Re: [Buildroot] [PATCH 1/1] package/libssh: security bump version to 0.12.1

Julien Olivain via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
On 21/07/2026 20:43, Bernd Kuhls wrote:
> https://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1
> https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
> 
> Fixes the following security problems:
> 
> CVE-2026-15370: Stack buffer overflow in SFTP server longname 
> construction
> CVE-2026-59842: Information disclosure via short GSSAPI Curve25519 
> public key
> CVE-2026-59843: Denial of service via zero advertised channel packet 
> size
> CVE-2026-59844: Denial of service via oversized SFTP read length
> CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() 
> failure
> CVE-2026-59846: Information disclosure via ProxyCommand %r username 
> expansion
> CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag 
> verification
> CVE-2026-59848: Denial of service via SFTP responses with unknown 
> request IDs
> CVE-2026-59849: Denial of service via automatic certificate 
> authentication loop
> CVE-2026-59850: Use-after-free via data callbacks on closed channels
> CVE-2026-59851: Authentication bypass via missing GSSAPI principal 
> check
> Zero-initialize every ssh_string
> 
> Signed-off-by: Bernd Kuhls <[email protected]>

Applied to master, thanks.
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.