From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-devel@lists.openembedded.org
Subject: Re: [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
Date: Tue, 01 Sep 2026 01:23:55 -0700 [thread overview]
Message-ID: <2992798.1788251035800302150@lists.openembedded.org> (raw)
In-Reply-To: <CA+s=J=wUKLeAd2UNi-krDvXyyQG73H_XXcm9oLU4D1jQeTwf8Q@mail.gmail.com>
[-- Attachment #1: Type: text/plain, Size: 1811 bytes --]
On Tue, Sep 1, 2026 at 07:07 AM, Anuj Mittal wrote:
>
> On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
> PRIVATE LIMITED at Cisco) via lists.openembedded.org
> <hthakar=cisco.com@lists.openembedded.org> wrote:
>
>> From: Hetvi Thakar <hthakar@cisco.com>
>>
>> Backport five upstream libssh security fixes to the 0.10.6 recipe on
>> scarthgap:
>>
>> - CVE-2026-59843
>> - CVE-2026-59844
>> - CVE-2026-59846
>> - CVE-2026-59848
>> - CVE-2026-59850
>>
>> Carry these as focused backports instead of upgrading libssh because
>> newer releases include API and functional changes outside the security
>> scope.
>>
>> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
>> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
>> code or features absent from 0.10.6. NVD correction requests have been
>> submitted for these inaccurate affected-version entries; therefore, no
>> CVE_STATUS entries are added.
>>
>> The individual commits retain the upstream fix provenance and advisory
>> references for each CVE.
>>
>> Testing:
>> - Applied all five patches to libssh 0.10.6 in series order without
>> conflicts or fuzz.
>> - Package build completed successfully.
>>
>> Hetvi Thakar (5):
>> libssh: Fix CVE-2026-59843
>> libssh: Fix CVE-2026-59844
>> libssh: Fix CVE-2026-59846
>> libssh: Fix CVE-2026-59848
>> libssh: Fix CVE-2026-59850
>
> 3/5 is adding unresolved merge markers to recipe that 4/5 is then
> removing. Please fix the patches, rebase them on current scarthgap and
> resend.
>
> Thanks,
>
> Anuj
Hi,
Thanks for pointing this out.
I will fix the unresolved merge markers, rebase the patch series on
the current scarthgap branch, and resend the updated series.
Regards,
Hetvi
[-- Attachment #2: Type: text/html, Size: 2109 bytes --]
prev parent reply other threads:[~2026-09-01 8:24 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2992798.1788251035800302150@lists.openembedded.org \
--to=hthakar@cisco.com \
--cc=openembedded-devel@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.