Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libssh for openSUSE:Factory checked 
in at 2026-07-26 11:27:49
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libssh (Old)
 and      /work/SRC/openSUSE:Factory/.libssh.new.2004 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libssh"

Sun Jul 26 11:27:49 2026 rev:83 rq:1367382 version:0.11.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/libssh/libssh.changes    2026-03-28 
20:14:36.036517137 +0100
+++ /work/SRC/openSUSE:Factory/.libssh.new.2004/libssh.changes  2026-07-26 
11:29:55.661701566 +0200
@@ -1,0 +2,37 @@
+Wed Jul 22 08:10:14 UTC 2026 - Pedro Monreal <[email protected]>
+
+- Update to 0.11.5:
+  * Security:
+    - CVE-2026-15370: Stack buffer overflow in SFTP server
+      longname construction (bsc#1272162)
+    - CVE-2026-59843: Denial of service via zero advertised
+      channel packet size (bsc#1272164)
+    - CVE-2026-59844: Denial of service via oversized SFTP read
+      length (bsc#1272165)
+    - CVE-2026-59845: Denial of service via unchecked ProxyCommand
+      fork() failure (bsc#1272166)
+    - CVE-2026-59846: Information disclosure via ProxyCommand %r
+      username expansion (bsc#1272167)
+    - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag
+      verification (bsc#1272168)
+    - CVE-2026-59848: Denial of service via SFTP responses with
+      unknown request IDs (bsc#1272169)
+    - CVE-2026-59849: Denial of service via automatic certificate
+      authentication loop (bsc#1272170)
+    - CVE-2026-59850: Use-after-free via data callbacks on closed
+      channels (bsc#1272171)
+    - Zero-initialize every ssh_string
+  * Compatibility:
+    - Fix compatibility with C23 / gcc16
+  * Bugfixes:
+    - Fix multiple memory leaks, null checks, and error checks
+    - Validate peer public key in DH key exchange
+    - Avoid remote window overflow
+    - Avoid off-by-one overflow during kbdint authentication
+    - Avoid logging uninitialized sequence numbers
+    - Avoid double conversion of SFTP version number
+    - Send correct SFTP server version number
+    - Avoid handling repeated SFTP INIT messages
+    - Harmonize return values from SFTP server callbacks
+
+-------------------------------------------------------------------

Old:
----
  libssh-0.11.4.tar.xz
  libssh-0.11.4.tar.xz.asc

New:
----
  libssh-0.11.5.tar.xz
  libssh-0.11.5.tar.xz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libssh.spec ++++++
--- /var/tmp/diff_new_pack.3aQFVW/_old  2026-07-26 11:29:56.217720766 +0200
+++ /var/tmp/diff_new_pack.3aQFVW/_new  2026-07-26 11:29:56.217720766 +0200
@@ -32,7 +32,7 @@
 %endif
 
 Name:           libssh%{pkg_suffix}
-Version:        0.11.4
+Version:        0.11.5
 Release:        0
 Summary:        The SSH library
 License:        LGPL-2.1-or-later

++++++ libssh-0.11.4.tar.xz -> libssh-0.11.5.tar.xz ++++++
++++ 3411 lines of diff (skipped)

Reply via email to