On Thu Sep 3, 2026 at 12:06 PM CEST, Ghanshyam Banait via 
lists.openembedded.org wrote:
> libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does 
> not zero-initialize new entries before parsing populates them,
> so a parse failure reaching the cleanup path leaves 
> libssh2_publickey_list_free operating on an uninitialized entry.
> A malicious SSH server offering the publickey subsystem can use a malformed 
> response to make cleanup free an uninitialized,
> attacker-influenceable attrs pointer in a connecting libssh2 client.
>
> Reference:
> https://nvd.nist.gov/vuln/detail/CVE-2026-58051
>
> Backport the patch to fix CVE-2026-58051.
> https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
>
> Signed-off-by: Ghanshyam Banait <[email protected]>
> ---
>  .../libssh2/libssh2/CVE-2026-58051.patch      | 34 +++++++++++++++++++
>  .../recipes-support/libssh2/libssh2_1.11.1.bb |  1 +
>  2 files changed, 35 insertions(+)
>  create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch

Hello,

There is already a pending patch for this CVE on wrynose:
https://patchwork.yoctoproject.org/project/oe-core/patch/[email protected]/

Maybe you can help reviewing it?

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245025): 
https://lists.openembedded.org/g/openembedded-core/message/245025
Mute This Topic: https://lists.openembedded.org/mt/121066571/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Ghanshyam Banait via lists.openembedded.org
      • ... Yoann Congal via lists.openembedded.org

Reply via email to