pypi scapy 2.8.0
v2.8.0

4 hours ago

Hi everyone. This release is a bit different, as it is heavily focused on security fixes as we are clearing our backlog of AI-Assisted reports. We have also clarified the guidelines around AI, contributions and security reports. To contributors, feel free to reach out if you haven't heard back from us in a whilte !

Deprecation notice

  • This major version will be the last to support Python 3.7 and 3.8. While this was initially planned for 2.7.0, support was extended because of how used those versions still were. They have been EoL for more than 2 years, and we highly encourage remaining users to upgrade.

A note about contributing guidelines

We have clarified our CONTRIBUTING and SECURITY guidelines. This notably includes some new guidance related to the use of AI, and some instructions regarding the submission of security issues. We encourage contributors to take a moment to read the updated versions.

Security

Scapy has taken part in OpenAI + Trail of Bits collab's initiative called "Patch the Planet". As part of this initiative, we have received a free security coverage of our code overseen by KernelClint (Trail of Bits) and multiple OpenAI agents. This has led to the discovery of around 130+ bugs, among which were 54 issues that could be considered related to security, with various degrees of severity. You can find a partial list on https://github.com/secdev/scapy/security/advisories and here but please bear in mind that some reports have been written entirely by AI.

After analysis, we have marked 5 vulnerabilities with a "High" level of impact, which justify an immediate upgrade to 2.8.0, or backporting if packaged by downstream repositories:

The other issues have been triaged as "Moderate" or "Low" and don't justify immediate action from users or downstream package maintainers (those include crashes, issues in various protocol implementations, automatons and answering machines, mis-implementations of protocols like our TLS stack, etc. but nothing that leads to a potential compromission of the host machine).

We would like to thank again OpenAI and Trail of Bits (and in particular @KernelClint) for this opportunity and the time spent on this project.

Changelog

  • Windows protocols:
    • Kerberos: IAKERB support, WinSSP, KDC pinning, S4U+FAST fix, NTLM MIC server-side check
    • SMB: various SMB2 fixes, new smbclient() features
    • DCE/RPC: fragmentation fixes, proper client auth denial, context commit fixes
    • NTLM/SPNEGO/WinSSP: late fallback mechanism, encryption support, doc fixes
    • [new] registry abstraction layer for [MS-RRP] RPC
    • [MS-NRTP] fix
  • Automotive related changes:
    • Added SAE J1939 support
    • Added standalone UDS/KWP/OBD/GMLAN packets
    • Improved CAN/ISO-TP soft-socket robustness
    • Added configurable busy-response retries in automotive scanners
  • Work has begun to clean up the remaining compatibility code that allowed the transition from Python 2.
  • Minor security fixes (the full list is available in the Security tab):
    • RADIUS: verify Message-Authenticator
    • fwdmachine: verify upstream TLS certs, correct TLS server context
    • tls/sslv2: stricter security handling
    • Several fuzzing-found crash fixes (HSRP, Bluetooth, Kerberos)
    • Bound/robustness fixes across pcap, pcapng, ISOTP, TCP reassembly, BGP, IPv6, HTTP, DNS, LDAP, modbus parsing
  • Bluetooth:
    • Many new vendor-specific command modules (Realtek, Barrot, Intel, Espressif, CSR, Zephyr)
    • Fixed link-layer byte order, normalized field naming
    • New HCI event handler registration mechanism
  • New protocols/contrib:
    • DICOM support
    • CBOR implementation (fields + packets)
    • SAE J1939 protocol + soft socket
    • PTP protocol
    • MySQL classic protocol
  • 802.11: added HE Operation, HT Operation, EHT Operation, and Radio Measurement elements
  • Performance: minor improvements to packet dissection/build speed, reduced unnecessary copying in reassembly paths (netbios, pcapng, HTTP/2, LDAP, ISOTP, TFTP)
  • DNS: EDNS0 padding option, client-subnet fixes, off-by-four fix
  • IGMP: full rework, merged implementations
  • Misc fixes: TCP MD5 option calculation, BPF error reporting, FreeBSD 32-bit BPF support, hexdiff bounds check

Don't miss a new scapy release

NewReleases is sending notifications on new releases.