Your message dated Tue, 28 Jul 2026 15:19:04 +0000
with message-id <[email protected]>
and subject line Bug#1142856: fixed in libssh2 1.11.1-5
has caused the Debian Bug report #1142856,
regarding libssh2: CVE-2026-66032 CVE-2026-66033 CVE-2026-66034 CVE-2026-66035
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142856: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142856
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libssh
Version: 1.11.1-4
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for libssh.

CVE-2026-66032[0]:
| libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-
| free vulnerability in the sftp_open() function in src/sftp.c that
| allows a malicious SSH server to corrupt the heap of any
| authenticated client opening an SFTP session. When a server responds
| to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response
| data buffer is freed, and if a subsequent sftp_packet_require() call
| returns a specific error such as
| LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a
| second time, enabling tcache dup conditions on glibc systems that
| allow overlapping allocations and function pointer overwrites.


CVE-2026-66033[1]:
| libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-
| authentication integer underflow vulnerability in the
| ssh2_cipher_crypt() function in src/openssl.c that allows a
| malicious SSH server to crash any connecting client by negotiating
| AES-GCM ciphers during handshake. Attackers can exploit the
| underflow in the expression computing blocksize minus aadlen minus
| authentication tag length to trigger an out-of-bounds read and a
| memcpy call with a near-SIZE_MAX length argument, causing immediate
| process crash before any authentication occurs.


CVE-2026-66034[2]:
| libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing
| bounds check vulnerability that allows a malicious SSH server to
| trigger an arbitrary-length heap out-of-bounds read and a free of an
| uninitialized pointer via the publickey subsystem. In
| libssh2_publickey_list_fetch(), the version 1 response parser reads
| a server-controlled comment_len value and advances the parse pointer
| without verifying sufficient bytes remain in the buffer, causing the
| out-of-bounds read to leak heap pointers from adjacent allocations
| defeating ASLR, followed by heap allocator state corruption when the
| error cleanup path frees an uninitialized pointer from a non-zeroed
| realloc() region.


CVE-2026-66035[3]:
| libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-
| authentication heap buffer overflow vulnerability that allows a
| malicious SSH server to corrupt heap metadata in any connecting
| client by sending a packet with a packet_length smaller than the
| cipher's block size during Encrypt-then-MAC cipher negotiation. In
| the fullpacket() function in src/transport.c, the ETM path allocates
| a buffer of packet_length bytes but copies blocksize minus one bytes
| via memcpy, causing an overflow that on 32-bit glibc writes
| attacker-controlled bytes into an adjacent chunk's SIZE field,
| enabling tcache bin confusion, overlapping live objects, and
| function pointer overwrite during the session handshake before
| authentication.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66032
    https://www.cve.org/CVERecord?id=CVE-2026-66032
[1] https://security-tracker.debian.org/tracker/CVE-2026-66033
    https://www.cve.org/CVERecord?id=CVE-2026-66033
[2] https://security-tracker.debian.org/tracker/CVE-2026-66034
    https://www.cve.org/CVERecord?id=CVE-2026-66034
[3] https://security-tracker.debian.org/tracker/CVE-2026-66035
    https://www.cve.org/CVERecord?id=CVE-2026-66035

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libssh2
Source-Version: 1.11.1-5
Done: Nicolas Mora <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libssh2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Nicolas Mora <[email protected]> (supplier of updated libssh2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 27 Jul 2026 07:32:55 -0400
Source: libssh2
Architecture: source
Version: 1.11.1-5
Distribution: unstable
Urgency: medium
Maintainer: Nicolas Mora <[email protected]>
Changed-By: Nicolas Mora <[email protected]>
Closes: 1142856
Changes:
 libssh2 (1.11.1-5) unstable; urgency=medium
 .
   * d/patches: Fix CVEs CVE-2026-66032 CVE-2026-66033 CVE-2026-66034
     CVE-2026-66035 (Closes: #1142856)
   * d/control: Upgrade debhelper-compat version to 14
Checksums-Sha1:
 7a40a6992d3d44091f37d2c70fcf6fbfdec5acf8 2329 libssh2_1.11.1-5.dsc
 61c721696f08bf91d23dd59b766bac65e9a78b04 1093012 libssh2_1.11.1.orig.tar.gz
 d1d810ea2c4807fe71b0b66c784bd874ad5b9c67 488 libssh2_1.11.1.orig.tar.gz.asc
 a4bcef5bb5acaabc2578b94aad20385e22923e43 20688 libssh2_1.11.1-5.debian.tar.xz
 e8f039d06a11cc5b4521f65618fd9a5800b72989 6195 libssh2_1.11.1-5_amd64.buildinfo
Checksums-Sha256:
 15cbf3b1503c99397ac14333a7a3b69ac6c60f22745f86a358702022c303cab5 2329 
libssh2_1.11.1-5.dsc
 d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7 1093012 
libssh2_1.11.1.orig.tar.gz
 f5618c9356a1d5a8059d6cf64015d86547f06b2b8b1f542fbbaf381a736c8075 488 
libssh2_1.11.1.orig.tar.gz.asc
 953b3206b83c5c5fe4d6ad0da95743ba0e3fdb9de22d2ab11e5aabdb0701b81d 20688 
libssh2_1.11.1-5.debian.tar.xz
 391b35c55236370a6b119cb48980fc436014195c9857a7904ab00d90a12f80e4 6195 
libssh2_1.11.1-5_amd64.buildinfo
Files:
 7ff9112107c3c32a0fee3065ee877608 2329 libs optional libssh2_1.11.1-5.dsc
 38857d10b5c5deb198d6989dacace2e6 1093012 libs optional 
libssh2_1.11.1.orig.tar.gz
 5ecd37626fbb7ca0850a56a05a37a4c2 488 libs optional 
libssh2_1.11.1.orig.tar.gz.asc
 f5dacf8c9138fa76a97ab62a7d5c755c 20688 libs optional 
libssh2_1.11.1-5.debian.tar.xz
 1e5e2fd22cfde0171b2d57792ea0ea4b 6195 libs optional 
libssh2_1.11.1-5_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEhAWwL8wo75dEyPJT/oITlEC9IrkFAmpoweAACgkQ/oITlEC9
Irk9HA/9EfkDLNgdwgpHHBorGIXZ7Rhpv7JCg0PMgqk1lB8T3+c6iga2g2T1GQBg
kMRUJFczZNL5jx4yfzWTgcsQV+M0+YpbxUJlw0CjbstfQiVCfSO6eSWU1DxnCoSO
3+wMhotCWsPFfMLFxunSl5z/ISH1X5IpRL1GgCNEkn1AzQ2TLKFwfKVwq9S/kCvT
6kLcU5zbQCe4l6yWAez7SA3Rlkocr8qa/RW2nkITiIsYcF4tJEqIqT+tXUydvVed
RFdOdXS6cmizpysLwpLkZPWD6fQK/ioY4Ie6JGJyyftdRi09mGsswK61CHnTB2Al
kLPxKDVpprQK0kEzH21tmm3JovyDzD+lakRsTBjRj0WyV49b3dfIcp+78VgdUtzG
hgzoz5twz8GS7D/T8h2sh72wkn5EmUdZ/SUifiHusyEmGCtnRSU2bAbcc0zCINY/
HfST7UyPmgbRVgJWZMw8oXtZoRTPWHHm+2QVYa8duzRxJCCDqTLZafz0Okf4ISDG
XopMvhXlDEyNORsnO1ECSbowZBiiStn2I2uIoM3yBpzHeSo7NrWa5tW6nzO9/Bsq
8RidJ3tz8UjtyAVH3qqsFGVoxSuhdqeQSGxrbvTr2E6W3sGbQtCrs5i5jyyQBN83
ETFgykZDuPPMOlhN0Y5TxeTnt9uRCoCy0wrUkui+CMC9XXwpwY4=
=2HN+
-----END PGP SIGNATURE-----

Attachment: pgpI13tmCRDD3.pgp
Description: PGP signature


--- End Message ---

Reply via email to