Control: tag -1 pending Hello Salvatore!
Salvatore Bonaccorso [2026-07-21 14:38 +0200]: > Source: libssh > Version: 0.12.0-3 > Severity: grave > Tags: security upstream > Justification: user security hole Sorry for the delay! Life.. But the fixes have been in unstable for about a week, and in testing since yesterday, and I got no complaints. autopkgtests were happy as well. > CVE-2026-59842[1]: > | A flaw was found in libssh. During server-side GSSAPI key exchange, > | a client-supplied Curve25519 public key shorter than the expected > | length is copied without proper length validation, leading to an > | out-of-bounds heap read. This could allow a remote unauthenticated > | attacker to disclose small amounts of server memory. This does not apply to trixie and earlier. Fix is https://git.libssh.org/projects/libssh.git/commit/?id=ed9109dfc64b92c250b7e8c4c2045dad30d433f8 and that code was introduced in the 0.12 series, i.e. not present in 0.11 and earlier. > CVE-2026-59851[10]: > | Authentication bypass via missing GSSAPI principal check Same story: https://git.libssh.org/projects/libssh.git/commit/?id=a45d20b75278858a6f06364722e068b32f181197 kex-gss.cs does not exist in 0.11 and ealier. The others are fixed in 0.11.5. I packaged and tested it, ran autopkgtest, and put it on https://people.debian.org/~mpitt/tmp/ Note that this includes (and the above dir still separately contains) the previous 0.11.4 which was declined for -security and never accepted into updates. debdiff to current trixie-security is at https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1_0.11.5-0+deb13u1.debdiff Thanks! Pitti
signature.asc
Description: PGP signature

