From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
To: openembedded-core@lists.openembedded.org
Cc: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Subject: [scarthgap][PATCH v2 2/4] libssh2: fix CVE-2026-66033
Date: Tue, 4 Aug 2026 15:09:44 +0200 [thread overview]
Message-ID: <20260804130946.3539-3-jaipaul.cheernam@est.tech> (raw)
In-Reply-To: <20260804130946.3539-1-jaipaul.cheernam@est.tech>
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-66033
https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6
libssh2 ptest results (qemux86-64):
before: PASSED: 1 FAILED: 0 SKIPPED: 0
after: PASSED: 1 FAILED: 0 SKIPPED: 0
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../libssh2/libssh2/CVE-2026-66033.patch | 45 +++++++++++++++++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 1 +
2 files changed, 46 insertions(+)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
new file mode 100644
index 0000000000..bb046a6eae
--- /dev/null
+++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
@@ -0,0 +1,45 @@
+From d1b6996c3b31ce6b60d5a820ecc33880e61ef0ae Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Thu, 23 Jul 2026 10:32:04 +0200
+Subject: [PATCH] openssl: fix potential OOB read/write with AES-GCM in
+ `ssh2_cipher_crypt()`
+
+By applying two bounds checks to non-debug builds.
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-c4f7-cvfc-33j7
+Follow-up to 3c953c05d67eb1ebcfd3316f279f12c4b1d600b4 #797
+
+Closes #2401
+
+CVE: CVE-2026-66033
+Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/openssl.c | 10 ++++++----
+ 1 file changed, 6 insertions(+), 4 deletions(-)
+
+diff --git a/src/openssl.c b/src/openssl.c
+index eba05031..28ae1cc0 100644
+--- a/src/openssl.c
++++ b/src/openssl.c
+@@ -1042,13 +1042,15 @@ _libssh2_cipher_crypt(_libssh2_cipher_ctx * ctx,
+ const int aadlen = (is_aesgcm && IS_FIRST(firstlast)) ? 4 : 0;
+ /* size of AT, if present */
+ const int authenticationtag = IS_LAST(firstlast) ? authlen : 0;
+- /* length to encrypt */
+- const int cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
++ unsigned int cryptlen; /* length to encrypt */
+
+ (void)algo;
+
+- assert(blocksize <= sizeof(buf));
+- assert(cryptlen >= 0);
++ if(blocksize > sizeof(buf) ||
++ blocksize < (size_t)(aadlen + authenticationtag))
++ return 1;
++
++ cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
+
+ #if LIBSSH2_AES_GCM
+ /* First block */
diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
index 32cb3898dd..a87c013017 100644
--- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb
+++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
@@ -14,6 +14,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
file://CVE-2026-55200.patch \
file://CVE-2026-55199.patch \
file://CVE-2026-66032.patch \
+ file://CVE-2026-66033.patch \
"
SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"
next prev parent reply other threads:[~2026-08-04 13:10 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 12:22 [scarthgap][PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
2026-08-04 12:22 ` [scarthgap][PATCH 1/3] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
2026-08-04 12:22 ` [scarthgap][PATCH 2/3] libssh2: fix CVE-2026-66034 Jaipaul Cheernam
2026-08-04 12:22 ` [scarthgap][PATCH 3/3] libssh2: fix CVE-2026-66035 Jaipaul Cheernam
2026-08-04 13:09 ` [scarthgap][PATCH v2 0/4] libssh2: fix CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
2026-08-04 13:09 ` [scarthgap][PATCH v2 1/4] libssh2: fix CVE-2026-66032 Jaipaul Cheernam
2026-08-04 13:09 ` Jaipaul Cheernam [this message]
2026-08-04 13:09 ` [scarthgap][PATCH v2 3/4] libssh2: fix CVE-2026-66034 Jaipaul Cheernam
2026-08-04 13:09 ` [scarthgap][PATCH v2 4/4] libssh2: fix CVE-2026-66035 Jaipaul Cheernam
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804130946.3539-3-jaipaul.cheernam@est.tech \
--to=jaipaul.cheernam@est.tech \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.