[Buildroot] [PATCH 2/5] package/libssh2: fix CVE-2026-66032

Stefan Müller via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
Backport the fix for CVE-2026-66032.

A SFTP error path can leave a dangling pointer after freeing the

response buffer, which may result in a double free on subsequent error

handling.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <[email protected]>

---

Backport to: 2025.02.x

---

...-prevent-dangling-pointer-after-free.patch | 28 +++++++++++++++++++

package/libssh2/libssh2.mk | 3 ++

2 files changed, 31 insertions(+)

create mode 100644 package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch

diff --git a/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch b/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch

new file mode 100644

index 0000000000..527365b33a

--- /dev/null

+++ b/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch

@@ -0,0 +1,28 @@

+From 5e4776146552d898b9c0e1b313cd093fa8dc92d0 Mon Sep 17 00:00:00 2001

+From: Will Cosgrove <[email protected]>

+Date: Thu, 2 Jul 2026 11:00:23 -0700

+Subject: [PATCH] Prevent dangling pointer by nullifying data (#2180)

+

+Set data to NULL after freeing it to avoid dangling pointer. fixes

+GHSA-px3w-7g75-hg7w.

+

+Credit: VladimirEliTokarev

+Forwarded: not-needed

+

+CVE: CVE-2026-66032

+Upstream: https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0

+Signed-off-by: Stefan Müller <[email protected]>

+---

+ src/sftp.c | 1 +

+ 1 file changed, 1 insertion(+)

+

+--- a/src/sftp.c

++++ b/src/sftp.c

+@@ -1279,6 +1279,7 @@

+ "got HANDLE FXOK"));

+

+ LIBSSH2_FREE(session, data);

++ data = NULL;

+

+ /* silly situation, but check for a HANDLE */

+ rc = sftp_packet_require(sftp, SSH_FXP_HANDLE,

diff --git a/package/libssh2/libssh2.mk b/package/libssh2/libssh2.mk

index 6b2d774b38..583ed56c1c 100644

--- a/package/libssh2/libssh2.mk

+++ b/package/libssh2/libssh2.mk

@@ -27,6 +27,9 @@ LIBSSH2_IGNORE_CVES += CVE-2026-55200

# 0006-sftp-symlink-fix-SSH_FXP_STATUS-response.patch

LIBSSH2_IGNORE_CVES += CVE-2025-15661

+# 0007-sftp-prevent-dangling-pointer-after-free.patch

+LIBSSH2_IGNORE_CVES += CVE-2026-66032

+

ifeq ($(BR2_PACKAGE_LIBSSH2_MBEDTLS),y)

LIBSSH2_DEPENDENCIES += mbedtls

LIBSSH2_CONF_OPTS += --with-libmbedcrypto-prefix=$(STAGING_DIR)/usr \

--

2.25.1

Freundliche GrüsseStefan MüllerREY TECHNOLOGY AGRütihofstrasse 6, CH-8370 SirnachStefan Müller | CTODirect +41 58 810 04 82 | Support +41 58 810 04 [email protected] | rey-technology.com

https://www.linkedin.com/company/rey-technology https://www.instagram.com/reytechnology_com/ https://teams.microsoft.com/l/chat/0/[email protected]

_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
linkedinmedium_e5ee0685-3767-4ffd-a5c5-9e4e3fc32352.png (image/png, 1.5 KB) - not displayed
instagrammedium_908c8ebd-b03d-4881-a6e2-043808ead83d.png (image/png, 1.9 KB) - not displayed
teamsmedium_9934c99a-98a5-42b7-9a66-2bebfdd7ebf1.png (image/png, 1.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.