Bug#1135798: marked as done (openssh-client: OpenSSH in trixie-p-u breaks ControlPersist)
"Debian Bug Tracking System" <[email protected]> Wed, 06 May 2026 18:35:12 +0000
| Newsgroups | gmane.linux.debian.devel.ssh |
|---|---|
| Message-ID | <handler.1135798.D1135798.17780923723246131.ackdone@bugs.debian.org> |
This is a multi-part message in MIME format... ------------=_1778092512-3247875-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your message dated Wed, 06 May 2026 18:32:51 +0000 with message-id <[email protected]> and subject line Bug#1135798: fixed in openssh 1:10.0p1-7+deb13u4 has caused the Debian Bug report #1135798, regarding openssh-client: OpenSSH in trixie-p-u breaks ControlPersist to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) --=20 1135798: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1135798 Debian Bug Tracking System Contact [email protected] with problems ------------=_1778092512-3247875-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.debian.org; 6 May 2026 01:42:35 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-19.9 required=4.0 tests=BAYES_00, BODY_INCLUDES_PACKAGE,FOURLA,HAS_PACKAGE,MD5_SHA1_SUM,SPF_HELO_PASS, SPF_PASS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 30; hammy, 150; neutral, 173; spammy, 0. spammytokens: hammytokens:0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug, 0.000-+--H*Ad:N*Tracking, 0.000-+--HTo:N*System, 0.000-+--HTo:N*Bug Return-path: <[email protected]> Received: from pinero.vault24.org ([69.164.212.126]:47770) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wKRHW-00BiLg-0g for [email protected]; Wed, 06 May 2026 01:42:35 +0000 Received: from feynman.vault24.org (unknown [IPv6:2601:40f:4001:103b::14]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519MLKEM768 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by pinero.vault24.org (Postfix) with ESMTPS id C04171409CB for <[email protected]>; Tue, 05 May 2026 21:42:31 -0400 (EDT) Received: from [127.0.1.1] (nobel.vault24.org [10.222.173.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519MLKEM768 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by feynman.vault24.org (Postfix) with ESMTPS id 5AE6C69C79; Tue, 05 May 2026 21:42:31 -0400 (EDT) Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: Jon <[email protected]> To: Debian Bug Tracking System <[email protected]> Subject: openssh-client: OpenSSH in trixie-p-u breaks ControlPersist Message-ID: <177803175125.3140.6687568678069032515.reportbug@nobel-debian> X-Mailer: reportbug 13.2.0 Date: Tue, 05 May 2026 21:42:31 -0400 Delivered-To: [email protected] Package: openssh-client Version: 1:10.0p1-7+deb13u3 Severity: important Dear Maintainer, I'm not sure if this is the right way to file a bug against something sitting in stable-proposed-updates. I'm flagging it as important only because it would be a notable regression if it reached stable. The recent upload of OpenSSH to trixie-p-u backported the IPQoS changes from 10.1p1 without including the fix for bz#3872 https://bugzilla.mindrot.org/show_bug.cgi?id=3872 https://anongit.mindrot.org/openssh.git/commit/?h=V_10_1&id=979cbc2c1e0c9cd2f60d45d8d1da69519ec425cf I've confirmed that the bug appears in the package sitting in trixie-p-u Back when 10.1p1 was uploaded to Sid this bug was reported twice within a day of uploading, so this regression will almost certainly be noticed rather quickly: https://tracker.debian.org/news/1676107/accepted-openssh-1101p1-1-source-into-unstable/ https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117574 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117594 https://tracker.debian.org/news/1676531/accepted-openssh-1101p1-2-source-into-unstable/ -- System Information: Debian Release: 13.4 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'proposed-updates'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 6.12.85+deb13-amd64 (SMP w/2 CPU threads; PREEMPT) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages openssh-client depends on: ii adduser 3.152 ii init-system-helpers 1.69~deb13u1 ii libc6 2.41-12+deb13u2 ii libedit2 3.1-20250104-1 ii libfido2-1 1.15.0-1+b1 ii libgssapi-krb5-2 1.21.3-5 ii libselinux1 3.8.1-1 ii libssl3t64 3.5.5-1~deb13u2 ii passwd 1:4.17.4-2 ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1 Versions of packages openssh-client recommends: pn xauth <none> Versions of packages openssh-client suggests: pn keychain <none> pn libpam-ssh <none> pn monkeysphere <none> pn ssh-askpass <none> -- no debconf information ------------=_1778092512-3247875-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 1135798-close) by bugs.debian.org; 6 May 2026 18:32:52 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-114.2 required=4.0 tests=ALL_TRUSTED,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD, HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 10; hammy, 150; neutral, 518; spammy, 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK, 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo Return-path: <[email protected]> Received: from muffat.debian.org ([2607:f8f0:614:1::1274:33]:40108) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wKh3E-00DcSf-22 for [email protected]; Wed, 06 May 2026 18:32:52 +0000 Received: via submission from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified) by muffat.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wKh3F-005VJB-1W for [email protected]; Wed, 06 May 2026 18:32:52 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type: Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID :Content-Description:In-Reply-To:References; bh=5D1M72p1Ze0GoLhbkNEzKfpAYXPQsMdaBQHzXd7FbH8=; b=innWQnCIvgK/B/+tDrb9tJpeUx jKleA7k1Wu6bbAr6QsYw5FtAKcw0ANCi3VyDKsMjnTPpCCHQfPQu01LgReowr/IMczbJYH/g4Q7XN 5xkZL02Nfe8e+LkgdI1ZLXz8S9CqfauppkwD1X0QWbpNQf2C9favJxzX8E5KUUIW5mFt0UfcDJG5f gg1kePHJlftXXBAF/f0Fm2hygtidvH4zWnOJB6j/cF2VuOQT5jrrerwhoG670e13xkqjxmEy5uExr rGyIwSoqInxtPrU/2/LPL/O1DHsdHenJqy5xrmy+s34rP4LJzf6G8v4HO/s5l8lDTNHqFwPpOflVd JwULTlzQ==; Received: from dak by fasolo.debian.org with local (Exim 4.98.2) (envelope-from <[email protected]>) id 1wKh3D-00000009E6c-2pSz; Wed, 06 May 2026 18:32:51 +0000 From: Debian FTP Masters <[email protected]> Reply-To: Colin Watson <[email protected]> To: [email protected] X-DAK: dak process-policy X-Debian: DAK X-Debian-Package: openssh Debian: DAK Debian-Changes: openssh_10.0p1-7+deb13u4_source.changes Debian-Source: openssh Debian-Version: 1:10.0p1-7+deb13u4 Debian-Architecture: source Debian-Suite: proposed-updates Debian-Archive-Action: accept MIME-Version: 1.0 Subject: Bug#1135798: fixed in openssh 1:10.0p1-7+deb13u4 Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="===============4010797172185342612==" Message-Id: <[email protected]> Date: Wed, 06 May 2026 18:32:51 +0000 X-CrossAssassin-Score: 4 --===============4010797172185342612== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Source: openssh Source-Version: 1:10.0p1-7+deb13u4 Done: Colin Watson <[email protected]> We believe that the bug you reported is fixed in the latest version of openssh, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Colin Watson <[email protected]> (supplier of updated openssh package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 06 May 2026 13:33:32 +0100 Source: openssh Architecture: source Version: 1:10.0p1-7+deb13u4 Distribution: trixie Urgency: medium Maintainer: Debian OpenSSH Maintainers <[email protected]> Changed-By: Colin Watson <[email protected]> Closes: 1130595 1132572 1132573 1132574 1132575 1132576 1135798 Changes: openssh (1:10.0p1-7+deb13u4) trixie; urgency=3Dmedium . * Don't reuse c->isatty for signalling that the remote channel has a tty attached (closes: #1135798). . openssh (1:10.0p1-7+deb13u3) trixie; urgency=3Dmedium . * Backport minor security fixes from 10.3p1: - ssh(1): the -J and equivalent -oProxyJump=3D"..." options now validate user and host names for ProxyJump/-J options passed via the command-line (no such validation is performed for this option in configuration files). This prevents shell injection in situations where these were directly exposed to adversarial input, which would have been a terrible idea to begin with. - CVE-2026-35386: ssh(1): validation of shell metacharacters in user names supplied on the command-line was performed too late to prevent some situations where they could be expanded from %-tokens in ssh_config. For certain configurations, such as those that use a "%u" token in a "Match exec" block, an attacker who can control the user name passed to ssh(1) could potentially execute arbitrary shell commands. Reported by Florian Kohnh=C3=A4user (closes: #1132573). We continue to recommend against directly exposing ssh(1) and other tools' command-lines to untrusted input. Mitigations such as this can not be absolute given the variety of shells and user configurations in use. - CVE-2026-35414: sshd(8): when matching an authorized_keys principals=3D"" option against a list of principals in a certificate, = an incorrect algorithm was used that could allow inappropriate matching in cases where a principal name in the certificate contains a comma character. Exploitation of the condition requires an authorized_keys principals=3D"" option that lists more than one principal *and* a CA that will issue a certificate that encodes more than one of these principal names separated by a comma (typical CAs strongly constrain which principal names they will place in a certificate). This condition only applies to user- trusted CA keys in authorized_keys, the main certificate authentication path (TrustedUserCAKeys/AuthorizedPrincipalsFile) is not affected. Reported by Vladimir Tokarev (closes: #1132576). - CVE-2026-35385: scp(1): when downloading files as root in legacy (-O) mode and without the -p (preserve modes) flag set, scp did not clear setuid/setgid bits from downloaded files as one might typically expect. This bug dates back to the original Berkeley rcp program. Reported by Christos Papakonstantinou of Cantina and Spearbit (closes: #1132572). - CVE-2026-35387: sshd(8): fix incomplete application of PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms with regard to ECDSA keys. Previously if one of these directives contains any ECDSA algorithm name (say "ecdsa-sha2-nistp384"), then any other ECDSA algorithm would be accepted in its place regardless of whether it was listed or not. Reported by Christos Papakonstantinou of Cantina and Spearbit (closes: #1132574). - CVE-2026-35388: ssh(1): connection multiplexing confirmation (requested using "ControlMaster ask/autoask") was not being tested for proxy mode multiplexing sessions (i.e. "ssh -O proxy ..."). Reported by Michalis Vasileiadis (closes: #1132575). * Cherry-pick IPQoS handling updates from upstream: - Set default IPQoS for interactive sessions to Expedited Forwarding (EF). - Deprecate support for IPv4 type-of-service (TOS) IPQoS keywords. - Make ssh(1) and sshd(8) set IP QoS (aka IP_TOS, IPV6_TCLASS) continually at runtime based on what sessions/channels are open. - Correctly set extended type for client-side channels. Fixes interactive vs bulk IPQoS for client->server traffic. . openssh (1:10.0p1-7+deb13u2) trixie-security; urgency=3Dmedium . * CVE-2026-3497: Fix incorrect GSS-API error handling; Replace incorrect use of sshpkt_disconnect() with ssh_packet_disconnect(), and properly initialize some variables (closes: #1130595; thanks, Marc Deslauriers). Checksums-Sha1: 7651f1e593d7286556598700aa1bbc38273616bf 3763 openssh_10.0p1-7+deb13u4.dsc 5322cbd663e2d9e72726ec01a88ebd49c767a517 215600 openssh_10.0p1-7+deb13u4.deb= ian.tar.xz d2fd5a034e631437412375c4e17168279c4b5489 53237612 openssh_10.0p1-7+deb13u4.g= it.tar.xz 76f6ec4023fbdb12a1579021648e6423a98a6bc6 17386 openssh_10.0p1-7+deb13u4_sour= ce.buildinfo Checksums-Sha256: 73fed3fd77d60925ed342bcb0afd3c037e4ea0d39333107bf617aa90f859910f 3763 openss= h_10.0p1-7+deb13u4.dsc 102e1065030c6002acabd7f896eeba1462bf54b4d7393bac34b0308312868ec6 215600 open= ssh_10.0p1-7+deb13u4.debian.tar.xz 68618631cc634059a9b061321af098fa29986cf67b1423a04f1b68b2cfa30efd 53237612 op= enssh_10.0p1-7+deb13u4.git.tar.xz aa0756d97dae64a0e31a2043e5cd0928c9ee22c8beafd9403d522d56063ca939 17386 opens= sh_10.0p1-7+deb13u4_source.buildinfo Files: 1d2c0582504849dd95fa0e3f1bcf1986 3763 net standard openssh_10.0p1-7+deb13u4.= dsc cd617a64903b9e5e723c21983348b5e0 215600 net standard openssh_10.0p1-7+deb13u= 4.debian.tar.xz 69cf6f3da54f68154078205636179525 53237612 net standard openssh_10.0p1-7+deb1= 3u4.git.tar.xz d0e1c20b5c1efc602524612a18a720a3 17386 net standard openssh_10.0p1-7+deb13u4= _source.buildinfo Git-Tag-Info: tag=3D1d2a4689aeb611f9744c168417a8f213d84a2348 fp=3Dac0a4ff1261= 1b6fccf01c111393587d97d86500b Git-Tag-Tagger: Colin Watson <[email protected]> -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmn7NjkACgkQYG0ITkaD wHkzBBAAtWjjdK5WLBVsDDlpldOgN2V0/nmlnkFGIGL3ajUhQ6ChVTGxxnkpUrib 9o1U42KQO0avc0lovzjTZATfWZvC45wTs0+BRFz1EwJe1QFkVqTecJSegDBPA/um EE6JiV9arLWTkEoOOrtf+i16m2f1kRNStOenP9D/f/08Qnu3nnudWmQAIcTQdU/e 3jB+ulrHMhXI0I+L8h9oPCAm3Bb/cqsJ7s67tysApFymE0FHu8DffA6WlzTIfBBA vZcGT10MpLLztSpgWIIh0EXWM/BNi4KYOXFEjXFgtbXhb7JfOMedh0/oF1zIx1NS o37gqgMszP+tmbF4HQhWokl17W0+0Jh0jvDMUgxltzc0kprvLiPQ6oE2DWiw+pcH 3GCdqhsj+t/xAOzZquyN1ilQFuwLD5PftSSe2CDbzw+viyKSP4OyJFEn8I4jeCbH oetg90ghxOiC4/Lvt9wiXKMWF0aMqNpCpdQOdSrrS+W3lQuI7XGHtT1h0LD8GRrS OhC77AhpFQQsvLirUw39/XBDYesEbUnp4il89rvSx2oO5+bldf6a11CoSnyKKeSd hpwlRXMn4nDcdW/HpF/0cGeGyVezbgdGUlNjvs57bSF16iFQ7lVRb5SEcnUzHExE RfDnqA4DZx/4Dr574BOlEN3SomFTZq4EmkUNFl0I6+sIE5UjwRk=3D =3DLYOe -----END PGP SIGNATURE----- --===============4010797172185342612== Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCafuJUwAKCRCb9qggYcy5 ISI3AQCb2e/d2MRTLJc5Ekmf0sZlzvWTQkoz7I1Cnw/SLMvFLwEAt+IaDPBwmFH4 hegEW5EVlLgRvd1R/Dwlq1SnmI7QWQc= =p91k -----END PGP SIGNATURE----- --===============4010797172185342612==-- ------------=_1778092512-3247875-0--