Fix three CVEs in libssh2 1.11.1 by backporting upstream fixes:

- CVE-2026-66033: potential OOB read/write with AES-GCM in ssh2_cipher_crypt()
- CVE-2026-66034: potential OOB read in libssh2_publickey_list_fetch()
- CVE-2026-66035: potential heap overflow on ETM decrypt

Backport adaptations:
- CVE-2026-66034: upstream uses ssh2_err() which is not available in
  1.11.1, replaced with _libssh2_error().
- CVE-2026-66035: upstream uses SSH2_SAFEFREE() (not in 1.11.1),
  replaced with LIBSSH2_FREE() + NULL reset. Also upstream renames
  decrypt() to transport_decrypt(), retained original name.

libssh2 ptest results (qemux86-64):
  before: PASSED: 1 FAILED: 0 SKIPPED: 0
  after:  PASSED: 1 FAILED: 0 SKIPPED: 0

Jaipaul Cheernam (3):
  libssh2: fix CVE-2026-66033
  libssh2: fix CVE-2026-66034
  libssh2: fix CVE-2026-66035

 .../libssh2/libssh2/CVE-2026-66033.patch      | 45 +++++++++++++++
 .../libssh2/libssh2/CVE-2026-66034.patch      | 40 +++++++++++++
 .../libssh2/libssh2/CVE-2026-66035.patch      | 56 +++++++++++++++++++
 .../recipes-support/libssh2/libssh2_1.11.1.bb |  3 +
 4 files changed, 144 insertions(+)
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242622): 
https://lists.openembedded.org/g/openembedded-core/message/242622
Mute This Topic: https://lists.openembedded.org/mt/120574042/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to