From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-devel@lists.openembedded.org
Cc: xe-linux-external@cisco.com, Hetvi Thakar <hthakar@cisco.com>
Subject: [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
Date: Wed, 19 Aug 2026 04:10:42 -0700 [thread overview]
Message-ID: <20260819111047.44043-1-hthakar@cisco.com> (raw)
From: Hetvi Thakar <hthakar@cisco.com>
Backport five upstream libssh security fixes to the 0.10.6 recipe on
scarthgap:
- CVE-2026-59843
- CVE-2026-59844
- CVE-2026-59846
- CVE-2026-59848
- CVE-2026-59850
Carry these as focused backports instead of upgrading libssh because
newer releases include API and functional changes outside the security
scope.
CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
code or features absent from 0.10.6. NVD correction requests have been
submitted for these inaccurate affected-version entries; therefore, no
CVE_STATUS entries are added.
The individual commits retain the upstream fix provenance and advisory
references for each CVE.
Testing:
- Applied all five patches to libssh 0.10.6 in series order without
conflicts or fuzz.
- Package build completed successfully.
Hetvi Thakar (5):
libssh: Fix CVE-2026-59843
libssh: Fix CVE-2026-59844
libssh: Fix CVE-2026-59846
libssh: Fix CVE-2026-59848
libssh: Fix CVE-2026-59850
.../libssh/libssh/CVE-2026-59843.patch | 84 +++
.../libssh/libssh/CVE-2026-59844.patch | 52 ++
.../libssh/libssh/CVE-2026-59846.patch | 87 +++
.../libssh/CVE-2026-59848-regression.patch | 45 ++
.../libssh/libssh/CVE-2026-59848.patch | 684 ++++++++++++++++++
.../libssh/libssh/CVE-2026-59850.patch | 40 +
.../recipes-support/libssh/libssh_0.10.6.bb | 6 +
7 files changed, 998 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
--
2.35.6
next reply other threads:[~2026-08-19 11:10 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 11:10 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260819111047.44043-1-hthakar@cisco.com \
--to=hthakar@cisco.com \
--cc=openembedded-devel@lists.openembedded.org \
--cc=xe-linux-external@cisco.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.