149 lines
4.3 KiB
Markdown
149 lines
4.3 KiB
Markdown
# RustyTorch++ Security Audit Report
|
|
|
|
**Date**: 2025-12-16
|
|
**Tool**: cargo-audit (RustSec Advisory Database)
|
|
**Total Dependencies**: 1413 crates
|
|
|
|
---
|
|
|
|
## Summary
|
|
|
|
| Category | Before | After |
|
|
|----------|--------|-------|
|
|
| Vulnerabilities | 7 | 4 |
|
|
| Warnings (unmaintained) | 14 | ~14 |
|
|
| Total Advisories | 21 | ~18 |
|
|
|
|
### Fixed Vulnerabilities (2025-12-16)
|
|
- ✅ **object_store** 0.8 → 0.11 (RUSTSEC-2024-0358)
|
|
- ✅ **ring** 0.16 → 0.17 (RUSTSEC-2025-0009)
|
|
- ✅ **tonic** 0.12 → 0.13 (RUSTSEC-2025-0019)
|
|
|
|
---
|
|
|
|
## Vulnerabilities (Require Action)
|
|
|
|
### 1. RUSTSEC-2024-0421: idna Punycode Validation Issue
|
|
- **Crate**: `idna 0.4.0`
|
|
- **Severity**: Low
|
|
- **Fix**: Upgrade to `>=1.0.0`
|
|
- **Path**: `idna → validator → rtx-config`
|
|
- **Action**: Update `validator` crate to newer version
|
|
|
|
### 2. RUSTSEC-2024-0358: object_store AWS Token Exposure
|
|
- **Crate**: `object_store 0.8.0`
|
|
- **Severity**: Low (3.8)
|
|
- **Fix**: Upgrade to `>=0.10.2`
|
|
- **Path**: `object_store → rtx-hub`
|
|
- **Action**: Update `object_store` in rtx-hub
|
|
|
|
### 3. RUSTSEC-2024-0437: protobuf Uncontrolled Recursion
|
|
- **Crate**: `protobuf 2.28.0`
|
|
- **Severity**: Medium
|
|
- **Fix**: Upgrade to `>=3.7.2`
|
|
- **Path**: `protobuf → prometheus → rtx-monitoring/rtx-serving-api/rtx-streaming`
|
|
- **Action**: Update `prometheus` crate or switch to `prometheus-client`
|
|
- **Note**: prometheus 0.13.4 uses old protobuf; may need to switch metrics library
|
|
|
|
### 4. RUSTSEC-2025-0020: pyo3 Buffer Overflow Risk
|
|
- **Crate**: `pyo3 0.20.3`
|
|
- **Severity**: Medium
|
|
- **Fix**: Upgrade to `>=0.24.1`
|
|
- **Path**: `pyo3 → rtx-sklearn-py`
|
|
- **Action**: Update pyo3 in rtx-sklearn-py (major version bump)
|
|
|
|
### 5. RUSTSEC-2025-0009: ring AES Panic Issue
|
|
- **Crate**: `ring 0.16.20`
|
|
- **Severity**: Low
|
|
- **Fix**: Upgrade to `>=0.17.12`
|
|
- **Path**: `ring → rtx-platform, rtx-federated`
|
|
- **Action**: Update ring dependency
|
|
|
|
### 6. RUSTSEC-2023-0071: rsa Timing Side-channel (Marvin Attack)
|
|
- **Crate**: `rsa 0.9.8`
|
|
- **Severity**: Medium (5.9)
|
|
- **Fix**: ⚠️ NO FIX AVAILABLE
|
|
- **Path**: `rsa → sqlx-mysql → sqlx → many crates`
|
|
- **Action**: Monitor for upstream fix; consider avoiding MySQL RSA auth
|
|
- **Mitigation**: Use password authentication instead of RSA key exchange
|
|
|
|
### 7. RUSTSEC-2025-0019: tonic Buffer Overflow
|
|
- **Crate**: `tonic 0.12.3` and `0.13.0`
|
|
- **Severity**: Medium
|
|
- **Fix**: Upgrade to `>=0.13.1`
|
|
- **Path**: `tonic → rtx-streaming, rtx-distributed, etc.`
|
|
- **Action**: Update tonic to 0.13.1+
|
|
|
|
---
|
|
|
|
## Warnings (Unmaintained Crates)
|
|
|
|
These crates are no longer maintained but may not have active vulnerabilities:
|
|
|
|
| Crate | Advisory | Alternative |
|
|
|-------|----------|-------------|
|
|
| `proc-macro-error` | RUSTSEC-2024-0370 | Use `manyhow` or `proc-macro-error2` |
|
|
| `instant` | RUSTSEC-2024-0384 | Use `std::time::Instant` or `web-time` |
|
|
| `serde-xml-rs` | RUSTSEC-2024-0399 | Use `quick-xml` with serde |
|
|
| `rusttype` | RUSTSEC-2021-0140 | Use `ab_glyph` |
|
|
| `term_size` | RUSTSEC-2020-0163 | Use `terminal_size` |
|
|
| `safemem` | RUSTSEC-2023-0081 | Use standard library |
|
|
| `raw-cpuid` | RUSTSEC-2021-0089 | Update to latest version |
|
|
| `mach` | RUSTSEC-2020-0168 | Use `mach2` |
|
|
| `ansi_term` | RUSTSEC-2021-0139 | Use `nu-ansi-term` or `yansi` |
|
|
|
|
---
|
|
|
|
## Remediation Plan
|
|
|
|
### Priority 1: Critical/Immediate
|
|
1. **tonic** - Update to 0.13.1+ (buffer overflow)
|
|
2. **protobuf/prometheus** - Evaluate switching to `prometheus-client`
|
|
|
|
### Priority 2: High
|
|
3. **pyo3** - Update to 0.24.1+ (buffer overflow risk)
|
|
4. **ring** - Update to 0.17.12+ (panic issue)
|
|
5. **object_store** - Update to 0.10.2+ (token exposure)
|
|
|
|
### Priority 3: Medium
|
|
6. **idna/validator** - Update validator crate
|
|
7. **rsa** - Monitor upstream; mitigate via auth config
|
|
|
|
### Priority 4: Low (Warnings)
|
|
8. Replace unmaintained crates when convenient
|
|
|
|
---
|
|
|
|
## Commands
|
|
|
|
```bash
|
|
# Re-run audit
|
|
cargo audit
|
|
|
|
# Update specific dependency
|
|
cargo update -p <package_name>
|
|
|
|
# Check for available updates
|
|
cargo outdated
|
|
```
|
|
|
|
---
|
|
|
|
## CI/CD Integration
|
|
|
|
Security scanning is already integrated in `.github/workflows/ci.yml`:
|
|
```yaml
|
|
- name: Security audit
|
|
uses: rustsec/audit-check@v2
|
|
with:
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
```
|
|
|
|
---
|
|
|
|
## Notes
|
|
|
|
- The `rsa` vulnerability has no fix yet; sqlx team is aware
|
|
- Many warnings are from transitive dependencies (not direct)
|
|
- Consider using `cargo deny` for stricter dependency policies
|