From: Hetvi Thakar <[email protected]>

This patch applies the upstream fix that tracks pending remote-forward
requests by index instead of retaining a pointer that realloc may
invalidate. The upstream fix commit is referenced in [1], and the
public CVE advisory is referenced in [2].

[1] 
https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299
[2] https://www.cve.org/CVERecord?id=CVE-2026-73282

Signed-off-by: Hetvi Thakar <[email protected]>
---
 .../openssh/openssh/CVE-2026-73282.patch      | 80 +++++++++++++++++++
 .../openssh/openssh_9.6p1.bb                  |  1 +
 2 files changed, 81 insertions(+)
 create mode 100644 
meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch 
b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch
new file mode 100644
index 0000000000..a527cca762
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch
@@ -0,0 +1,80 @@
+From 9910d5ef53124ce1157d57bc11e222658aa41299 Mon Sep 17 00:00:00 2001
+From: [email protected] <[email protected]>
+Date: Fri, 7 Aug 2026 05:03:56 +0000
+Subject: [PATCH] upstream: avoid potential realloc use-after-free in the
+ client if a
+
+remote forwarding is added via the local session multiplexing socket while a
+remote forwarding open request is pending with the server.
+
+Report and fix from Brian Mingus of Cognatory
+
+OpenBSD-Commit-ID: c7888d566576386d0e96859f9ec7310a1e2d3609
+
+CVE: CVE-2026-73282
+Upstream-Status: Backport 
[https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299]
+
+Backport Changes:
+- Omitted the upstream OpenBSD RCS revision header update because it does
+  not apply to the OpenSSH 9.6p1 source revision.
+
+(cherry picked from commit 9910d5ef53124ce1157d57bc11e222658aa41299)
+Signed-off-by: Hetvi Thakar <[email protected]>
+---
+ ssh.c | 19 +++++++++++++++++---
+ 1 file changed, 16 insertions(+), 3 deletions(-)
+
+diff --git a/ssh.c b/ssh.c
+index aecdb79e..2d2837d4 100644
+--- a/ssh.c
++++ b/ssh.c
+@@ -1867,14 +1867,24 @@ forwarding_success(void)
+       }
+ }
+ 
++struct rfwd_confirm_ctx {
++      int fid;
++};
++
+ /* Callback for remote forward global requests */
+ static void
+ ssh_confirm_remote_forward(struct ssh *ssh, int type, u_int32_t seq, void 
*ctxt)
+ {
+-      struct Forward *rfwd = (struct Forward *)ctxt;
++      struct rfwd_confirm_ctx *rctx = (struct rfwd_confirm_ctx *)ctxt;
++      struct Forward *rfwd;
+       u_int port;
+       int r;
+ 
++      if (rctx->fid < 0 || rctx->fid >= options.num_remote_forwards)
++              fatal_f("invalid forwarding ID %d", rctx->fid);
++      rfwd = &options.remote_forwards[rctx->fid];
++      freezero(rctx, sizeof(*rctx));
++
+       /* XXX verbose() on failure? */
+       debug("remote forward %s for: listen %s%s%d, connect %s:%d",
+           type == SSH2_MSG_REQUEST_SUCCESS ? "success" : "failure",
+@@ -2052,6 +2062,8 @@ ssh_init_forwarding(struct ssh *ssh, char **ifname)
+ 
+       /* Initiate remote TCP/IP port forwardings. */
+       for (i = 0; i < options.num_remote_forwards; i++) {
++              struct rfwd_confirm_ctx *rctx;
++
+               debug("Remote connections from %.200s:%d forwarded to "
+                   "local address %.200s:%d",
+                   (options.remote_forwards[i].listen_path != NULL) ?
+@@ -2066,9 +2078,10 @@ ssh_init_forwarding(struct ssh *ssh, char **ifname)
+               if ((options.remote_forwards[i].handle =
+                   channel_request_remote_forwarding(ssh,
+                   &options.remote_forwards[i])) >= 0) {
++                      rctx = xcalloc(1, sizeof(*rctx));
++                      rctx->fid = i;
+                       client_register_global_confirm(
+-                          ssh_confirm_remote_forward,
+-                          &options.remote_forwards[i]);
++                          ssh_confirm_remote_forward, rctx);
+                       forward_confirms_pending++;
+               } else if (options.exit_on_forward_failure)
+                       fatal("Could not request remote forwarding.");
+-- 
+2.43.0
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb 
b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index f660e78dba..651b7437a6 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -45,6 +45,7 @@ SRC_URI = 
"http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
            file://CVE-2026-60002.patch \
            file://CVE-2026-60000.patch \
            file://CVE-2026-73283.patch \
+           file://CVE-2026-73282.patch \
            "
 SRC_URI[sha256sum] = 
"910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
 
-- 
2.35.6

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246915): 
https://lists.openembedded.org/g/openembedded-core/message/246915
Mute This Topic: https://lists.openembedded.org/mt/121504069/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to