[Buildroot] [git commit] package/libssh2: fix CVE-2026-66032

Julien Olivain via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
commit: https://gitlab.com/buildroot.org/buildroot/-/commit/05c13e87e983705ef65c18979a5d1bb7b50438a2
branch: https://gitlab.com/buildroot.org/buildroot/-/tree/master

Backport the fix for CVE-2026-66032.

A SFTP error path can leave a dangling pointer after freeing the
response buffer, which may result in a double free on subsequent error
handling.

Use Debian's libssh2 1.11.1 backport of the upstream fix.

Signed-off-by: Stefan Müller <[email protected]>
[Julien: add links to Debian patches]
Signed-off-by: Julien Olivain <[email protected]>
---
 ...-sftp-prevent-dangling-pointer-after-free.patch | 29 ++++++++++++++++++++++
 package/libssh2/libssh2.mk                         |  3 +++
 2 files changed, 32 insertions(+)

diff --git a/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch b/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch
new file mode 100644
index 0000000000..3658c00e0d
--- /dev/null
+++ b/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch
@@ -0,0 +1,29 @@
+From 5e4776146552d898b9c0e1b313cd093fa8dc92d0 Mon Sep 17 00:00:00 2001
+From: Will Cosgrove <[email protected]>
+Date: Thu, 2 Jul 2026 11:00:23 -0700
+Subject: [PATCH] Prevent dangling pointer by nullifying data (#2180)
+
+Set data to NULL after freeing it to avoid dangling pointer. fixes
+GHSA-px3w-7g75-hg7w.
+
+Credit: VladimirEliTokarev
+Forwarded: not-needed
+
+CVE: CVE-2026-66032
+Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/CVE-2026-66032.patch/
+Upstream: https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0
+Signed-off-by: Stefan Müller <[email protected]>
+---
+ src/sftp.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -1279,6 +1279,7 @@
+                                "got HANDLE FXOK"));
+
+                 LIBSSH2_FREE(session, data);
++                data = NULL;
+
+                 /* silly situation, but check for a HANDLE */
+                 rc = sftp_packet_require(sftp, SSH_FXP_HANDLE,
diff --git a/package/libssh2/libssh2.mk b/package/libssh2/libssh2.mk
index 6b2d774b38..583ed56c1c 100644
--- a/package/libssh2/libssh2.mk
+++ b/package/libssh2/libssh2.mk
@@ -27,6 +27,9 @@ LIBSSH2_IGNORE_CVES += CVE-2026-55200
 # 0006-sftp-symlink-fix-SSH_FXP_STATUS-response.patch
 LIBSSH2_IGNORE_CVES += CVE-2025-15661
 
+# 0007-sftp-prevent-dangling-pointer-after-free.patch
+LIBSSH2_IGNORE_CVES += CVE-2026-66032
+
 ifeq ($(BR2_PACKAGE_LIBSSH2_MBEDTLS),y)
 LIBSSH2_DEPENDENCIES += mbedtls
 LIBSSH2_CONF_OPTS += --with-libmbedcrypto-prefix=$(STAGING_DIR)/usr \

_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.