Control: tag -1 pending

Hello Salvatore,

Salvatore Bonaccorso [2026-07-21 14:38 +0200]:
> Making a RC bug due to the amount of CVEs mainly and two CVEs only
> relevant for 0.12.0. We still need to assess the rest for trixie.

As usual, I'd recommend uploading 0.11.5 to trixie. The upstream stable
releases are well curated and tested. The previous two rounds were missed
though -- I prepared them for -security, then you said you marked them as
"wontfix" for stable-security, but I never got the "go!" for the stable-pu
request. Can't find the old bugs now, but "something" went wrong/got lost.

I'll prepare/test it in the next days.

> CVE-2026-59843[2]:
> | A flaw was found in libssh. A remote authenticated peer can
> | advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN,
> | causing later channel writes to loop indefinitely and consume CPU,
> | leading to denial of service.
> 
> Can you help on this one to identify the needed upstream change? There
> is one from master branch referenced in the advisory but that does not
> look to be backported to libssh-0.12.1? 

This was indeed forgotten. It's present on the 0.11 branch. I notified the
maintainers by email and also created a corresponding unit test. I backported
the fix as a patch in the 0.12.1 upload.

Martin

Reply via email to