Hi Martin, On Sat, Aug 01, 2026 at 02:06:47PM +0200, Martin Pitt wrote: > Control: tag -1 pending > > Hello Salvatore! > > Salvatore Bonaccorso [2026-07-21 14:38 +0200]: > > Source: libssh > > Version: 0.12.0-3 > > Severity: grave > > Tags: security upstream > > Justification: user security hole > > Sorry for the delay! Life.. But the fixes have been in unstable for about a > week, and in testing since yesterday, and I got no complaints. autopkgtests > were happy as well. > > > CVE-2026-59842[1]: > > | A flaw was found in libssh. During server-side GSSAPI key exchange, > > | a client-supplied Curve25519 public key shorter than the expected > > | length is copied without proper length validation, leading to an > > | out-of-bounds heap read. This could allow a remote unauthenticated > > | attacker to disclose small amounts of server memory. > > This does not apply to trixie and earlier. Fix is > https://git.libssh.org/projects/libssh.git/commit/?id=ed9109dfc64b92c250b7e8c4c2045dad30d433f8 > > and that code was introduced in the 0.12 series, i.e. not present in 0.11 and > earlier. > > > CVE-2026-59851[10]: > > | Authentication bypass via missing GSSAPI principal check > > Same story: > https://git.libssh.org/projects/libssh.git/commit/?id=a45d20b75278858a6f06364722e068b32f181197 > > kex-gss.cs does not exist in 0.11 and ealier. > > The others are fixed in 0.11.5. I packaged and tested it, ran autopkgtest, and > put it on > > https://people.debian.org/~mpitt/tmp/ > > Note that this includes (and the above dir still separately contains) the > previous 0.11.4 which was declined for -security and never accepted into > updates. > > debdiff to current trixie-security is at > https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1_0.11.5-0+deb13u1.debdiff
Thank you, please upload to security-master (needs to be built with -sa). Regards, Salvatore

