From: Hetvi Thakar <[email protected]> This patch applies the upstream fix that tracks pending remote-forward requests by index instead of retaining a pointer that realloc may invalidate. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299 [2] https://www.cve.org/CVERecord?id=CVE-2026-73282 Signed-off-by: Hetvi Thakar <[email protected]> --- .../openssh/openssh/CVE-2026-73282.patch | 80 +++++++++++++++++++ .../openssh/openssh_9.6p1.bb | 1 + 2 files changed, 81 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch new file mode 100644 index 0000000000..a527cca762 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch @@ -0,0 +1,80 @@ +From 9910d5ef53124ce1157d57bc11e222658aa41299 Mon Sep 17 00:00:00 2001 +From: [email protected] <[email protected]> +Date: Fri, 7 Aug 2026 05:03:56 +0000 +Subject: [PATCH] upstream: avoid potential realloc use-after-free in the + client if a + +remote forwarding is added via the local session multiplexing socket while a +remote forwarding open request is pending with the server. + +Report and fix from Brian Mingus of Cognatory + +OpenBSD-Commit-ID: c7888d566576386d0e96859f9ec7310a1e2d3609 + +CVE: CVE-2026-73282 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299] + +Backport Changes: +- Omitted the upstream OpenBSD RCS revision header update because it does + not apply to the OpenSSH 9.6p1 source revision. + +(cherry picked from commit 9910d5ef53124ce1157d57bc11e222658aa41299) +Signed-off-by: Hetvi Thakar <[email protected]> +--- + ssh.c | 19 +++++++++++++++++--- + 1 file changed, 16 insertions(+), 3 deletions(-) + +diff --git a/ssh.c b/ssh.c +index aecdb79e..2d2837d4 100644 +--- a/ssh.c ++++ b/ssh.c +@@ -1867,14 +1867,24 @@ forwarding_success(void) + } + } + ++struct rfwd_confirm_ctx { ++ int fid; ++}; ++ + /* Callback for remote forward global requests */ + static void + ssh_confirm_remote_forward(struct ssh *ssh, int type, u_int32_t seq, void *ctxt) + { +- struct Forward *rfwd = (struct Forward *)ctxt; ++ struct rfwd_confirm_ctx *rctx = (struct rfwd_confirm_ctx *)ctxt; ++ struct Forward *rfwd; + u_int port; + int r; + ++ if (rctx->fid < 0 || rctx->fid >= options.num_remote_forwards) ++ fatal_f("invalid forwarding ID %d", rctx->fid); ++ rfwd = &options.remote_forwards[rctx->fid]; ++ freezero(rctx, sizeof(*rctx)); ++ + /* XXX verbose() on failure? */ + debug("remote forward %s for: listen %s%s%d, connect %s:%d", + type == SSH2_MSG_REQUEST_SUCCESS ? "success" : "failure", +@@ -2052,6 +2062,8 @@ ssh_init_forwarding(struct ssh *ssh, char **ifname) + + /* Initiate remote TCP/IP port forwardings. */ + for (i = 0; i < options.num_remote_forwards; i++) { ++ struct rfwd_confirm_ctx *rctx; ++ + debug("Remote connections from %.200s:%d forwarded to " + "local address %.200s:%d", + (options.remote_forwards[i].listen_path != NULL) ? +@@ -2066,9 +2078,10 @@ ssh_init_forwarding(struct ssh *ssh, char **ifname) + if ((options.remote_forwards[i].handle = + channel_request_remote_forwarding(ssh, + &options.remote_forwards[i])) >= 0) { ++ rctx = xcalloc(1, sizeof(*rctx)); ++ rctx->fid = i; + client_register_global_confirm( +- ssh_confirm_remote_forward, +- &options.remote_forwards[i]); ++ ssh_confirm_remote_forward, rctx); + forward_confirms_pending++; + } else if (options.exit_on_forward_failure) + fatal("Could not request remote forwarding."); +-- +2.43.0 diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index f660e78dba..651b7437a6 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -45,6 +45,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar file://CVE-2026-60002.patch \ file://CVE-2026-60000.patch \ file://CVE-2026-73283.patch \ + file://CVE-2026-73282.patch \ " SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" -- 2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246915): https://lists.openembedded.org/g/openembedded-core/message/246915 Mute This Topic: https://lists.openembedded.org/mt/121504069/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
