Bug#1142537: libssh: CVE-2026-15370 CVE-2026-59842 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850 CVE-2026-59851

Martin Pitt <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <amYcJyvTAooKBdj1__47998.9956294716$1785076875$gmane$org@piware.de>
Control: tag -1 pending

Hello Salvatore,

Salvatore Bonaccorso [2026-07-21 14:38 +0200]:
> Making a RC bug due to the amount of CVEs mainly and two CVEs only
> relevant for 0.12.0. We still need to assess the rest for trixie.

As usual, I'd recommend uploading 0.11.5 to trixie. The upstream stable
releases are well curated and tested. The previous two rounds were missed
though -- I prepared them for -security, then you said you marked them as
"wontfix" for stable-security, but I never got the "go!" for the stable-pu
request. Can't find the old bugs now, but "something" went wrong/got lost.

I'll prepare/test it in the next days.

> CVE-2026-59843[2]:
> | A flaw was found in libssh. A remote authenticated peer can
> | advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN,
> | causing later channel writes to loop indefinitely and consume CPU,
> | leading to denial of service.
> 
> Can you help on this one to identify the needed upstream change? There
> is one from master branch referenced in the advisory but that does not
> look to be backported to libssh-0.12.1? 

This was indeed forgotten. It's present on the 0.11 branch. I notified the
maintainers by email and also created a corresponding unit test. I backported
the fix as a patch in the 0.12.1 upload.

Martin
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.