3.4 h1:c2PJo/9UGVdiiw8SwrxuLxWGY+9b3jQ6Xp9zntneIvI= -github.com/containerd/containerd/v2 v2.3.4/go.mod h1:a30D8fWZJ1Uzx/2WpjLbLsxBkq9He41pe8ENW+QZ3LY= +github.com/containerd/containerd/v2 v2.3.5 h1:9MYlI81gUcOZ0WsCkSMtvOU7rTR3hqAoa2eCzhoLlkA= +github.com/containerd/containerd/v2 v2.3.5/go.mod h1:RXDyLPaI3zoO7dFdAW9/54W4cix+z3A6larieufC9mg= github.com/containerd/continuity v0.5.0 h1:7a85HZpCSs+1Zps0Ee3DPSuAWY+0SJM1JNM51nlEVDg= github.com/containerd/continuity v0.5.0/go.mod h1:/lNJvtJKUQStBzpVQ1+rasXO1LAWtUQssk28EZvJ3nE= github.com/containerd/errdefs v1.0.0 h1:tg5yIfIlQIrxYtu9ajqY42W3lpS19XqdxRQeEwYG8PI= diff --git a/vendor/github.com/containerd/containerd/v2/core/remotes/docker/fetcher.go b/vendor/github.com/containerd/containerd/v2/core/remotes/docker/fetcher.go index b5c29b1070c2..8b9961470076 100644 --- a/vendor/github.com/containerd/containerd/v2/core/remotes/docker/fetcher.go +++ b/vendor/github.com/containerd/containerd/v2/core/remotes/docker/fetcher.go @@ -218,6 +218,40 @@ type dockerFetcher struct { *dockerBase } +func stripSensitiveHeadersForExternalURLs(h http.Header) { + h.Del("Authorization") + h.Del("Proxy-Authorization") + h.Del("Cookie") + h.Del("Cookie2") +} + +func effectivePort(u *url.URL) string { + if port := u.Port(); port != "" { + return port + } + switch strings.ToLower(u.Scheme) { + case "http": + return "80" + case "https": + return "443" + default: + return "" + } +} + +func isRegistryOrigin(u *url.URL, hosts []RegistryHost) bool { + for _, host := range hosts { + if !strings.EqualFold(u.Scheme, host.Scheme) { + continue + } + hostURL := &url.URL{Scheme: host.Scheme, Host: host.Host} + if strings.EqualFold(u.Hostname(), hostURL.Hostname()) && effectivePort(u) == effectivePort(hostURL) { + return true + } + } + return false +} + func (r dockerFetcher) Fetch(ctx context.Context, desc ocispec.Descriptor) (io.ReadCloser, error) { ctx = log.WithLogger(ctx, log.G(ctx).WithField("digest", desc.Digest)) @@ -255,7 +289,9 @@ func (r dockerFetcher) Fetch(ctx context.Context, desc ocispec.Descriptor) (io.R Capabilities: HostCapabilityPull, } req := r.request(host, http.MethodGet) - // Strip namespace from base + if !isRegistryOrigin(u, hosts) { + stripSensitiveHeadersForExternalURLs(req.header) + } req.path = u.Path if u.RawQuery != "" { req.path = req.path + "?" + u.RawQuery diff --git a/vendor/github.com/containerd/containerd/v2/pkg/tracing/helpers.go b/vendor/github.com/containerd/containerd/v2/pkg/tracing/helpers.go index ab1278ef1fcf..4354e6c14b12 100644 --- a/vendor/github.com/containerd/containerd/v2/pkg/tracing/helpers.go +++ b/vendor/github.com/containerd/containerd/v2/pkg/tracing/helpers.go @@ -73,13 +73,15 @@ func keyValue(k string, v any) attribute.KeyValue { return attribute.String(k, typed) case []string: return attribute.StringSlice(k, typed) + case error: + return attribute.String(k, fmt.Sprint(typed)) } if stringer, ok := v.(fmt.Stringer); ok { - return attribute.String(k, stringer.String()) + return attribute.String(k, fmt.Sprint(stringer)) } if b, err := json.Marshal(v); b != nil && err == nil { return attribute.String(k, string(b)) } - return attribute.String(k, fmt.Sprintf("%v", v)) + return attribute.String(k, fmt.Sprint(v)) } diff --git a/vendor/github.com/containerd/containerd/v2/version/version.go b/vendor/github.com/containerd/containerd/v2/version/version.go index c256226281b0..a010e26e6c75 100644 --- a/vendor/github.com/containerd/containerd/v2/version/version.go +++ b/vendor/github.com/containerd/containerd/v2/version/version.go @@ -24,7 +24,7 @@ var ( Package = "github.com/containerd/containerd/v2" // Version holds the complete version number. Filled in at linking time. - Version = "2.3.4+unknown" + Version = "2.3.5+unknown" // Revision is filled with the VCS (e.g. git) revision being used to build // the program at linking time. diff --git a/vendor/modules.txt b/vendor/modules.txt index 36eaff2f29d9..3de18c8a4aaa 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -212,7 +212,7 @@ github.com/containerd/console # github.com/containerd/containerd/api v1.11.1 ## explicit; go 1.24.0 github.com/containerd/containerd/api/services/content/v1 -# github.com/containerd/containerd/v2 v2.3.4 +# github.com/containerd/containerd/v2 v2.3.5 ## explicit; go 1.26.3 github.com/containerd/containerd/v2/core/content github.com/containerd/containerd/v2/core/content/proxy