From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-devel@lists.openembedded.org
Cc: xe-linux-external@cisco.com, Hetvi Thakar <hthakar@cisco.com>
Subject: [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843
Date: Wed, 19 Aug 2026 04:10:43 -0700 [thread overview]
Message-ID: <20260819111047.44043-2-hthakar@cisco.com> (raw)
In-Reply-To: <20260819111047.44043-1-hthakar@cisco.com>
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59843 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919
[2] https://www.libssh.org/security/advisories/CVE-2026-59843.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59843.patch | 84 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 1 +
2 files changed, 85 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
new file mode 100644
index 0000000000..03d3ce6ea2
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
@@ -0,0 +1,84 @@
+From d965eb941a9a83a0643570a93d8997b91e248fc1 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Fri, 6 Mar 2026 13:58:30 +0100
+Subject: [PATCH] CVE-2026-59843 channels: Fail when receiving max packet size
+ 0
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Do this both for SSH2_MSG_CHANNEL_OPEN and for
+SSH2_MSG_CHANNEL_OPEN_CONFIRMATION. Using the
+max packet size 0 would lead to an infinite loop
+in channel_write_common.
+
+Originally reported by Rinku Das on on 23th February.
+Independently reported by Yi Lin on 26th February and
+Haruto Kimura on 22nd March.
+
+We do not consider this as a security issue as connecting
+to untrusted servers on the internet brings much worse
+security consequences than hanging your clinet.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59843
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919]
+
+(cherry picked from commit 44b186fa17aff497dae420c59c003222e438103c)
+(cherry picked from commit 687ef1c44b646b9db0b1c6e8f987edb7c9e4d919)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/channels.c | 7 +++++++
+ src/messages.c | 19 +++++++++++++++----
+ 2 files changed, 22 insertions(+), 4 deletions(-)
+
+diff --git a/src/channels.c b/src/channels.c
+index 8290dbd1..3afdcf11 100644
+--- a/src/channels.c
++++ b/src/channels.c
+@@ -192,6 +192,13 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open_conf){
+ if (rc != SSH_OK)
+ goto error;
+
++ if (channel->remote_maxpacket == 0) {
++ SSH_LOG(SSH_LOG_RARE,
++ "Invalid maximum packet size 0 in "
++ "SSH2_MSG_CHANNEL_OPEN_CONFIRMATION");
++ goto error;
++ }
++
+ SSH_LOG(SSH_LOG_PROTOCOL,
+ "Received a CHANNEL_OPEN_CONFIRMATION for channel %d:%d",
+ channel->local_channel,
+diff --git a/src/messages.c b/src/messages.c
+index 6dadabf0..e79ecec2 100644
+--- a/src/messages.c
++++ b/src/messages.c
+@@ -1160,10 +1160,21 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open){
+ SSH_LOG(SSH_LOG_PACKET,
+ "Clients wants to open a %s channel", type_c);
+
+- ssh_buffer_unpack(packet,"ddd",
+- &msg->channel_request_open.sender,
+- &msg->channel_request_open.window,
+- &msg->channel_request_open.packet_size);
++ rc = ssh_buffer_unpack(packet,
++ "ddd",
++ &msg->channel_request_open.sender,
++ &msg->channel_request_open.window,
++ &msg->channel_request_open.packet_size);
++ if (rc != SSH_OK){
++ goto error;
++ }
++
++ if (msg->channel_request_open.packet_size == 0) {
++ ssh_set_error(session,
++ SSH_FATAL,
++ "Invalid maximum packet size 0 in SSH2_MSG_CHANNEL_OPEN");
++ goto error;
++ }
+
+ if (session->session_state != SSH_SESSION_STATE_AUTHENTICATED){
+ ssh_set_error(session,SSH_FATAL, "Invalid state when receiving channel open request (must be authenticated)");
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 1f64920a50..381b3efc7d 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -32,6 +32,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0968-2.patch \
file://CVE-2026-0967.patch \
file://CVE-2026-0965.patch \
+ file://CVE-2026-59843.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
next prev parent reply other threads:[~2026-08-19 11:11 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260819111047.44043-2-hthakar@cisco.com \
--to=hthakar@cisco.com \
--cc=openembedded-devel@lists.openembedded.org \
--cc=xe-linux-external@cisco.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.