Bug#1145104: trixie-pu: package libssh2/libssh2_1.11.1-1+deb13u2

Nicolas Mora <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <178740908264.818026.12477521299255759341.reportbug__2632.74371843494$1787409696$gmane$org@leodagan>
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], Salvatore Bonaccorso <[email protected]>, Emmanuel Arias <[email protected]>
Control: affects -1 + src:libssh2
User: [email protected]
Usertags: pu

[ Reason ]
Fix CVEs CVE-2026-66032 CVE-2026-66033 CVE-2026-66034 CVE-2026-66035
CVE-2026-58050 CVE-2026-58051

[ Impact ]
Denial of service, heap corruption or information disclosure

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
Backport of the packages 1.11.1-6 and 1.11.1-5 in unstable
libssh2_1.11.1-1+deb13u2.debdiff (text/plain, 9 KB)
diff -Nru libssh2-1.11.1/debian/changelog libssh2-1.11.1/debian/changelog
--- libssh2-1.11.1/debian/changelog	2026-06-23 17:01:56.000000000 -0400
+++ libssh2-1.11.1/debian/changelog	2026-08-02 10:50:39.000000000 -0400
@@ -1,3 +1,10 @@
+libssh2 (1.11.1-1+deb13u2) trixie; urgency=medium
+
+  * d/patches: Fix CVEs CVE-2026-66032 CVE-2026-66033 CVE-2026-66034
+    CVE-2026-66035 CVE-2026-58050 CVE-2026-58051 (Backport from unstable)
+
+ -- Nicolas Mora <[email protected]>  Sun, 02 Aug 2026 10:50:39 -0400
+
 libssh2 (1.11.1-1+deb13u1) trixie-security; urgency=medium
 
   * CVE-2026-7598 (Closes: #1135647)
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-58050.patch libssh2-1.11.1/debian/patches/CVE-2026-58050.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-58050.patch	1969-12-31 19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-58050.patch	2026-08-02 10:50:39.000000000 -0400
@@ -0,0 +1,34 @@
+From 34497525929b9a47f03dfb81887ac896202b7e12 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Sun, 28 Jun 2026 02:12:52 +0200
+Subject: [PATCH] publickey: fix potential multiplication overflow in 32-bit
+ `libssh2_publickey_list_fetch()`
+
+Cap list size at 1024 elements.
+
+Reported-and-initial-patch-by: Mateusz Gierblinski
+Reported-and-initial-patch-by: Behzod Abdullayev
+Reported-by: Sharique Raza
+
+Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9
+
+Closes #2128
+Forwarded: not-needed
+---
+ src/publickey.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -1121,6 +1121,11 @@
+                 }
+ 
+                 if(list[keys].num_attrs) {
++                    if(list[keys].num_attrs > 1024) {
++                        _libssh2_error(session, LIBSSH2_ERROR_OUT_OF_BOUNDARY,
++                                 "Too many publickey attributes");
++                        goto err_exit;
++                    }
+                     list[keys].attrs =
+                         LIBSSH2_ALLOC(session,
+                                       list[keys].num_attrs *
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-58051.patch libssh2-1.11.1/debian/patches/CVE-2026-58051.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-58051.patch	1969-12-31 19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-58051.patch	2026-08-02 10:50:39.000000000 -0400
@@ -0,0 +1,25 @@
+From 32092f0d310f4d769e5ed073ad5987f997f446dc Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Sun, 28 Jun 2026 02:13:32 +0200
+Subject: [PATCH] publickey: fix potential arbitrary free in
+ `libssh2_publickey_list_fetch()`
+
+Due to uninitialized list entry.
+
+Reported-and-patch-by: Behzod Abdullayev
+Reported-by: Sharique Raza
+Forwarded: not-needed
+---
+ src/publickey.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -972,6 +972,7 @@
+                     goto err_exit;
+                 }
+                 list = newlist;
++                memset(&list[keys], 0, sizeof(list[keys]));
+             }
+             if(pkey->version == 1) {
+                 unsigned long comment_len;
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-66032.patch libssh2-1.11.1/debian/patches/CVE-2026-66032.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-66032.patch	1969-12-31 19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-66032.patch	2026-08-02 10:44:29.000000000 -0400
@@ -0,0 +1,24 @@
+From 5e4776146552d898b9c0e1b313cd093fa8dc92d0 Mon Sep 17 00:00:00 2001
+From: Will Cosgrove <[email protected]>
+Date: Thu, 2 Jul 2026 11:00:23 -0700
+Subject: [PATCH] Prevent dangling pointer by nullifying data (#2180)
+
+Set data to NULL after freeing it to avoid dangling pointer. fixes
+GHSA-px3w-7g75-hg7w.
+
+Credit: VladimirEliTokarev
+Forwarded: not-needed
+---
+ src/sftp.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -1279,6 +1279,7 @@
+                                "got HANDLE FXOK"));
+ 
+                 LIBSSH2_FREE(session, data);
++                data = NULL;
+ 
+                 /* silly situation, but check for a HANDLE */
+                 rc = sftp_packet_require(sftp, SSH_FXP_HANDLE,
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-66033.patch libssh2-1.11.1/debian/patches/CVE-2026-66033.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-66033.patch	1969-12-31 19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-66033.patch	2026-08-02 10:44:33.000000000 -0400
@@ -0,0 +1,40 @@
+From a2ed82d40964bbc0d64cd717aa0a5a892117d2e6 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Thu, 23 Jul 2026 10:32:04 +0200
+Subject: [PATCH] openssl: fix potential OOB read/write with AES-GCM in
+ `ssh2_cipher_crypt()`
+
+By applying two bounds checks to non-debug builds.
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-c4f7-cvfc-33j7
+Follow-up to 3c953c05d67eb1ebcfd3316f279f12c4b1d600b4 #797
+
+Closes #2401
+Forwarded: not-needed
+---
+ src/openssl.c | 10 ++++++----
+ 1 file changed, 6 insertions(+), 4 deletions(-)
+
+--- a/src/openssl.c
++++ b/src/openssl.c
+@@ -1042,13 +1042,15 @@
+     const int aadlen = (is_aesgcm && IS_FIRST(firstlast)) ? 4 : 0;
+     /* size of AT, if present */
+     const int authenticationtag = IS_LAST(firstlast) ? authlen : 0;
+-    /* length to encrypt */
+-    const int cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
++    unsigned int cryptlen; /* length to encrypt */
+ 
+     (void)algo;
+ 
+-    assert(blocksize <= sizeof(buf));
+-    assert(cryptlen >= 0);
++    if(blocksize > sizeof(buf) ||
++       blocksize < (size_t)(aadlen + authenticationtag))
++        return 1;
++
++    cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
+ 
+ #if LIBSSH2_AES_GCM
+     /* First block */
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-66034.patch libssh2-1.11.1/debian/patches/CVE-2026-66034.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-66034.patch	1969-12-31 19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-66034.patch	2026-08-02 10:44:38.000000000 -0400
@@ -0,0 +1,31 @@
+From a13bb6c773f0d55ad1628cede57e99803cd898d9 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Sat, 4 Jul 2026 11:19:49 +0200
+Subject: [PATCH] publickey: fix potential OOB read in
+ `libssh2_publickey_list_fetch()`
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-w6g9-cpfp-22gc
+
+Closes #2202
+Forwarded: not-needed
+---
+ src/publickey.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -988,6 +988,13 @@
+                 }
+ 
+                 if(comment_len) {
++                    if(pkey->listFetch_s + comment_len >
++                       pkey->listFetch_data + pkey->listFetch_data_len) {
++                        _libssh2_error(session, LIBSSH2_ERROR_BUFFER_TOO_SMALL,
++                                 "ListFetch data too short");
++                        goto err_exit;
++                    }
++
+                     list[keys].num_attrs = 1;
+                     list[keys].attrs =
+                         LIBSSH2_ALLOC(session,
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-66035.patch libssh2-1.11.1/debian/patches/CVE-2026-66035.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-66035.patch	1969-12-31 19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-66035.patch	2026-08-02 10:44:41.000000000 -0400
@@ -0,0 +1,37 @@
+From 42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Fri, 3 Jul 2026 18:22:55 +0200
+Subject: [PATCH] transport: fix potential heap overflow on ETM decrypt
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-6c79-444r-wx26
+
+Closes #2198
+Forwarded: not-needed
+---
+ src/transport.c | 7 ++++++-
+ 1 file changed, 6 insertions(+), 1 deletion(-)
+
+--- a/src/transport.c
++++ b/src/transport.c
+@@ -242,6 +242,12 @@
+                 unsigned char *decrypt_buffer;
+                 int blocksize = session->remote.crypt->blocksize;
+ 
++                if(p->total_num < mac_len + 4 + (size_t)blocksize) {
++                    LIBSSH2_FREE(session, p->payload);
++                    return LIBSSH2_ERROR_DECRYPT;
++                }
++                decrypt_size = (ssize_t)(p->total_num - mac_len - 4);
++
+                 rc = decrypt(session, p->payload + 4,
+                              first_block, blocksize, FIRST_BLOCK);
+                 if(rc) {
+@@ -249,7 +255,6 @@
+                 }
+ 
+                 /* we need buffer for decrypt */
+-                decrypt_size = p->total_num - mac_len - 4;
+                 decrypt_buffer = LIBSSH2_ALLOC(session, decrypt_size);
+                 if(!decrypt_buffer) {
+                     return LIBSSH2_ERROR_ALLOC;
diff -Nru libssh2-1.11.1/debian/patches/series libssh2-1.11.1/debian/patches/series
--- libssh2-1.11.1/debian/patches/series	2026-06-23 17:01:56.000000000 -0400
+++ libssh2-1.11.1/debian/patches/series	2026-08-02 10:50:39.000000000 -0400
@@ -11,3 +11,9 @@
 CVE-2026-55199.patch
 CVE-2026-55200.patch
 libssh-unconst-backport.patch
+CVE-2026-66032.patch
+CVE-2026-66033.patch
+CVE-2026-66034.patch
+CVE-2026-66035.patch
+CVE-2026-58050.patch
+CVE-2026-58051.patch
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.