Hi Martin,

On Sat, Aug 01, 2026 at 02:06:47PM +0200, Martin Pitt wrote:
> Control: tag -1 pending
> 
> Hello Salvatore!
> 
> Salvatore Bonaccorso [2026-07-21 14:38 +0200]:
> > Source: libssh
> > Version: 0.12.0-3
> > Severity: grave
> > Tags: security upstream
> > Justification: user security hole
> 
> Sorry for the delay! Life.. But the fixes have been in unstable for about a
> week, and in testing since yesterday, and I got no complaints. autopkgtests
> were happy as well.
> 
> > CVE-2026-59842[1]:
> > | A flaw was found in libssh. During server-side GSSAPI key exchange,
> > | a client-supplied Curve25519 public key shorter than the expected
> > | length is copied without proper length validation, leading to an
> > | out-of-bounds heap read. This could allow a remote unauthenticated
> > | attacker to disclose small amounts of server memory.
> 
> This does not apply to trixie and earlier. Fix is
> https://git.libssh.org/projects/libssh.git/commit/?id=ed9109dfc64b92c250b7e8c4c2045dad30d433f8
> 
> and that code was introduced in the 0.12 series, i.e. not present in 0.11 and
> earlier.
> 
> > CVE-2026-59851[10]:
> > | Authentication bypass via missing GSSAPI principal check
> 
> Same story:
> https://git.libssh.org/projects/libssh.git/commit/?id=a45d20b75278858a6f06364722e068b32f181197
> 
> kex-gss.cs does not exist in 0.11 and ealier.
> 
> The others are fixed in 0.11.5. I packaged and tested it, ran autopkgtest, and
> put it on
> 
>   https://people.debian.org/~mpitt/tmp/
> 
> Note that this includes (and the above dir still separately contains) the
> previous 0.11.4 which was declined for -security and never accepted into
> updates.
> 
> debdiff to current trixie-security is at
> https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1_0.11.5-0+deb13u1.debdiff

Thank you, please upload to security-master (needs to be built with
-sa).

Regards,
Salvatore

Reply via email to