Skip to content

Bump the bundled rclone once upstream ships a release carrying the grpc fix for CVE-2026-84445 #74

Description

@oc-tmueller

bin/rclone_linux_amd64 is upstream rclone v1.75.1, which pins
google.golang.org/grpc at v1.84.0-dev.0.20260723093437-b6eac429d7b6. That
pseudo-version is affected by CVE-2026-84445 / GHSA-2v4p-qf9q-27wj (HIGH,
gRPC-Go denial of service). Trivy lists the fix as
v1.85.0-dev.0.20260825072537-93e31b48545e, which rclone master already carries
but no rclone release does yet — v1.75.1 (2026-09-04) is still the newest:

$ curl -s https://raw.githubusercontent.com/rclone/rclone/master/go.mod | grep grpc
	google.golang.org/grpc v1.85.0-dev.0.20260825072537-93e31b48545e // indirect
$ curl -s https://raw.githubusercontent.com/rclone/rclone/v1.75.1/go.mod | grep grpc
	google.golang.org/grpc v1.84.0-dev.0.20260723093437-b6eac429d7b6 // indirect

So there is nothing to do here until upstream ships a release. Until then the
finding is accepted in two places, both expiring 2026-12-01:

  • .trivyignore.yaml in this repo, scoped to bin/rclone_linux_amd64.
  • owncloud/server-release's root ignore file, scoped to
    apps/migrate_to_ocis/bin/rclone_linux_amd64. The assembled-bundle scan in
    spec-check.yml is a separate gate and does not read this repo's file, so the
    acceptance has to exist on both sides.

Why it is acceptable in the meantime: the panic is in the xDS routing
interceptor, which is installed only by servers constructed with
xds.NewGRPCServer(), and is triggered by an inbound RPC carrying neither
:authority nor Host. grpc is an indirect dependency of rclone's Google
backends; this app never speaks gRPC at all, let alone serves it. It shells out
to rclone sync between two WebDAV remotes
(StateMigrateFiles::buildRCloneSyncCommand()) and to rclone obscure
(StateMigrateFiles::RCloneObscure()), and uses neither rclone serve nor the
rc API.

What to do when the rclone release lands

  1. Confirm the new release's go.mod carries grpc >= the fixed pseudo-version —
    read go.mod, not the release notes.
  2. Replace bin/rclone_linux_amd64 with the upstream linux-amd64 binary from
    that release, keeping mode 100755. Trivy's gobinary analyzer skips
    non-executable files, so a lost exec bit turns the scan green by accident
    rather than red.
  3. Diff the new binary's -v output against v1.75.1's on the app's exact flag
    set before calling the bump safe.
    StateMigrateFiles fails a user's
    migration on any rclone output line containing NOTICE/WARNING/ERROR, and
    rclone's -v stats banner is itself a bare NOTICE: line. v1.75.0 and
    v1.75.1 happened to match; a future release need not.
  4. Drop the acceptance from .trivyignore.yaml here and from
    owncloud/server-release, and confirm both scans are green with no entry for
    this CVE rather than assuming it.

If no rclone release has appeared by 2026-12-01, the two expired_at dates lapse
and both scans go red on purpose — that is the reminder to re-decide, not a
regression.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions