Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libssh for openSUSE:Factory checked in at 2026-07-26 11:27:49 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libssh (Old) and /work/SRC/openSUSE:Factory/.libssh.new.2004 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libssh" Sun Jul 26 11:27:49 2026 rev:83 rq:1367382 version:0.11.5 Changes: -------- --- /work/SRC/openSUSE:Factory/libssh/libssh.changes 2026-03-28 20:14:36.036517137 +0100 +++ /work/SRC/openSUSE:Factory/.libssh.new.2004/libssh.changes 2026-07-26 11:29:55.661701566 +0200 @@ -1,0 +2,37 @@ +Wed Jul 22 08:10:14 UTC 2026 - Pedro Monreal <[email protected]> + +- Update to 0.11.5: + * Security: + - CVE-2026-15370: Stack buffer overflow in SFTP server + longname construction (bsc#1272162) + - CVE-2026-59843: Denial of service via zero advertised + channel packet size (bsc#1272164) + - CVE-2026-59844: Denial of service via oversized SFTP read + length (bsc#1272165) + - CVE-2026-59845: Denial of service via unchecked ProxyCommand + fork() failure (bsc#1272166) + - CVE-2026-59846: Information disclosure via ProxyCommand %r + username expansion (bsc#1272167) + - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag + verification (bsc#1272168) + - CVE-2026-59848: Denial of service via SFTP responses with + unknown request IDs (bsc#1272169) + - CVE-2026-59849: Denial of service via automatic certificate + authentication loop (bsc#1272170) + - CVE-2026-59850: Use-after-free via data callbacks on closed + channels (bsc#1272171) + - Zero-initialize every ssh_string + * Compatibility: + - Fix compatibility with C23 / gcc16 + * Bugfixes: + - Fix multiple memory leaks, null checks, and error checks + - Validate peer public key in DH key exchange + - Avoid remote window overflow + - Avoid off-by-one overflow during kbdint authentication + - Avoid logging uninitialized sequence numbers + - Avoid double conversion of SFTP version number + - Send correct SFTP server version number + - Avoid handling repeated SFTP INIT messages + - Harmonize return values from SFTP server callbacks + +------------------------------------------------------------------- Old: ---- libssh-0.11.4.tar.xz libssh-0.11.4.tar.xz.asc New: ---- libssh-0.11.5.tar.xz libssh-0.11.5.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libssh.spec ++++++ --- /var/tmp/diff_new_pack.3aQFVW/_old 2026-07-26 11:29:56.217720766 +0200 +++ /var/tmp/diff_new_pack.3aQFVW/_new 2026-07-26 11:29:56.217720766 +0200 @@ -32,7 +32,7 @@ %endif Name: libssh%{pkg_suffix} -Version: 0.11.4 +Version: 0.11.5 Release: 0 Summary: The SSH library License: LGPL-2.1-or-later ++++++ libssh-0.11.4.tar.xz -> libssh-0.11.5.tar.xz ++++++ ++++ 3411 lines of diff (skipped)
