Re: [Buildroot] [PATCH v2 1/5] package/libssh2: fix CVE-2025-15661
Julien Olivain via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
On 20/08/2026 09:32, Stefan Mueller via buildroot wrote: > From: Stefan Müller <[email protected]> > > Backport the SFTP symlink bounds checking fix for CVE-2025-15661. > > The initial fix requires the LIBSSH2_UNCONST compatibility backport on > libssh2 1.11.1. Also include the upstream follow-up fixing > SSH_FXP_STATUS handling introduced by the initial security fix. > > The patches are based on the upstream fixes and Debian's libssh2 1.11.1 > backports. > > Signed-off-by: Stefan Müller <[email protected]> Series applied to master, thanks. I also added links to the Debian patches, for better transparency and traceability. Best regards, Julien. _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot