From: Devansh Patel <[email protected]> This patch applies the upstream OpenSSH 10.4p1 backport for CVE-2026-59999. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753 [2] https://www.cve.org/CVERecord?id=CVE-2026-59999 Signed-off-by: Devansh Patel <[email protected]> [YC: patch referenced at https://ubuntu.com/security/CVE-2026-59999] Signed-off-by: Yoann Congal <[email protected]> --- .../openssh/openssh/CVE-2026-59999.patch | 38 +++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 39 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch new file mode 100644 index 00000000000..5907a991b9a --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch @@ -0,0 +1,38 @@ +From a83dd105dc407d95c42140ea6f04a1e247aaf2f9 Mon Sep 17 00:00:00 2001 +From: "[email protected]" <[email protected]> +Date: Sun, 31 May 2026 04:47:29 +0000 +Subject: [PATCH] upstream: DisableForwarding=yes didn't override + PermitTunnel=yes + +Reported independently by Huzaifa Sidhpurwala of Redhat and Marko +Jevtic; ok markus@ + +OpenBSD-Commit-ID: b5c13f0746cf079b21f8deba47407fad49ccbf4c + +CVE: CVE-2026-59999 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk in serverloop.c and + retained the Wrynose OpenSSH 10.3p1 revision because this stable + backport carries only the functional security change. + +(cherry picked from commit 8dfe7ed6e2fd988de08df508355a196b956b2753) +Signed-off-by: Devansh Patel <[email protected]> +--- + serverloop.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/serverloop.c b/serverloop.c +index 8e63480ec..42c3ce9fe 100644 +--- a/serverloop.c ++++ b/serverloop.c +@@ -523,7 +523,7 @@ server_request_tun(struct ssh *ssh) + ssh_packet_send_debug(ssh, "Unsupported tunnel device mode."); + return NULL; + } +- if ((options.permit_tun & mode) == 0) { ++ if ((options.permit_tun & mode) == 0 || options.disable_forwarding) { + ssh_packet_send_debug(ssh, "Server has rejected tunnel device " + "forwarding"); + return NULL; diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index 8669d080b6e..53704a0cc7e 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -24,6 +24,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://run-ptest \ file://sshd_check_keys \ file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ + file://CVE-2026-59999.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4"
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#241729): https://lists.openembedded.org/g/openembedded-core/message/241729 Mute This Topic: https://lists.openembedded.org/mt/120397944/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
