Bug#1142537: libssh: CVE-2026-15370 CVE-2026-59842 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850 CVE-2026-59851

Martin Pitt <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Control: tag -1 pending

Hello Salvatore!

Salvatore Bonaccorso [2026-07-21 14:38 +0200]:
> Source: libssh
> Version: 0.12.0-3
> Severity: grave
> Tags: security upstream
> Justification: user security hole

Sorry for the delay! Life.. But the fixes have been in unstable for about a
week, and in testing since yesterday, and I got no complaints. autopkgtests
were happy as well.

> CVE-2026-59842[1]:
> | A flaw was found in libssh. During server-side GSSAPI key exchange,
> | a client-supplied Curve25519 public key shorter than the expected
> | length is copied without proper length validation, leading to an
> | out-of-bounds heap read. This could allow a remote unauthenticated
> | attacker to disclose small amounts of server memory.

This does not apply to trixie and earlier. Fix is
https://git.libssh.org/projects/libssh.git/commit/?id=ed9109dfc64b92c250b7e8c4c2045dad30d433f8

and that code was introduced in the 0.12 series, i.e. not present in 0.11 and
earlier.

> CVE-2026-59851[10]:
> | Authentication bypass via missing GSSAPI principal check

Same story:
https://git.libssh.org/projects/libssh.git/commit/?id=a45d20b75278858a6f06364722e068b32f181197

kex-gss.cs does not exist in 0.11 and ealier.

The others are fixed in 0.11.5. I packaged and tested it, ran autopkgtest, and
put it on

  https://people.debian.org/~mpitt/tmp/

Note that this includes (and the above dir still separately contains) the
previous 0.11.4 which was declined for -security and never accepted into
updates.

debdiff to current trixie-security is at
https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1_0.11.5-0+deb13u1.debdiff

Thanks!

Pitti
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmpt4VcACgkQ7nvd5Lhr
VxPPfw/9EkOrGrmQQQgSL4NlDxPGmqEw7C0rhVqZim6BJydsjCHMyZ0lIy2W0j62
6zIzT+koQASdve9ITU5EyPar7cr6Ol+j4XWvRMp584JkXWoRi40ffHUOOmJbgIOa
ecIDkyr16lNevbwYXP6o4ZpzXwPgIN7l4BcUP3dnUU2t+qFW4lSW5jJyodWE0r1X
Rv4oRvl6A+AUPNwI+P+s0ZoVufoSjmgMx7+tMAMU3vnLIRCngjZz5BZ31Izzoxux
6Z0xOEICvzfyyUHxLcXBpHPI1WzphflxeJO/2RcaFmvqjircMYbannnI03wFGHpi
W7x/i2H6cikGFX4WYE9FQLfXSV2mr6XvA41dTeHyNr8nIHGHJNU9ojLAtkc6/mq7
LuiLf/STL+1U85K9pPhLKcgKVspbELUo/fkypvOozkDuSZp9Xf/rE9hHF23bQLop
h/ibpOASUuKC6gTAOLlabBoj76/TNWVrI15mABxM7sKf3jVKExgjkeGru+wf2ldz
vPmaKORXfYpe6AUqFbmkJ8h6glT5I1YaU/XuU2uZ3IdKhplXDQdb8qujXWTQB1Nw
uvl3t4PAxf9GvIpxplauGlVo67P+LDLIOXLOb7e47wG8zdMcfbzdVxOPuH+LSQqT
CO5lVowmGZ+nhYYx9aUuliaJsxYEbAYZhVvciykfDf8QkIDQQVg=
=P6vs
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.