Re: [Buildroot] [PATCH 1/1] package/openssh: security bump to version 10.5p1
Julien Olivain via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
On 16/08/2026 09:53, Bernd Kuhls wrote: > https://www.openssh.org/releasenotes.html#10.5p1 > > Changes since OpenSSH 10.4 > ========================== > > This release contains a number of security fixes and small bugfixes. > > Security > ======== > > * ssh-agent(1): fix an interaction between agent locking and the > [email protected] extension that is used to identify > forwarded agents. These binding requests were refused when the > agent was locked, with the result that operations that were > intended to be limited to local use only could be performed > remotely, including the ability to add PKCS#11 tokens and make > use of keys that had destination restrictions applied. > Reported by sn0x-sharma > > * ssh(1): avoid potential realloc use-after-free in the client if a > remote forwarding is added via the local session multiplexing > socket while a remote forwarding open request is pending with the > server. Report and fix from Brian Mingus of Cognatory > > * sshd(8): make the authorized_keys "restrict" keyword apply > correctly to tunnel forwarding too (which is administratively > disabled by default). Reported by Erichen, Institute of Computing > Technology, Chinese Academy of Sciences > [...] > > Signed-off-by: Bernd Kuhls <[email protected]> Applied to master, thanks. _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot