From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
To: openembedded-core@lists.openembedded.org
Cc: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Subject: [scarthgap][PATCH v2 4/4] libssh2: fix CVE-2026-66035
Date: Tue, 4 Aug 2026 15:09:46 +0200 [thread overview]
Message-ID: <20260804130946.3539-5-jaipaul.cheernam@est.tech> (raw)
In-Reply-To: <20260804130946.3539-1-jaipaul.cheernam@est.tech>
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-66035
https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
libssh2 ptest results (qemux86-64):
before: PASSED: 1 FAILED: 0 SKIPPED: 0
after: PASSED: 1 FAILED: 0 SKIPPED: 0
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../libssh2/libssh2/CVE-2026-66035.patch | 56 +++++++++++++++++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 1 +
2 files changed, 57 insertions(+)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch
diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch
new file mode 100644
index 0000000000..7c15f92fb6
--- /dev/null
+++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch
@@ -0,0 +1,56 @@
+From 6671019836476649792eea12868a370133be1abe Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Fri, 3 Jul 2026 18:22:55 +0200
+Subject: [PATCH] transport: fix potential heap overflow on ETM decrypt
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-6c79-444r-wx26
+
+Closes #2198
+
+Backport adaptations:
+- The upstream fix uses SSH2_SAFEFREE() to safely release allocated
+ memory and reset the pointer. Since SSH2_SAFEFREE() is not available
+ in libssh2 1.11.1, replace its usage with the equivalent NULL check,
+ LIBSSH2_FREE(), and pointer reset sequence.
+- The upstream fix renames decrypt() to transport_decrypt(). Since this
+ rename is not present in libssh2 1.11.1, retain the original
+ decrypt() function name.
+
+CVE: CVE-2026-66035
+Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/transport.c | 12 +++++++++++-
+ 1 file changed, 11 insertions(+), 1 deletion(-)
+
+diff --git a/src/transport.c b/src/transport.c
+index d147505b..9f386e75 100644
+--- a/src/transport.c
++++ b/src/transport.c
+@@ -242,6 +242,17 @@ fullpacket(LIBSSH2_SESSION * session, int encrypted /* 1 or 0 */ )
+ unsigned char *decrypt_buffer;
+ int blocksize = session->remote.crypt->blocksize;
+
++ if(p->total_num < mac_len + 4 + (size_t)blocksize) {
++ if(p->payload) {
++ LIBSSH2_FREE(session, p->payload);
++ p->payload = NULL;
++ }
++ return LIBSSH2_ERROR_DECRYPT;
++ }
++ decrypt_size = (ssize_t)(p->total_num - mac_len - 4);
++
++ first_block[0] = 0;
++
+ rc = decrypt(session, p->payload + 4,
+ first_block, blocksize, FIRST_BLOCK);
+ if(rc) {
+@@ -249,7 +260,6 @@ fullpacket(LIBSSH2_SESSION * session, int encrypted /* 1 or 0 */ )
+ }
+
+ /* we need buffer for decrypt */
+- decrypt_size = p->total_num - mac_len - 4;
+ decrypt_buffer = LIBSSH2_ALLOC(session, decrypt_size);
+ if(!decrypt_buffer) {
+ return LIBSSH2_ERROR_ALLOC;
diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
index 999c3db55a..5a0e6904b3 100644
--- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb
+++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
@@ -16,6 +16,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
file://CVE-2026-66032.patch \
file://CVE-2026-66033.patch \
file://CVE-2026-66034.patch \
+ file://CVE-2026-66035.patch \
"
SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"
prev parent reply other threads:[~2026-08-04 13:10 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 12:22 [scarthgap][PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
2026-08-04 12:22 ` [scarthgap][PATCH 1/3] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
2026-08-04 12:22 ` [scarthgap][PATCH 2/3] libssh2: fix CVE-2026-66034 Jaipaul Cheernam
2026-08-04 12:22 ` [scarthgap][PATCH 3/3] libssh2: fix CVE-2026-66035 Jaipaul Cheernam
2026-08-04 13:09 ` [scarthgap][PATCH v2 0/4] libssh2: fix CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
2026-08-04 13:09 ` [scarthgap][PATCH v2 1/4] libssh2: fix CVE-2026-66032 Jaipaul Cheernam
2026-08-04 13:09 ` [scarthgap][PATCH v2 2/4] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
2026-08-04 13:09 ` [scarthgap][PATCH v2 3/4] libssh2: fix CVE-2026-66034 Jaipaul Cheernam
2026-08-04 13:09 ` Jaipaul Cheernam [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804130946.3539-5-jaipaul.cheernam@est.tech \
--to=jaipaul.cheernam@est.tech \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.