Control: tag -1 pending Hello Salvatore,
Salvatore Bonaccorso [2026-07-21 14:38 +0200]: > Making a RC bug due to the amount of CVEs mainly and two CVEs only > relevant for 0.12.0. We still need to assess the rest for trixie. As usual, I'd recommend uploading 0.11.5 to trixie. The upstream stable releases are well curated and tested. The previous two rounds were missed though -- I prepared them for -security, then you said you marked them as "wontfix" for stable-security, but I never got the "go!" for the stable-pu request. Can't find the old bugs now, but "something" went wrong/got lost. I'll prepare/test it in the next days. > CVE-2026-59843[2]: > | A flaw was found in libssh. A remote authenticated peer can > | advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, > | causing later channel writes to loop indefinitely and consume CPU, > | leading to denial of service. > > Can you help on this one to identify the needed upstream change? There > is one from master branch referenced in the advisory but that does not > look to be backported to libssh-0.12.1? This was indeed forgotten. It's present on the 0.11 branch. I notified the maintainers by email and also created a corresponding unit test. I backported the fix as a patch in the 0.12.1 upload. Martin

