Bug#1142537: libssh: CVE-2026-15370 CVE-2026-59842 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850 CVE-2026-59851
Martin Pitt <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <[email protected]> |
Control: tag -1 pending Hello Salvatore! Salvatore Bonaccorso [2026-07-21 14:38 +0200]: > Source: libssh > Version: 0.12.0-3 > Severity: grave > Tags: security upstream > Justification: user security hole Sorry for the delay! Life.. But the fixes have been in unstable for about a week, and in testing since yesterday, and I got no complaints. autopkgtests were happy as well. > CVE-2026-59842[1]: > | A flaw was found in libssh. During server-side GSSAPI key exchange, > | a client-supplied Curve25519 public key shorter than the expected > | length is copied without proper length validation, leading to an > | out-of-bounds heap read. This could allow a remote unauthenticated > | attacker to disclose small amounts of server memory. This does not apply to trixie and earlier. Fix is https://git.libssh.org/projects/libssh.git/commit/?id=ed9109dfc64b92c250b7e8c4c2045dad30d433f8 and that code was introduced in the 0.12 series, i.e. not present in 0.11 and earlier. > CVE-2026-59851[10]: > | Authentication bypass via missing GSSAPI principal check Same story: https://git.libssh.org/projects/libssh.git/commit/?id=a45d20b75278858a6f06364722e068b32f181197 kex-gss.cs does not exist in 0.11 and ealier. The others are fixed in 0.11.5. I packaged and tested it, ran autopkgtest, and put it on https://people.debian.org/~mpitt/tmp/ Note that this includes (and the above dir still separately contains) the previous 0.11.4 which was declined for -security and never accepted into updates. debdiff to current trixie-security is at https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1_0.11.5-0+deb13u1.debdiff Thanks! Pitti
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmpt4VcACgkQ7nvd5Lhr VxPPfw/9EkOrGrmQQQgSL4NlDxPGmqEw7C0rhVqZim6BJydsjCHMyZ0lIy2W0j62 6zIzT+koQASdve9ITU5EyPar7cr6Ol+j4XWvRMp584JkXWoRi40ffHUOOmJbgIOa ecIDkyr16lNevbwYXP6o4ZpzXwPgIN7l4BcUP3dnUU2t+qFW4lSW5jJyodWE0r1X Rv4oRvl6A+AUPNwI+P+s0ZoVufoSjmgMx7+tMAMU3vnLIRCngjZz5BZ31Izzoxux 6Z0xOEICvzfyyUHxLcXBpHPI1WzphflxeJO/2RcaFmvqjircMYbannnI03wFGHpi W7x/i2H6cikGFX4WYE9FQLfXSV2mr6XvA41dTeHyNr8nIHGHJNU9ojLAtkc6/mq7 LuiLf/STL+1U85K9pPhLKcgKVspbELUo/fkypvOozkDuSZp9Xf/rE9hHF23bQLop h/ibpOASUuKC6gTAOLlabBoj76/TNWVrI15mABxM7sKf3jVKExgjkeGru+wf2ldz vPmaKORXfYpe6AUqFbmkJ8h6glT5I1YaU/XuU2uZ3IdKhplXDQdb8qujXWTQB1Nw uvl3t4PAxf9GvIpxplauGlVo67P+LDLIOXLOb7e47wG8zdMcfbzdVxOPuH+LSQqT CO5lVowmGZ+nhYYx9aUuliaJsxYEbAYZhVvciykfDf8QkIDQQVg= =P6vs -----END PGP SIGNATURE-----