From: Devansh Patel <[email protected]>

This patch applies the upstream OpenSSH 10.4p1 backport for
CVE-2026-60000. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] 
https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192
[2] https://www.cve.org/CVERecord?id=CVE-2026-60000

Signed-off-by: Devansh Patel <[email protected]>
[YC: Patch referenced in https://ubuntu.com/security/CVE-2026-60000]
Signed-off-by: Yoann Congal <[email protected]>
---
 .../openssh/openssh/CVE-2026-60000.patch      | 140 ++++++++++++++++++
 .../openssh/openssh_10.3p1.bb                 |   1 +
 2 files changed, 141 insertions(+)
 create mode 100644 
meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch 
b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
new file mode 100644
index 00000000000..e9b62e64545
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
@@ -0,0 +1,140 @@
+From 884e94fafb20259c78bf394611b9929a7683e2b3 Mon Sep 17 00:00:00 2001
+From: "[email protected]" <[email protected]>
+Date: Mon, 6 Jul 2026 07:53:30 +0000
+Subject: [PATCH] upstream: Fix multiple RFC 4462 (GSSAPIAuthentication)
+ compliance
+
+problems
+
+1) Remove an early failure return for GSSAPI authentication attempts
+made for invalid accounts that yielded different behaviour for
+valid vs invalid accounts.
+
+2) Fix a situation where some GSSAPI requestes were not correctly
+subjected to MaxAuthTries.
+
+3) Fix a moderate pre-authentication resource DoS related to #2.
+
+Add missing logging for error cases.
+
+Report and fixes from Manfred Kaiser, milCERT AT
+
+OpenBSD-Commit-ID: ca0acdd64eea435d6f89534538a9eb404a5629d3
+
+CVE: CVE-2026-60000
+Upstream-Status: Backport 
[https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192]
+
+Backport Changes:
+- Omitted the upstream OpenBSD revision-only hunk in auth2-gss.c and
+  retained the Wrynose OpenSSH 10.3p1 revision because this stable
+  backport carries only the functional security change.
+
+(cherry picked from commit 5d04ca6af739b82fd30d84d2783ca802ebfa1192)
+Signed-off-by: Devansh Patel <[email protected]>
+---
+ auth2-gss.c | 53 ++++++++++++++++++++++++-----------------------------
+ 1 file changed, 24 insertions(+), 29 deletions(-)
+
+diff --git a/auth2-gss.c b/auth2-gss.c
+index f27ac9221..54c96fe4b 100644
+--- a/auth2-gss.c
++++ b/auth2-gss.c
+@@ -111,12 +111,6 @@ userauth_gssapi(struct ssh *ssh, const char *method)
+               return (0);
+       }
+ 
+-      if (!authctxt->valid || authctxt->user == NULL) {
+-              debug2_f("disabled because of invalid user");
+-              free(doid);
+-              return (0);
+-      }
+-
+       if (GSS_ERROR(mm_ssh_gssapi_server_ctx(&ctxt, &goid))) {
+               if (ctxt != NULL)
+                       ssh_gssapi_delete_ctx(&ctxt);
+@@ -178,8 +172,14 @@ input_gssapi_token(int type, uint32_t plen, struct ssh 
*ssh)
+                           (r = sshpkt_send(ssh)) != 0)
+                               fatal_fr(r, "send ERRTOK packet");
+               }
++              logit("Failed gssapi-with-mic for %s%.100s "
++                  "from %.200s port %d ssh2",
++                  authctxt->valid ? "" : "invalid user ",
++                  authctxt->user,
++                  ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
+               authctxt->postponed = 0;
+               ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
++              ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
+               userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
+       } else {
+               if (send_tok.length != 0) {
+@@ -191,14 +191,18 @@ input_gssapi_token(int type, uint32_t plen, struct ssh 
*ssh)
+                               fatal_fr(r, "send TOKEN packet");
+               }
+               if (maj_status == GSS_S_COMPLETE) {
+-                      ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, 
NULL);
+-                      if (flags & GSS_C_INTEG_FLAG)
+-                              ssh_dispatch_set(ssh, 
SSH2_MSG_USERAUTH_GSSAPI_MIC,
++                      ssh_dispatch_set(ssh,
++                          SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
++                      /* note: keep ERRTOK handler as per RFC 4462 s3.4 */
++                      if (flags & GSS_C_INTEG_FLAG) {
++                              ssh_dispatch_set(ssh,
++                                  SSH2_MSG_USERAUTH_GSSAPI_MIC,
+                                   &input_gssapi_mic);
+-                      else
++                      } else {
+                               ssh_dispatch_set(ssh,
+                                   SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE,
+                                   &input_gssapi_exchange_complete);
++                      }
+               }
+       }
+ 
+@@ -210,10 +214,6 @@ static int
+ input_gssapi_errtok(int type, uint32_t plen, struct ssh *ssh)
+ {
+       Authctxt *authctxt = ssh->authctxt;
+-      Gssctxt *gssctxt;
+-      gss_buffer_desc send_tok = GSS_C_EMPTY_BUFFER;
+-      gss_buffer_desc recv_tok;
+-      OM_uint32 maj_status;
+       int r;
+       u_char *p;
+       size_t len;
+@@ -221,26 +221,21 @@ input_gssapi_errtok(int type, uint32_t plen, struct ssh 
*ssh)
+       if (authctxt == NULL)
+               fatal("No authentication or GSSAPI context");
+ 
+-      gssctxt = authctxt->methoddata;
+-      if ((r = sshpkt_get_string(ssh, &p, &len)) != 0 ||
++      /* Minimal error handling - just cancel auth and return FAILURE */
++      if ((r = sshpkt_get_string_direct(ssh, NULL, NULL)) != 0 ||
+           (r = sshpkt_get_end(ssh)) != 0)
+               fatal_fr(r, "parse packet");
+-      recv_tok.value = p;
+-      recv_tok.length = len;
+-
+-      /* Push the error token into GSSAPI to see what it says */
+-      maj_status = mm_ssh_gssapi_accept_ctx(gssctxt, &recv_tok,
+-          &send_tok, NULL);
+-
+-      free(recv_tok.value);
+ 
+-      /* We can't return anything to the client, even if we wanted to */
++      logit("Failed gssapi-with-mic for %s%.100s from %.200s port %d ssh2",
++          authctxt->valid ? "" : "invalid user ",
++          authctxt->user,
++          ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
++      authctxt->postponed = 0;
+       ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
+       ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
+-
+-      /* The client will have already moved on to the next auth */
+-
+-      gss_release_buffer(&maj_status, &send_tok);
++      ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, NULL);
++      ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, NULL);
++      userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
+       return 0;
+ }
+ 
diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb 
b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
index 8edb1440fe0..f5184b1fce3 100644
--- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
@@ -30,6 +30,7 @@ SRC_URI = 
"https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta
            file://CVE-2026-59995.patch \
            file://CVE-2026-60001.patch \
            file://CVE-2026-60002.patch \
+           file://CVE-2026-60000.patch \
            "
 SRC_URI[sha256sum] = 
"56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4"
 
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241736): 
https://lists.openembedded.org/g/openembedded-core/message/241736
Mute This Topic: https://lists.openembedded.org/mt/120397953/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to