Bug#984940: CVE-2021-28041

Darren Tucker <[email protected]>
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <CALDDTe0eGuZqFUdhwSsFQDvsLwduauvUJ6yvDwQaFgooedNSAw__32216.5944193088$1615608023$gmane$org@mail.gmail.com>
On Sat, 13 Mar 2021 at 10:01, Colin Watson <[email protected]> wrote:
> This patch unfortunately doesn't apply terribly cleanly to OpenSSH
> 8.4p1, [...]
> If I understand the vulnerability correctly, then it seems to me that
> the following shorter patch would fix it, and would run less risk of me
> fouling something else up by backporting the refactoring wrongly:

There's a patch against 8.4 here:
https://ftp.openbsd.org/pub/OpenBSD/patches/6.8/common/015_sshagent.patch.sig

It has the first of the two changes in your diff.  The second is
harmless but unnecessary as it's on the exit path from the function
and there can't be a following call to free.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.