Source: libssh Version: 1.11.1-4 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for libssh. CVE-2026-66032[0]: | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double- | free vulnerability in the sftp_open() function in src/sftp.c that | allows a malicious SSH server to corrupt the heap of any | authenticated client opening an SFTP session. When a server responds | to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response | data buffer is freed, and if a subsequent sftp_packet_require() call | returns a specific error such as | LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a | second time, enabling tcache dup conditions on glibc systems that | allow overlapping allocations and function pointer overwrites. CVE-2026-66033[1]: | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre- | authentication integer underflow vulnerability in the | ssh2_cipher_crypt() function in src/openssl.c that allows a | malicious SSH server to crash any connecting client by negotiating | AES-GCM ciphers during handshake. Attackers can exploit the | underflow in the expression computing blocksize minus aadlen minus | authentication tag length to trigger an out-of-bounds read and a | memcpy call with a near-SIZE_MAX length argument, causing immediate | process crash before any authentication occurs. CVE-2026-66034[2]: | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing | bounds check vulnerability that allows a malicious SSH server to | trigger an arbitrary-length heap out-of-bounds read and a free of an | uninitialized pointer via the publickey subsystem. In | libssh2_publickey_list_fetch(), the version 1 response parser reads | a server-controlled comment_len value and advances the parse pointer | without verifying sufficient bytes remain in the buffer, causing the | out-of-bounds read to leak heap pointers from adjacent allocations | defeating ASLR, followed by heap allocator state corruption when the | error cleanup path frees an uninitialized pointer from a non-zeroed | realloc() region. CVE-2026-66035[3]: | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre- | authentication heap buffer overflow vulnerability that allows a | malicious SSH server to corrupt heap metadata in any connecting | client by sending a packet with a packet_length smaller than the | cipher's block size during Encrypt-then-MAC cipher negotiation. In | the fullpacket() function in src/transport.c, the ETM path allocates | a buffer of packet_length bytes but copies blocksize minus one bytes | via memcpy, causing an overflow that on 32-bit glibc writes | attacker-controlled bytes into an adjacent chunk's SIZE field, | enabling tcache bin confusion, overlapping live objects, and | function pointer overwrite during the session handshake before | authentication. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-66032 https://www.cve.org/CVERecord?id=CVE-2026-66032 [1] https://security-tracker.debian.org/tracker/CVE-2026-66033 https://www.cve.org/CVERecord?id=CVE-2026-66033 [2] https://security-tracker.debian.org/tracker/CVE-2026-66034 https://www.cve.org/CVERecord?id=CVE-2026-66034 [3] https://security-tracker.debian.org/tracker/CVE-2026-66035 https://www.cve.org/CVERecord?id=CVE-2026-66035 Regards, Salvatore

