All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-devel@lists.openembedded.org
Cc: xe-linux-external@cisco.com, Hetvi Thakar <hthakar@cisco.com>
Subject: [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844
Date: Wed, 19 Aug 2026 04:10:44 -0700	[thread overview]
Message-ID: <20260819111047.44043-3-hthakar@cisco.com> (raw)
In-Reply-To: <20260819111047.44043-1-hthakar@cisco.com>

From: Hetvi Thakar <hthakar@cisco.com>

The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59844 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.

[1] https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9
[2] https://www.libssh.org/security/advisories/CVE-2026-59844.txt

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
 .../libssh/libssh/CVE-2026-59844.patch        | 52 +++++++++++++++++++
 .../recipes-support/libssh/libssh_0.10.6.bb   |  1 +
 2 files changed, 53 insertions(+)
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch

diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
new file mode 100644
index 0000000000..ac380622d9
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
@@ -0,0 +1,52 @@
+From ef7cd6d4aef6d18ca8bf15cb0398b630284f46f4 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Fri, 6 Mar 2026 18:05:29 +0100
+Subject: [PATCH] CVE-2026-59844 sftpserver: cap accepted values of len in
+ SSH_FXP_READ
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The client-provided length is directly used in
+a malloc in process_read(), so not restricting it
+leads to allocations bounded only by UINT32_MAX.
+
+The new cap is the same as the one currently used
+by OpenSSH.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59844
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9]
+
+Backport Changes:
+- Replace the upstream goto error path with equivalent direct message cleanup
+  and return because libssh 0.10.6 does not have the refactored
+  sftp_make_client_message() error label.
+
+(cherry picked from commit 6dba2e06f0713c04ad5eca7d4315d0104be7e627)
+(cherry picked from commit e31f06e5380be4e714d5ad6965981fbf30738da9)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/sftpserver.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/sftpserver.c b/src/sftpserver.c
+index 528ef6f9..77290068 100644
+--- a/src/sftpserver.c
++++ b/src/sftpserver.c
+@@ -105,6 +105,13 @@ sftp_client_message sftp_get_client_message(sftp_session sftp) {
+         sftp_client_message_free(msg);
+         return NULL;
+       }
++      if (msg->len > MAX_PACKET_LEN - 1024) {
++        ssh_set_error(sftp->session, SSH_FATAL,
++                      "Too large SSH_FXP_READ length: %" PRIu32,
++                      msg->len);
++        sftp_client_message_free(msg);
++        return NULL;
++      }
+       break;
+     case SSH_FXP_WRITE:
+       rc = ssh_buffer_unpack(payload,
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 381b3efc7d..a9d7729f2c 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -33,6 +33,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
            file://CVE-2026-0967.patch \
            file://CVE-2026-0965.patch \
            file://CVE-2026-59843.patch \
+           file://CVE-2026-59844.patch \
           "
 SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
 
-- 
2.35.6



  parent reply	other threads:[~2026-08-19 11:11 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01  1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01  8:23   ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260819111047.44043-3-hthakar@cisco.com \
    --to=hthakar@cisco.com \
    --cc=openembedded-devel@lists.openembedded.org \
    --cc=xe-linux-external@cisco.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.