[Buildroot] [git commit] package/libssh2: fix CVE-2026-66033
Julien Olivain via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
commit: https://gitlab.com/buildroot.org/buildroot/-/commit/6755a00cd23e52cee0085cf2a16f29042731bc0c branch: https://gitlab.com/buildroot.org/buildroot/-/tree/master Backport the fix for CVE-2026-66033. The OpenSSL AES-GCM cipher path lacks runtime bounds checks around the input block size. A malformed packet can therefore lead to an out-of-bounds read or write. Use Debian's libssh2 1.11.1 backport of the upstream fix. Signed-off-by: Stefan Müller <[email protected]> [Julien: add links to Debian patches] Signed-off-by: Julien Olivain <[email protected]> --- .../0008-openssl-fix-AES-GCM-bounds-checks.patch | 45 ++++++++++++++++++++++ package/libssh2/libssh2.mk | 3 ++ 2 files changed, 48 insertions(+) diff --git a/package/libssh2/0008-openssl-fix-AES-GCM-bounds-checks.patch b/package/libssh2/0008-openssl-fix-AES-GCM-bounds-checks.patch new file mode 100644 index 0000000000..4d8eed0643 --- /dev/null +++ b/package/libssh2/0008-openssl-fix-AES-GCM-bounds-checks.patch @@ -0,0 +1,45 @@ +From a2ed82d40964bbc0d64cd717aa0a5a892117d2e6 Mon Sep 17 00:00:00 2001 +From: Viktor Szakats <[email protected]> +Date: Thu, 23 Jul 2026 10:32:04 +0200 +Subject: [PATCH] openssl: fix potential OOB read/write with AES-GCM in + `ssh2_cipher_crypt()` + +By applying two bounds checks to non-debug builds. + +Reported-by: Vladimir Eli Tokarev +Fixes GHSA-c4f7-cvfc-33j7 +Follow-up to 3c953c05d67eb1ebcfd3316f279f12c4b1d600b4 #797 + +Closes #2401 +Forwarded: not-needed + +CVE: CVE-2026-66033 +Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/CVE-2026-66033.patch/ +Upstream: https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6 +Signed-off-by: Stefan Müller <[email protected]> +--- + src/openssl.c | 10 ++++++---- + 1 file changed, 6 insertions(+), 4 deletions(-) + +--- a/src/openssl.c ++++ b/src/openssl.c +@@ -1042,13 +1042,15 @@ + const int aadlen = (is_aesgcm && IS_FIRST(firstlast)) ? 4 : 0; + /* size of AT, if present */ + const int authenticationtag = IS_LAST(firstlast) ? authlen : 0; +- /* length to encrypt */ +- const int cryptlen = (unsigned int)blocksize - aadlen - authenticationtag; ++ unsigned int cryptlen; /* length to encrypt */ + + (void)algo; + +- assert(blocksize <= sizeof(buf)); +- assert(cryptlen >= 0); ++ if(blocksize > sizeof(buf) || ++ blocksize < (size_t)(aadlen + authenticationtag)) ++ return 1; ++ ++ cryptlen = (unsigned int)blocksize - aadlen - authenticationtag; + + #if LIBSSH2_AES_GCM + /* First block */ diff --git a/package/libssh2/libssh2.mk b/package/libssh2/libssh2.mk index 583ed56c1c..a3c0b6a67f 100644 --- a/package/libssh2/libssh2.mk +++ b/package/libssh2/libssh2.mk @@ -30,6 +30,9 @@ LIBSSH2_IGNORE_CVES += CVE-2025-15661 # 0007-sftp-prevent-dangling-pointer-after-free.patch LIBSSH2_IGNORE_CVES += CVE-2026-66032 +# 0008-openssl-fix-AES-GCM-bounds-checks.patch +LIBSSH2_IGNORE_CVES += CVE-2026-66033 + ifeq ($(BR2_PACKAGE_LIBSSH2_MBEDTLS),y) LIBSSH2_DEPENDENCIES += mbedtls LIBSSH2_CONF_OPTS += --with-libmbedcrypto-prefix=$(STAGING_DIR)/usr \ _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot