Your message dated Sat, 12 Sep 2026 08:05:41 +0000
with message-id <[email protected]>
and subject line Released in 13.7
has caused the Debian Bug report #1145104,
regarding trixie-pu: package libssh2/libssh2_1.11.1-1+deb13u2
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1145104: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145104
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], Salvatore Bonaccorso
<[email protected]>, Emmanuel Arias <[email protected]>
Control: affects -1 + src:libssh2
User: [email protected]
Usertags: pu
[ Reason ]
Fix CVEs CVE-2026-66032 CVE-2026-66033 CVE-2026-66034 CVE-2026-66035
CVE-2026-58050 CVE-2026-58051
[ Impact ]
Denial of service, heap corruption or information disclosure
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
Backport of the packages 1.11.1-6 and 1.11.1-5 in unstable
diff -Nru libssh2-1.11.1/debian/changelog libssh2-1.11.1/debian/changelog
--- libssh2-1.11.1/debian/changelog 2026-06-23 17:01:56.000000000 -0400
+++ libssh2-1.11.1/debian/changelog 2026-08-02 10:50:39.000000000 -0400
@@ -1,3 +1,10 @@
+libssh2 (1.11.1-1+deb13u2) trixie; urgency=medium
+
+ * d/patches: Fix CVEs CVE-2026-66032 CVE-2026-66033 CVE-2026-66034
+ CVE-2026-66035 CVE-2026-58050 CVE-2026-58051 (Backport from unstable)
+
+ -- Nicolas Mora <[email protected]> Sun, 02 Aug 2026 10:50:39 -0400
+
libssh2 (1.11.1-1+deb13u1) trixie-security; urgency=medium
* CVE-2026-7598 (Closes: #1135647)
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-58050.patch
libssh2-1.11.1/debian/patches/CVE-2026-58050.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-58050.patch 1969-12-31
19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-58050.patch 2026-08-02
10:50:39.000000000 -0400
@@ -0,0 +1,34 @@
+From 34497525929b9a47f03dfb81887ac896202b7e12 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Sun, 28 Jun 2026 02:12:52 +0200
+Subject: [PATCH] publickey: fix potential multiplication overflow in 32-bit
+ `libssh2_publickey_list_fetch()`
+
+Cap list size at 1024 elements.
+
+Reported-and-initial-patch-by: Mateusz Gierblinski
+Reported-and-initial-patch-by: Behzod Abdullayev
+Reported-by: Sharique Raza
+
+Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9
+
+Closes #2128
+Forwarded: not-needed
+---
+ src/publickey.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -1121,6 +1121,11 @@
+ }
+
+ if(list[keys].num_attrs) {
++ if(list[keys].num_attrs > 1024) {
++ _libssh2_error(session, LIBSSH2_ERROR_OUT_OF_BOUNDARY,
++ "Too many publickey attributes");
++ goto err_exit;
++ }
+ list[keys].attrs =
+ LIBSSH2_ALLOC(session,
+ list[keys].num_attrs *
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-58051.patch
libssh2-1.11.1/debian/patches/CVE-2026-58051.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-58051.patch 1969-12-31
19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-58051.patch 2026-08-02
10:50:39.000000000 -0400
@@ -0,0 +1,25 @@
+From 32092f0d310f4d769e5ed073ad5987f997f446dc Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Sun, 28 Jun 2026 02:13:32 +0200
+Subject: [PATCH] publickey: fix potential arbitrary free in
+ `libssh2_publickey_list_fetch()`
+
+Due to uninitialized list entry.
+
+Reported-and-patch-by: Behzod Abdullayev
+Reported-by: Sharique Raza
+Forwarded: not-needed
+---
+ src/publickey.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -972,6 +972,7 @@
+ goto err_exit;
+ }
+ list = newlist;
++ memset(&list[keys], 0, sizeof(list[keys]));
+ }
+ if(pkey->version == 1) {
+ unsigned long comment_len;
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-66032.patch
libssh2-1.11.1/debian/patches/CVE-2026-66032.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-66032.patch 1969-12-31
19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-66032.patch 2026-08-02
10:44:29.000000000 -0400
@@ -0,0 +1,24 @@
+From 5e4776146552d898b9c0e1b313cd093fa8dc92d0 Mon Sep 17 00:00:00 2001
+From: Will Cosgrove <[email protected]>
+Date: Thu, 2 Jul 2026 11:00:23 -0700
+Subject: [PATCH] Prevent dangling pointer by nullifying data (#2180)
+
+Set data to NULL after freeing it to avoid dangling pointer. fixes
+GHSA-px3w-7g75-hg7w.
+
+Credit: VladimirEliTokarev
+Forwarded: not-needed
+---
+ src/sftp.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -1279,6 +1279,7 @@
+ "got HANDLE FXOK"));
+
+ LIBSSH2_FREE(session, data);
++ data = NULL;
+
+ /* silly situation, but check for a HANDLE */
+ rc = sftp_packet_require(sftp, SSH_FXP_HANDLE,
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-66033.patch
libssh2-1.11.1/debian/patches/CVE-2026-66033.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-66033.patch 1969-12-31
19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-66033.patch 2026-08-02
10:44:33.000000000 -0400
@@ -0,0 +1,40 @@
+From a2ed82d40964bbc0d64cd717aa0a5a892117d2e6 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Thu, 23 Jul 2026 10:32:04 +0200
+Subject: [PATCH] openssl: fix potential OOB read/write with AES-GCM in
+ `ssh2_cipher_crypt()`
+
+By applying two bounds checks to non-debug builds.
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-c4f7-cvfc-33j7
+Follow-up to 3c953c05d67eb1ebcfd3316f279f12c4b1d600b4 #797
+
+Closes #2401
+Forwarded: not-needed
+---
+ src/openssl.c | 10 ++++++----
+ 1 file changed, 6 insertions(+), 4 deletions(-)
+
+--- a/src/openssl.c
++++ b/src/openssl.c
+@@ -1042,13 +1042,15 @@
+ const int aadlen = (is_aesgcm && IS_FIRST(firstlast)) ? 4 : 0;
+ /* size of AT, if present */
+ const int authenticationtag = IS_LAST(firstlast) ? authlen : 0;
+- /* length to encrypt */
+- const int cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
++ unsigned int cryptlen; /* length to encrypt */
+
+ (void)algo;
+
+- assert(blocksize <= sizeof(buf));
+- assert(cryptlen >= 0);
++ if(blocksize > sizeof(buf) ||
++ blocksize < (size_t)(aadlen + authenticationtag))
++ return 1;
++
++ cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
+
+ #if LIBSSH2_AES_GCM
+ /* First block */
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-66034.patch
libssh2-1.11.1/debian/patches/CVE-2026-66034.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-66034.patch 1969-12-31
19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-66034.patch 2026-08-02
10:44:38.000000000 -0400
@@ -0,0 +1,31 @@
+From a13bb6c773f0d55ad1628cede57e99803cd898d9 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Sat, 4 Jul 2026 11:19:49 +0200
+Subject: [PATCH] publickey: fix potential OOB read in
+ `libssh2_publickey_list_fetch()`
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-w6g9-cpfp-22gc
+
+Closes #2202
+Forwarded: not-needed
+---
+ src/publickey.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -988,6 +988,13 @@
+ }
+
+ if(comment_len) {
++ if(pkey->listFetch_s + comment_len >
++ pkey->listFetch_data + pkey->listFetch_data_len) {
++ _libssh2_error(session,
LIBSSH2_ERROR_BUFFER_TOO_SMALL,
++ "ListFetch data too short");
++ goto err_exit;
++ }
++
+ list[keys].num_attrs = 1;
+ list[keys].attrs =
+ LIBSSH2_ALLOC(session,
diff -Nru libssh2-1.11.1/debian/patches/CVE-2026-66035.patch
libssh2-1.11.1/debian/patches/CVE-2026-66035.patch
--- libssh2-1.11.1/debian/patches/CVE-2026-66035.patch 1969-12-31
19:00:00.000000000 -0500
+++ libssh2-1.11.1/debian/patches/CVE-2026-66035.patch 2026-08-02
10:44:41.000000000 -0400
@@ -0,0 +1,37 @@
+From 42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <[email protected]>
+Date: Fri, 3 Jul 2026 18:22:55 +0200
+Subject: [PATCH] transport: fix potential heap overflow on ETM decrypt
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-6c79-444r-wx26
+
+Closes #2198
+Forwarded: not-needed
+---
+ src/transport.c | 7 ++++++-
+ 1 file changed, 6 insertions(+), 1 deletion(-)
+
+--- a/src/transport.c
++++ b/src/transport.c
+@@ -242,6 +242,12 @@
+ unsigned char *decrypt_buffer;
+ int blocksize = session->remote.crypt->blocksize;
+
++ if(p->total_num < mac_len + 4 + (size_t)blocksize) {
++ LIBSSH2_FREE(session, p->payload);
++ return LIBSSH2_ERROR_DECRYPT;
++ }
++ decrypt_size = (ssize_t)(p->total_num - mac_len - 4);
++
+ rc = decrypt(session, p->payload + 4,
+ first_block, blocksize, FIRST_BLOCK);
+ if(rc) {
+@@ -249,7 +255,6 @@
+ }
+
+ /* we need buffer for decrypt */
+- decrypt_size = p->total_num - mac_len - 4;
+ decrypt_buffer = LIBSSH2_ALLOC(session, decrypt_size);
+ if(!decrypt_buffer) {
+ return LIBSSH2_ERROR_ALLOC;
diff -Nru libssh2-1.11.1/debian/patches/series
libssh2-1.11.1/debian/patches/series
--- libssh2-1.11.1/debian/patches/series 2026-06-23 17:01:56.000000000
-0400
+++ libssh2-1.11.1/debian/patches/series 2026-08-02 10:50:39.000000000
-0400
@@ -11,3 +11,9 @@
CVE-2026-55199.patch
CVE-2026-55200.patch
libssh-unconst-backport.patch
+CVE-2026-66032.patch
+CVE-2026-66033.patch
+CVE-2026-66034.patch
+CVE-2026-66035.patch
+CVE-2026-58050.patch
+CVE-2026-58051.patch
--- End Message ---
--- Begin Message ---
Version: 13.7
This update was released as part of 13.7.
--- End Message ---