fluent-package v6.0.5 has been released

Hi users!

We have released fluent-package v6.0.5 on 2026-09-29. Fluent Package is a stable distribution package of Fluentd. (successor of td-agent)

This is a maintenance release of v6.0.x LTS series.

Fluent Package v6.0.5

Fluent Package v6.0.5 includes the following improvements:

  • Updated bundled Fluentd to v1.19.4 which fixes some vulnerabilities
  • Updated bundled Ruby to 3.4.11
  • Updated bundled gems which fix vulnerabilities and crashes (oj, json)
  • msi: Fixed a broken link to enterprise services on the popup window of the Windows installer
  • rpm: Kept compatibility with older RHEL 9.x and 10.x
  • deb rpm: Reduced build time by disabling LTO on RHEL 10 and Ubuntu

This article explains the changes in Fluent Package v6.0.5.

Changes

Updated bundled Fluentd to v1.19.4 which fixes some vulnerabilities

In this release, some critical vulnerabilities were fixed.

The above vulnerabilities affects to older than v1.19.4, thus the following packages also will be affected.

  • fluent-package LTS v6.0.4 or earlier
  • fluent-package Standard edition v6.0.0 (NOTE: no patched version planned yet, please consider to use LTS)
  • fluent-package LTS v5.0.9 or earlier (NOTE: v5.0.x already reached EOL, no patched updates anymore)
  • fluent-package Standard edition v5.2.0 or earlier (NOTE: v5.x already reached EOL, no patched updates anymore)
  • All of td-agent (NOTE: td-agent already reached EOL, no patched updates anymore)

We recommend upgrading fluent-package to v6.0.5.

If you can't upgrade it immediately, there is a case that mitigation method is explained in above advisory. Please check each advisory and take care of it.

Fluentd v1.19.4 also contains many bug fixes. See the release announcement of Fluentd v1.19.4 for details.

Updated bundled Ruby to 3.4.11

Ruby 3.4.11 is a maintenance release. Compared to Ruby 3.4.9 which was bundled in the previous version, it includes the following security fixes in bundled gems:

For details, please see the Ruby 3.4.10 and Ruby 3.4.11 release notes.

msi: fixed a broken link to enterprise services on popup window

The link to the enterprise services page on the popup window of the Windows installer was broken. It has been fixed in this release. (#1079)

rpm: keep compatibility with older RHEL 9.x and 10.x

The packages for RHEL 9.x and 10.x were built on the latest minor version of each series. As a result, the built binaries required newer symbols such as GLIBC_2.35 or OPENSSL_3.4.0, and they did not work on older minor versions like RHEL 9.6 or RHEL 10.1.

To keep the ABI compatible in the whole 9.x and 10.x series, the build environment is now pinned to RHEL 9.2 and RHEL 10.0. (#1089, #1090)

This issue was fixed and shipped as 6.0.4-2 on above platforms which had been implemented in advance, has now been officially released.

rpm deb: disable LTO for RHEL 10 and Ubuntu

RPM 4.19 (AlmaLinux 10) and dpkg-buildflags on Ubuntu export LTO (Link Time Optimization) flags (-flto=auto -ffat-lto-objects) into the build process. These flags leaked into jemalloc, Ruby and native gem extensions, and made the build much slower. For example, the total build time on AlmaLinux 10 grew extraordinaly.

Since the bundled Ruby uses its own optimization settings, LTO gives no measurable benefit here. So we removed the LTO flags and the annobin plugin from the build environment. The hardening flags such as stack protection, control flow protection and FORTIFY_SOURCE are kept as before.

This change also means that native extensions which users build with fluent-gem install no longer inherit the LTO overhead. (#1102)

Download

Please visit the download page.

Announcement

About next LTS schedule

We plan to release the next LTS version of fluent-package v6.0.6 at Dec 2026. The content of updates are still TBD.

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

There are some commercial supports for Fluentd, see Enterprise Services. If you use Fluentd on production, Let's share your use-case/testimonial on Testimonials page. Please consider to feedback Use-Case/Testimonials via GitHub.

Subscribed to the RSS feed here.

Written by ClearCode, Inc.

ClearCode, Inc. is a software company specializing in the development of Free Software. We maintain Fluentd and its plugin ecosystem, and provide commercial support for them.


About Fluentd

Fluentd is an open source data collector to unify log management.

Learn

Want to learn the basics of Fluentd? Check out these pages.

Ask the Community

Couldn't find enough information? Let's ask the community!

Ask the Experts

You need commercial-grade support from Fluentd committers and experts?

Follow Us!