From: Hetvi Thakar <[email protected]>

This patch applies the upstream fix that permits session-bind requests
while the agent is locked so forwarded sessions remain classified as
remote. The upstream fix commit is referenced in [1], and the public
CVE advisory is referenced in [2].

[1] 
https://github.com/openssh/openssh-portable/commit/6a57081dc35acf3ee298108d4bc3580489608d5
[2] https://www.cve.org/CVERecord?id=CVE-2026-73281

Signed-off-by: Hetvi Thakar <[email protected]>
---
 .../openssh/openssh/CVE-2026-73281.patch      | 80 +++++++++++++++++++
 .../openssh/openssh_10.3p1.bb                 |  1 +
 2 files changed, 81 insertions(+)
 create mode 100644 
meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch 
b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch
new file mode 100644
index 00000000000..6dbe7b33ff3
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch
@@ -0,0 +1,80 @@
+From 6a57081dc35acf3ee298108d4bc3580489608d5 Mon Sep 17 00:00:00 2001
+From: "[email protected]" <[email protected]>
+Date: Fri, 7 Aug 2026 05:18:05 +0000
+Subject: [PATCH] upstream: Allow [email protected] requests when the
+ agent is
+
+locked, otherwise forwarding sessions established with an agent was locked
+will be treated as local, rather than remote.
+
+Reported by sn0x-sharma
+
+OpenBSD-Commit-ID: 524f210c6f2b3a06e0a2f6d0af5188a9a75fa2c7
+
+CVE: CVE-2026-73281
+Upstream-Status: Backport 
[https://github.com/openssh/openssh-portable/commit/6a57081dc35acf3ee298108d4bc3580489608d5]
+
+Backport Changes:
+- Omitted the upstream OpenBSD revision-only hunk and retained the Wrynose
+  OpenSSH 10.3p1 revision.
+- OpenSSH 10.3p1 lacks the later `replied` result tracking in
+  process_extension(), so retained `success = process_ext_query(e)`.
+
+(cherry picked from commit 6a57081dc35acf3ee298108d4bc3580489608d5)
+Signed-off-by: Hetvi Thakar <[email protected]>
+---
+ ssh-agent.c | 23 +++++++++++++++++++----
+ 1 file changed, 18 insertions(+), 5 deletions(-)
+
+diff --git a/ssh-agent.c b/ssh-agent.c
+index 5fc73d69..1604f540 100644
+--- a/ssh-agent.c
++++ b/ssh-agent.c
+@@ -1795,12 +1795,22 @@
+               return;
+       }
+ 
+-      if (strcmp(name, "query") == 0)
+-              success = process_ext_query(e);
+-      else if (strcmp(name, "[email protected]") == 0)
++      /*
++       * This function can be called while the agent is locked to allow
++       * session binds to be processed for new channels.
++       * Other operations should be refused when locked.
++       */
++
++      if (strcmp(name, "[email protected]") == 0) {
+               success = process_ext_session_bind(e);
+-      else {
++      } else if (locked) {
++              debug_f("attempt to use extension \"%s\" while locked", name);
++              goto generic_fail;
++      } else if (strcmp(name, "query") == 0) {
++              success = process_ext_query(e);
++      } else {
+               debug_f("unsupported extension \"%s\"", name);
++ generic_fail:
+               free(name);
+               send_status(e, 0);
+               return;
+@@ -1857,14 +1867,17 @@
+       /* check whether agent is locked */
+       if (locked && type != SSH_AGENTC_UNLOCK) {
+-              sshbuf_reset(e->request);
+               switch (type) {
+               case SSH2_AGENTC_REQUEST_IDENTITIES:
+                       /* send empty lists */
+                       no_identities(e);
+                       break;
++              case SSH_AGENTC_EXTENSION:
++                      process_extension(e);
++                      break;
+               default:
+                       /* send a fail message for all other request types */
+                       send_status(e, 0);
+               }
++              sshbuf_reset(e->request);
+               return 1;
+       }
+-- 
+2.43.0
diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb 
b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
index 00e2cd8726e..0b34e4563ca 100644
--- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
@@ -33,6 +33,7 @@ SRC_URI = 
"https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta
            file://CVE-2026-60000.patch \
            file://CVE-2026-73283.patch \
            file://CVE-2026-73282.patch \
+           file://CVE-2026-73281.patch \
            "
 SRC_URI[sha256sum] = 
"56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4"
 
-- 
2.35.6

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246802): 
https://lists.openembedded.org/g/openembedded-core/message/246802
Mute This Topic: https://lists.openembedded.org/mt/121485165/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to