Bug#1142537: libssh: CVE-2026-15370 CVE-2026-59842 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850 CVE-2026-59851

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Hi Martin,

On Sat, Aug 01, 2026 at 02:06:47PM +0200, Martin Pitt wrote:
> Control: tag -1 pending
> 
> Hello Salvatore!
> 
> Salvatore Bonaccorso [2026-07-21 14:38 +0200]:
> > Source: libssh
> > Version: 0.12.0-3
> > Severity: grave
> > Tags: security upstream
> > Justification: user security hole
> 
> Sorry for the delay! Life.. But the fixes have been in unstable for about a
> week, and in testing since yesterday, and I got no complaints. autopkgtests
> were happy as well.
> 
> > CVE-2026-59842[1]:
> > | A flaw was found in libssh. During server-side GSSAPI key exchange,
> > | a client-supplied Curve25519 public key shorter than the expected
> > | length is copied without proper length validation, leading to an
> > | out-of-bounds heap read. This could allow a remote unauthenticated
> > | attacker to disclose small amounts of server memory.
> 
> This does not apply to trixie and earlier. Fix is
> https://git.libssh.org/projects/libssh.git/commit/?id=ed9109dfc64b92c250b7e8c4c2045dad30d433f8
> 
> and that code was introduced in the 0.12 series, i.e. not present in 0.11 and
> earlier.
> 
> > CVE-2026-59851[10]:
> > | Authentication bypass via missing GSSAPI principal check
> 
> Same story:
> https://git.libssh.org/projects/libssh.git/commit/?id=a45d20b75278858a6f06364722e068b32f181197
> 
> kex-gss.cs does not exist in 0.11 and ealier.
> 
> The others are fixed in 0.11.5. I packaged and tested it, ran autopkgtest, and
> put it on
> 
>   https://people.debian.org/~mpitt/tmp/
> 
> Note that this includes (and the above dir still separately contains) the
> previous 0.11.4 which was declined for -security and never accepted into
> updates.
> 
> debdiff to current trixie-security is at
> https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1_0.11.5-0+deb13u1.debdiff

Thank you, please upload to security-master (needs to be built with
-sa).

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.