On Thu Sep 3, 2026 at 12:06 PM CEST, Ghanshyam Banait via lists.openembedded.org wrote: > libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does > not zero-initialize new entries before parsing populates them, > so a parse failure reaching the cleanup path leaves > libssh2_publickey_list_free operating on an uninitialized entry. > A malicious SSH server offering the publickey subsystem can use a malformed > response to make cleanup free an uninitialized, > attacker-influenceable attrs pointer in a connecting libssh2 client. > > Reference: > https://nvd.nist.gov/vuln/detail/CVE-2026-58051 > > Backport the patch to fix CVE-2026-58051. > https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a > > Signed-off-by: Ghanshyam Banait <[email protected]> > --- > .../libssh2/libssh2/CVE-2026-58051.patch | 34 +++++++++++++++++++ > .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + > 2 files changed, 35 insertions(+) > create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch
Hello, There is already a pending patch for this CVE on wrynose: https://patchwork.yoctoproject.org/project/oe-core/patch/[email protected]/ Maybe you can help reviewing it? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245025): https://lists.openembedded.org/g/openembedded-core/message/245025 Mute This Topic: https://lists.openembedded.org/mt/121066571/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
