Control: tag -1 pending

Hello Salvatore!

Salvatore Bonaccorso [2026-07-21 14:38 +0200]:
> Source: libssh
> Version: 0.12.0-3
> Severity: grave
> Tags: security upstream
> Justification: user security hole

Sorry for the delay! Life.. But the fixes have been in unstable for about a
week, and in testing since yesterday, and I got no complaints. autopkgtests
were happy as well.

> CVE-2026-59842[1]:
> | A flaw was found in libssh. During server-side GSSAPI key exchange,
> | a client-supplied Curve25519 public key shorter than the expected
> | length is copied without proper length validation, leading to an
> | out-of-bounds heap read. This could allow a remote unauthenticated
> | attacker to disclose small amounts of server memory.

This does not apply to trixie and earlier. Fix is
https://git.libssh.org/projects/libssh.git/commit/?id=ed9109dfc64b92c250b7e8c4c2045dad30d433f8

and that code was introduced in the 0.12 series, i.e. not present in 0.11 and
earlier.

> CVE-2026-59851[10]:
> | Authentication bypass via missing GSSAPI principal check

Same story:
https://git.libssh.org/projects/libssh.git/commit/?id=a45d20b75278858a6f06364722e068b32f181197

kex-gss.cs does not exist in 0.11 and ealier.

The others are fixed in 0.11.5. I packaged and tested it, ran autopkgtest, and
put it on

  https://people.debian.org/~mpitt/tmp/

Note that this includes (and the above dir still separately contains) the
previous 0.11.4 which was declined for -security and never accepted into
updates.

debdiff to current trixie-security is at
https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1_0.11.5-0+deb13u1.debdiff

Thanks!

Pitti

Attachment: signature.asc
Description: PGP signature

Reply via email to