Re: [Buildroot] [PATCH 1/1] package/libssh: security bump version to 0.12.1
Julien Olivain via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
On 21/07/2026 20:43, Bernd Kuhls wrote: > https://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1 > https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ > > Fixes the following security problems: > > CVE-2026-15370: Stack buffer overflow in SFTP server longname > construction > CVE-2026-59842: Information disclosure via short GSSAPI Curve25519 > public key > CVE-2026-59843: Denial of service via zero advertised channel packet > size > CVE-2026-59844: Denial of service via oversized SFTP read length > CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() > failure > CVE-2026-59846: Information disclosure via ProxyCommand %r username > expansion > CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag > verification > CVE-2026-59848: Denial of service via SFTP responses with unknown > request IDs > CVE-2026-59849: Denial of service via automatic certificate > authentication loop > CVE-2026-59850: Use-after-free via data callbacks on closed channels > CVE-2026-59851: Authentication bypass via missing GSSAPI principal > check > Zero-initialize every ssh_string > > Signed-off-by: Bernd Kuhls <[email protected]> Applied to master, thanks. _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot