[Buildroot] [PATCH 2/5] package/libssh2: fix CVE-2026-66032
Stefan Müller via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
Backport the fix for CVE-2026-66032. A SFTP error path can leave a dangling pointer after freeing the response buffer, which may result in a double free on subsequent error handling. Use Debian's libssh2 1.11.1 backport of the upstream fix. Signed-off-by: Stefan Müller <[email protected]> --- Backport to: 2025.02.x --- ...-prevent-dangling-pointer-after-free.patch | 28 +++++++++++++++++++ package/libssh2/libssh2.mk | 3 ++ 2 files changed, 31 insertions(+) create mode 100644 package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch diff --git a/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch b/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch new file mode 100644 index 0000000000..527365b33a --- /dev/null +++ b/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch @@ -0,0 +1,28 @@ +From 5e4776146552d898b9c0e1b313cd093fa8dc92d0 Mon Sep 17 00:00:00 2001 +From: Will Cosgrove <[email protected]> +Date: Thu, 2 Jul 2026 11:00:23 -0700 +Subject: [PATCH] Prevent dangling pointer by nullifying data (#2180) + +Set data to NULL after freeing it to avoid dangling pointer. fixes +GHSA-px3w-7g75-hg7w. + +Credit: VladimirEliTokarev +Forwarded: not-needed + +CVE: CVE-2026-66032 +Upstream: https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0 +Signed-off-by: Stefan Müller <[email protected]> +--- + src/sftp.c | 1 + + 1 file changed, 1 insertion(+) + +--- a/src/sftp.c ++++ b/src/sftp.c +@@ -1279,6 +1279,7 @@ + "got HANDLE FXOK")); + + LIBSSH2_FREE(session, data); ++ data = NULL; + + /* silly situation, but check for a HANDLE */ + rc = sftp_packet_require(sftp, SSH_FXP_HANDLE, diff --git a/package/libssh2/libssh2.mk b/package/libssh2/libssh2.mk index 6b2d774b38..583ed56c1c 100644 --- a/package/libssh2/libssh2.mk +++ b/package/libssh2/libssh2.mk @@ -27,6 +27,9 @@ LIBSSH2_IGNORE_CVES += CVE-2026-55200 # 0006-sftp-symlink-fix-SSH_FXP_STATUS-response.patch LIBSSH2_IGNORE_CVES += CVE-2025-15661 +# 0007-sftp-prevent-dangling-pointer-after-free.patch +LIBSSH2_IGNORE_CVES += CVE-2026-66032 + ifeq ($(BR2_PACKAGE_LIBSSH2_MBEDTLS),y) LIBSSH2_DEPENDENCIES += mbedtls LIBSSH2_CONF_OPTS += --with-libmbedcrypto-prefix=$(STAGING_DIR)/usr \ -- 2.25.1 Freundliche GrüsseStefan MüllerREY TECHNOLOGY AGRütihofstrasse 6, CH-8370 SirnachStefan Müller | CTODirect +41 58 810 04 82 | Support +41 58 810 04 [email protected] | rey-technology.com https://www.linkedin.com/company/rey-technology https://www.instagram.com/reytechnology_com/ https://teams.microsoft.com/l/chat/0/[email protected] _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot
linkedinmedium_e5ee0685-3767-4ffd-a5c5-9e4e3fc32352.png
(image/png, 1.5 KB) - not displayed
instagrammedium_908c8ebd-b03d-4881-a6e2-043808ead83d.png
(image/png, 1.9 KB) - not displayed
teamsmedium_9934c99a-98a5-42b7-9a66-2bebfdd7ebf1.png
(image/png, 1.9 KB) - not displayed