Re: [Buildroot] [PATCH 1/1] package/openssh: security bump to version 10.5p1

Julien Olivain via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
On 16/08/2026 09:53, Bernd Kuhls wrote:
> https://www.openssh.org/releasenotes.html#10.5p1
> 
> Changes since OpenSSH 10.4
> ==========================
> 
> This release contains a number of security fixes and small bugfixes.
> 
> Security
> ========
> 
>  * ssh-agent(1): fix an interaction between agent locking and the
>    [email protected] extension that is used to identify
>    forwarded agents. These binding requests were refused when the
>    agent was locked, with the result that operations that were
>    intended to be limited to local use only could be performed
>    remotely, including the ability to add PKCS#11 tokens and make
>    use of keys that had destination restrictions applied.
>    Reported by sn0x-sharma
> 
>  * ssh(1): avoid potential realloc use-after-free in the client if a
>    remote forwarding is added via the local session multiplexing
>    socket while a remote forwarding open request is pending with the
>    server. Report and fix from Brian Mingus of Cognatory
> 
>  * sshd(8): make the authorized_keys "restrict" keyword apply
>    correctly to tunnel forwarding too (which is administratively
>    disabled by default). Reported by Erichen, Institute of Computing
>    Technology, Chinese Academy of Sciences
> [...]
> 
> Signed-off-by: Bernd Kuhls <[email protected]>

Applied to master, thanks.
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.