NetBelt 1.3.3 - #8
Merged
Merged
Conversation
pyasn1 0.6.3 and earlier decode OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time (GHSA-8ppf-4f7h-5ppj / CVE-2026-59885). 0.6.4 fixes it, and also GHSA-hm4w-wwcw-mr6r, GHSA-m4p7-r5rc-7g4j and GHSA-jr27-m4p2-rc6r, which covered 0.5.1 as well. pysnmp 5.1.0 imports pyasn1.compat.octets, which 0.6.4 no longer has, so the SNMP code moves to pysnmp 7.1.28 (asyncio only). 7.1.30 was not taken: its AES imports a cryptography module that 46.0.3 does not have, which silently disables AES. - GET/WALK run on a private event loop per operation and close it, keeping cancel, partial results, progress and the default timeouts. WALK keeps the 5.1.0 order for non-increasing OIDs, the subtree end and noSuchObject/noSuchInstance/NULL values. - The trap receiver binds its own socket with SO_EXCLUSIVEADDRUSE in bind(), runs on a loop owned by the receiver thread and is stopped with call_soon_threadsafe. - Loop exceptions print only the type and location, so a packet that breaks the decoder no longer puts received bytes (communities) into the log, and an exception raised after a v1 reply was matched fails the GET/WALK at once instead of hanging it. - Tests: the old-API parts of the existing tests are ported. New loopback tests cover every v3 auth/priv choice for GET and traps, the trap receiver life cycle, and the hang regression in a child process. - THIRD-PARTY-NOTICES.txt is regenerated, and CHANGELOG [Unreleased] lists the differences from 5.1.0 approved for this change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
NetBelt 1.3.3: the fix for pyasn1 GHSA-8ppf-4f7h-5ppj / CVE-2026-59885.
The SNMP code moves from pysnmp 5.1.0 to 7.1.28 with pyasn1 0.6.4; cryptography stays at 46.0.3. The changes for users are in the CHANGELOG section
[1.3.3] - 2026-10-02, which is also the release body.🤖 Generated with Claude Code