* [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
@ 2026-08-19 11:10 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (5 more replies)
0 siblings, 6 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
Backport five upstream libssh security fixes to the 0.10.6 recipe on
scarthgap:
- CVE-2026-59843
- CVE-2026-59844
- CVE-2026-59846
- CVE-2026-59848
- CVE-2026-59850
Carry these as focused backports instead of upgrading libssh because
newer releases include API and functional changes outside the security
scope.
CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
code or features absent from 0.10.6. NVD correction requests have been
submitted for these inaccurate affected-version entries; therefore, no
CVE_STATUS entries are added.
The individual commits retain the upstream fix provenance and advisory
references for each CVE.
Testing:
- Applied all five patches to libssh 0.10.6 in series order without
conflicts or fuzz.
- Package build completed successfully.
Hetvi Thakar (5):
libssh: Fix CVE-2026-59843
libssh: Fix CVE-2026-59844
libssh: Fix CVE-2026-59846
libssh: Fix CVE-2026-59848
libssh: Fix CVE-2026-59850
.../libssh/libssh/CVE-2026-59843.patch | 84 +++
.../libssh/libssh/CVE-2026-59844.patch | 52 ++
.../libssh/libssh/CVE-2026-59846.patch | 87 +++
.../libssh/CVE-2026-59848-regression.patch | 45 ++
.../libssh/libssh/CVE-2026-59848.patch | 684 ++++++++++++++++++
.../libssh/libssh/CVE-2026-59850.patch | 40 +
.../recipes-support/libssh/libssh_0.10.6.bb | 6 +
7 files changed, 998 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
--
2.35.6
^ permalink raw reply [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (4 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59843 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919
[2] https://www.libssh.org/security/advisories/CVE-2026-59843.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59843.patch | 84 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 1 +
2 files changed, 85 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
new file mode 100644
index 0000000000..03d3ce6ea2
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
@@ -0,0 +1,84 @@
+From d965eb941a9a83a0643570a93d8997b91e248fc1 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Fri, 6 Mar 2026 13:58:30 +0100
+Subject: [PATCH] CVE-2026-59843 channels: Fail when receiving max packet size
+ 0
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Do this both for SSH2_MSG_CHANNEL_OPEN and for
+SSH2_MSG_CHANNEL_OPEN_CONFIRMATION. Using the
+max packet size 0 would lead to an infinite loop
+in channel_write_common.
+
+Originally reported by Rinku Das on on 23th February.
+Independently reported by Yi Lin on 26th February and
+Haruto Kimura on 22nd March.
+
+We do not consider this as a security issue as connecting
+to untrusted servers on the internet brings much worse
+security consequences than hanging your clinet.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59843
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919]
+
+(cherry picked from commit 44b186fa17aff497dae420c59c003222e438103c)
+(cherry picked from commit 687ef1c44b646b9db0b1c6e8f987edb7c9e4d919)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/channels.c | 7 +++++++
+ src/messages.c | 19 +++++++++++++++----
+ 2 files changed, 22 insertions(+), 4 deletions(-)
+
+diff --git a/src/channels.c b/src/channels.c
+index 8290dbd1..3afdcf11 100644
+--- a/src/channels.c
++++ b/src/channels.c
+@@ -192,6 +192,13 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open_conf){
+ if (rc != SSH_OK)
+ goto error;
+
++ if (channel->remote_maxpacket == 0) {
++ SSH_LOG(SSH_LOG_RARE,
++ "Invalid maximum packet size 0 in "
++ "SSH2_MSG_CHANNEL_OPEN_CONFIRMATION");
++ goto error;
++ }
++
+ SSH_LOG(SSH_LOG_PROTOCOL,
+ "Received a CHANNEL_OPEN_CONFIRMATION for channel %d:%d",
+ channel->local_channel,
+diff --git a/src/messages.c b/src/messages.c
+index 6dadabf0..e79ecec2 100644
+--- a/src/messages.c
++++ b/src/messages.c
+@@ -1160,10 +1160,21 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open){
+ SSH_LOG(SSH_LOG_PACKET,
+ "Clients wants to open a %s channel", type_c);
+
+- ssh_buffer_unpack(packet,"ddd",
+- &msg->channel_request_open.sender,
+- &msg->channel_request_open.window,
+- &msg->channel_request_open.packet_size);
++ rc = ssh_buffer_unpack(packet,
++ "ddd",
++ &msg->channel_request_open.sender,
++ &msg->channel_request_open.window,
++ &msg->channel_request_open.packet_size);
++ if (rc != SSH_OK){
++ goto error;
++ }
++
++ if (msg->channel_request_open.packet_size == 0) {
++ ssh_set_error(session,
++ SSH_FATAL,
++ "Invalid maximum packet size 0 in SSH2_MSG_CHANNEL_OPEN");
++ goto error;
++ }
+
+ if (session->session_state != SSH_SESSION_STATE_AUTHENTICATED){
+ ssh_set_error(session,SSH_FATAL, "Invalid state when receiving channel open request (must be authenticated)");
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 1f64920a50..381b3efc7d 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -32,6 +32,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0968-2.patch \
file://CVE-2026-0967.patch \
file://CVE-2026-0965.patch \
+ file://CVE-2026-59843.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (3 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59844 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9
[2] https://www.libssh.org/security/advisories/CVE-2026-59844.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59844.patch | 52 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 1 +
2 files changed, 53 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
new file mode 100644
index 0000000000..ac380622d9
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
@@ -0,0 +1,52 @@
+From ef7cd6d4aef6d18ca8bf15cb0398b630284f46f4 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Fri, 6 Mar 2026 18:05:29 +0100
+Subject: [PATCH] CVE-2026-59844 sftpserver: cap accepted values of len in
+ SSH_FXP_READ
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The client-provided length is directly used in
+a malloc in process_read(), so not restricting it
+leads to allocations bounded only by UINT32_MAX.
+
+The new cap is the same as the one currently used
+by OpenSSH.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59844
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9]
+
+Backport Changes:
+- Replace the upstream goto error path with equivalent direct message cleanup
+ and return because libssh 0.10.6 does not have the refactored
+ sftp_make_client_message() error label.
+
+(cherry picked from commit 6dba2e06f0713c04ad5eca7d4315d0104be7e627)
+(cherry picked from commit e31f06e5380be4e714d5ad6965981fbf30738da9)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/sftpserver.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/sftpserver.c b/src/sftpserver.c
+index 528ef6f9..77290068 100644
+--- a/src/sftpserver.c
++++ b/src/sftpserver.c
+@@ -105,6 +105,13 @@ sftp_client_message sftp_get_client_message(sftp_session sftp) {
+ sftp_client_message_free(msg);
+ return NULL;
+ }
++ if (msg->len > MAX_PACKET_LEN - 1024) {
++ ssh_set_error(sftp->session, SSH_FATAL,
++ "Too large SSH_FXP_READ length: %" PRIu32,
++ msg->len);
++ sftp_client_message_free(msg);
++ return NULL;
++ }
+ break;
+ case SSH_FXP_WRITE:
+ rc = ssh_buffer_unpack(payload,
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 381b3efc7d..a9d7729f2c 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -33,6 +33,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0967.patch \
file://CVE-2026-0965.patch \
file://CVE-2026-59843.patch \
+ file://CVE-2026-59844.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (2 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
libssh 0.10.6 predates the username-validation helper used by the
stable-0.11 fix, so the upstream commit in [1] cannot be applied as-is.
Adapt the same dangerous-character check directly at the ProxyCommand %r
expansion sink and add focused regression coverage.
The upstream advisory [2] identifies libssh 0.11.5 and 0.12.1 as the
fixed releases.
[1] https://gitlab.com/libssh/libssh-mirror/-/commit/56ce3c193eb06af5bf3b07ec0b4c7308b5c72130
[2] https://www.libssh.org/security/advisories/CVE-2026-59846.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59846.patch | 87 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 5 ++
2 files changed, 92 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
new file mode 100644
index 0000000000..9c626d113d
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
@@ -0,0 +1,87 @@
+From 19fe4c9fc7b3bd3553250bf9ddea03ed1dcf044f Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Thu, 2 Apr 2026 15:39:25 +0200
+Subject: [PATCH] CVE-2026-59846 Block shell metacharacters from usernames
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+When an attacker could sneak the dollar sign or backslash into the username
+expanded for example in proxy command, it can result in printing environment
+variables that might contain secrets.
+
+This is a fixup of CVE-2023-6004 which fixed this for hostnames, but these
+two metacharacters were left out from the username filter.
+
+This keeps the list in one place to simplify maintenance.
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+(cherry picked from commit 6309df220e3431deb41946f892f4bb5af8b59dba)
+
+CVE: CVE-2026-59846
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=56ce3c193eb06af5bf3b07ec0b4c7308b5c72130]
+
+Backport Changes:
+- libssh 0.10.6 predates ssh_check_username_syntax() and the centralized
+ SSH_DANGEROUS_SHELL_CHARS definition, so enforce the same character list
+ directly at the %r expansion sink in ssh_path_expand_escape().
+- Add focused regression coverage to the existing path-expansion unit test
+ for dollar-sign, backslash, and command-separator usernames.
+
+(cherry picked from commit 56ce3c193eb06af5bf3b07ec0b4c7308b5c72130)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/misc.c | 9 +++++++++
+ tests/unittests/torture_misc.c | 18 ++++++++++++++++++
+ 2 files changed, 27 insertions(+)
+
+diff --git a/src/misc.c b/src/misc.c
+index e78c92ba..15b427d7 100644
+--- a/src/misc.c
++++ b/src/misc.c
+@@ -1262,6 +1262,15 @@ char *ssh_path_expand_escape(ssh_session session, const char *s)
+ break;
+ case 'r':
+ if (session->opts.username) {
++ if (strpbrk(session->opts.username,
++ "'`\";&<>|(){}$\\,") != NULL) {
++ ssh_set_error(session,
++ SSH_FATAL,
++ "Invalid shell metacharacter in username");
++ free(buf);
++ free(r);
++ return NULL;
++ }
+ x = strdup(session->opts.username);
+ } else {
+ ssh_set_error(session, SSH_FATAL,
+diff --git a/tests/unittests/torture_misc.c b/tests/unittests/torture_misc.c
+index 82d6cf16..66d392ed 100644
+--- a/tests/unittests/torture_misc.c
++++ b/tests/unittests/torture_misc.c
+@@ -194,6 +194,24 @@ static void torture_path_expand_escape(void **state) {
+ assert_non_null(e);
+ assert_string_equal(e, "guru/meditation/222/by/root");
+ ssh_string_free_char(e);
++
++ free(session->opts.username);
++ session->opts.username = strdup("root$HOME");
++ assert_non_null(session->opts.username);
++ e = ssh_path_expand_escape(session, s);
++ assert_null(e);
++
++ free(session->opts.username);
++ session->opts.username = strdup("root\\user");
++ assert_non_null(session->opts.username);
++ e = ssh_path_expand_escape(session, s);
++ assert_null(e);
++
++ free(session->opts.username);
++ session->opts.username = strdup("root;id");
++ assert_non_null(session->opts.username);
++ e = ssh_path_expand_escape(session, s);
++ assert_null(e);
+ }
+
+ static void torture_path_expand_known_hosts(void **state) {
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index a9d7729f2c..8e86073fd3 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -34,6 +34,11 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0965.patch \
file://CVE-2026-59843.patch \
file://CVE-2026-59844.patch \
+<<<<<<< HEAD
+=======
+ file://CVE-2026-59845.patch \
+ file://CVE-2026-59846.patch \
+>>>>>>> b782f294a0 (libssh: Fix CVE-2026-59846)
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (2 preceding siblings ...)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the primary upstream fix selected
for this backport. Commit [2] corrects the request-queue pointer state
introduced by [1], so it is carried immediately afterward as a regression
fix. The upstream advisory [3] documents CVE-2026-59848 and identifies
libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497
[2] https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be
[3] https://www.libssh.org/security/advisories/CVE-2026-59848.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/CVE-2026-59848-regression.patch | 45 ++
.../libssh/libssh/CVE-2026-59848.patch | 684 ++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 6 +-
3 files changed, 731 insertions(+), 4 deletions(-)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
new file mode 100644
index 0000000000..161271264f
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
@@ -0,0 +1,45 @@
+From dddd93ac995ac382e4ec9496509f24003bd72c30 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Wed, 3 Jun 2026 12:56:09 +0200
+Subject: [PATCH] CVE-2026-59848 sftp: Initialize sftp_request_queue ptr in
+ sftp_free
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59848
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be]
+
+Backport Changes:
+- Adjusted hunk context for the consolidated libssh 0.10.6 SFTP
+ implementation; the pointer initialization is unchanged from upstream.
+- Omitted the upstream tests/client/torture_sftp_request_id.c follow-up hunk
+ because CVE-2026-59848.patch introduces the backported regression test
+ directly with sftp_read_and_dispatch(); there is no intermediate
+ sftp_recv_response_msg() version to update.
+
+(cherry picked from commit 00876f7658fd265682708572122502188fa22076)
+(cherry picked from commit 5309aefd99e1775db40bf20869f1fb1cc6c787be)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/sftp.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/sftp.c b/src/sftp.c
+index e6755e2b..ff6e5200 100644
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -371,7 +371,7 @@ void sftp_server_free(sftp_session sftp)
+
+ void sftp_free(sftp_session sftp)
+ {
+- sftp_request_queue ptr;
++ sftp_request_queue ptr = NULL;
+ struct ssh_iterator *id_it = NULL;
+
+ if (sftp == NULL) {
+--
+2.35.6
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
new file mode 100644
index 0000000000..2f4efb22f1
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
@@ -0,0 +1,684 @@
+From ef75e652dd2808c27251da4d03feef84d158c1de Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Mon, 1 Jun 2026 16:33:03 +0200
+Subject: [PATCH] CVE-2026-59848 sftp: handle responses with unknown request
+ IDs
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+This adds a new field to sftp_session_struct,
+containing a list of outstanding request IDs.
+An ID is added to the list when a request
+is constructed and removed when the corresponding
+request is received. If a client receives a response
+with an unknown request ID, it reports an error.
+
+Storing responses with unknown request IDs in
+the response queue could be abused by a malicious
+SFTP server which could deplete client memory
+this way.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59848
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497]
+
+Backport Changes:
+- Consolidated the upstream src/sftp_common.c and src/sftp_aio.c changes
+ into src/sftp.c, where libssh 0.10.6 implements response dispatch,
+ request-ID allocation, and asynchronous SFTP reads.
+- Kept sftp_get_new_id() static instead of exporting it through
+ sftp_priv.h because all 20 request-producing call sites in 0.10.6 are
+ in src/sftp.c; newer-only SFTP API call sites are absent.
+- Retained the 0.10.6 request construction order and free the existing
+ request buffer when request-ID tracking fails.
+- Adapted the unknown-ID regression test to call
+ sftp_read_and_dispatch() and verify the response queue remains empty;
+ 0.10.6 does not provide sftp_recv_response_msg().
+
+(cherry picked from commit 26147eb4767937c797f97ff3b1b1663384232417)
+(cherry picked from commit a30a51003205744c10ba4439306f555206ae8497)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ include/libssh/sftp.h | 1 +
+ src/sftp.c | 210 ++++++++++++++++++++++---
+ tests/client/CMakeLists.txt | 1 +
+ tests/client/torture_sftp_request_id.c | 183 +++++++++++++++++++++
+ 4 files changed, 369 insertions(+), 26 deletions(-)
+ create mode 100644 tests/client/torture_sftp_request_id.c
+
+diff --git a/include/libssh/sftp.h b/include/libssh/sftp.h
+index c713466e..984c4eb7 100644
+--- a/include/libssh/sftp.h
++++ b/include/libssh/sftp.h
+@@ -90,6 +90,7 @@ struct sftp_session_struct {
+ void **handles;
+ sftp_ext ext;
+ sftp_packet read_packet;
++ struct ssh_list *outstanding_ids;
+ };
+
+ struct sftp_packet_struct {
+diff --git a/src/sftp.c b/src/sftp.c
+index 2194a9ef..e6755e2b 100644
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -149,6 +149,12 @@ sftp_session sftp_new(ssh_session session)
+ goto error;
+ }
+
++ sftp->outstanding_ids = ssh_list_new();
++ if (sftp->outstanding_ids == NULL) {
++ ssh_set_error_oom(session);
++ goto error;
++ }
++
+ if (ssh_channel_open_session(sftp->channel)) {
+ goto error;
+ }
+@@ -165,6 +171,7 @@ error:
+ if (sftp->channel != NULL) {
+ ssh_channel_free(sftp->channel);
+ }
++ ssh_list_free(sftp->outstanding_ids);
+ if (sftp->read_packet != NULL) {
+ if (sftp->read_packet->payload != NULL) {
+ SSH_BUFFER_FREE(sftp->read_packet->payload);
+@@ -196,6 +203,12 @@ sftp_new_channel(ssh_session session, ssh_channel channel)
+ goto error;
+ }
+
++ sftp->outstanding_ids = ssh_list_new();
++ if (sftp->outstanding_ids == NULL) {
++ ssh_set_error_oom(session);
++ goto error;
++ }
++
+ sftp->read_packet = calloc(1, sizeof(struct sftp_packet_struct));
+ if (sftp->read_packet == NULL) {
+ ssh_set_error_oom(session);
+@@ -217,6 +230,7 @@ error:
+ if (sftp->ext != NULL) {
+ sftp_ext_free(sftp->ext);
+ }
++ ssh_list_free(sftp->outstanding_ids);
+ if (sftp->read_packet != NULL) {
+ if (sftp->read_packet->payload != NULL) {
+ SSH_BUFFER_FREE(sftp->read_packet->payload);
+@@ -358,6 +372,7 @@ void sftp_server_free(sftp_session sftp)
+ void sftp_free(sftp_session sftp)
+ {
+ sftp_request_queue ptr;
++ struct ssh_iterator *id_it = NULL;
+
+ if (sftp == NULL) {
+ return;
+@@ -384,6 +399,12 @@ void sftp_free(sftp_session sftp)
+
+ sftp_ext_free(sftp->ext);
+
++ id_it = ssh_list_get_iterator(sftp->outstanding_ids);
++ for (; id_it != NULL; id_it = id_it->next) {
++ free((uint32_t *)id_it->data);
++ }
++ ssh_list_free(sftp->outstanding_ids);
++
+ SAFE_FREE(sftp);
+ }
+
+@@ -571,6 +592,8 @@ static sftp_message sftp_get_message(sftp_packet packet)
+ {
+ sftp_session sftp = packet->sftp;
+ sftp_message msg = NULL;
++ struct ssh_iterator *id_it = NULL;
++ bool id_found = false;
+ int rc;
+
+ switch(packet->type) {
+@@ -618,6 +641,28 @@ static sftp_message sftp_get_message(sftp_packet packet)
+ msg->id,
+ msg->packet_type);
+
++ /* Validate that this ID is in our outstanding requests list */
++ id_it = ssh_list_get_iterator(sftp->outstanding_ids);
++ for (; id_it != NULL; id_it = id_it->next) {
++ uint32_t *stored_id = (uint32_t *)id_it->data;
++ if (*stored_id == msg->id) {
++ id_found = true;
++ ssh_list_remove(sftp->outstanding_ids, id_it);
++ free(stored_id);
++ break;
++ }
++ }
++
++ if (!id_found) {
++ ssh_set_error(packet->sftp->session,
++ SSH_FATAL,
++ "Unknown request ID %" PRIu32,
++ msg->id);
++ sftp_message_free(msg);
++ sftp_set_error(packet->sftp, SSH_FX_FAILURE);
++ return NULL;
++ }
++
+ return msg;
+ }
+
+@@ -902,13 +947,46 @@ static sftp_message sftp_dequeue(sftp_session sftp, uint32_t id){
+ return NULL;
+ }
+
+-/*
+- * Assigns a new SFTP ID for new requests and assures there is no collision
+- * between them.
+- * Returns a new ID ready to use in a request
++/**
++ * @brief Assigns a new SFTP ID for new requests and assures there is no
++ * collision between them.
++ *
++ * @param sftp The sftp session handle.
++ * @param id_out Pointer to store the new ID.
++ *
++ * @returns SSH_OK on success with the new ID stored in *id
++ * @returns SSH_ERROR on failure with the sftp and ssh errors set
+ */
+-static inline uint32_t sftp_get_new_id(sftp_session session) {
+- return ++session->id_counter;
++static int sftp_get_new_id(sftp_session sftp, uint32_t *id_out)
++{
++ uint32_t *id = NULL;
++ int rc;
++
++ if (id_out == NULL) {
++ ssh_set_error_invalid(sftp->session);
++ sftp_set_error(sftp, SSH_FX_FAILURE);
++ return SSH_ERROR;
++ }
++
++ id = malloc(sizeof(uint32_t));
++ if (id == NULL) {
++ ssh_set_error_oom(sftp->session);
++ sftp_set_error(sftp, SSH_FX_FAILURE);
++ return SSH_ERROR;
++ }
++
++ *id = ++sftp->id_counter;
++ rc = ssh_list_append(sftp->outstanding_ids, id);
++ if (rc != SSH_OK) {
++ free(id);
++ ssh_set_error_oom(sftp->session);
++ sftp_set_error(sftp, SSH_FX_FAILURE);
++ return SSH_ERROR;
++ }
++
++ *id_out = *id;
++
++ return SSH_OK;
+ }
+
+ static sftp_status_message parse_status_msg(sftp_message msg){
+@@ -1029,7 +1107,11 @@ sftp_dir sftp_opendir(sftp_session sftp, const char *path)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(payload);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(payload,
+ "ds",
+@@ -1571,7 +1653,11 @@ sftp_attributes sftp_readdir(sftp_session sftp, sftp_dir dir)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(payload);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(payload,
+ "dS",
+@@ -1704,7 +1790,11 @@ static int sftp_handle_close(sftp_session sftp, ssh_string handle)
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dS",
+@@ -1835,7 +1925,11 @@ sftp_file sftp_open(sftp_session sftp,
+ sftp_flags |= SSH_FXF_APPEND;
+ }
+ SSH_LOG(SSH_LOG_PACKET,"Opening file %s with sftp flags %x",file,sftp_flags);
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dsd",
+@@ -1946,7 +2040,11 @@ ssize_t sftp_read(sftp_file handle, void *buf, size_t count) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(handle->sftp);
++ rc = sftp_get_new_id(handle->sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dSqd",
+@@ -2047,7 +2145,11 @@ int sftp_async_read_begin(sftp_file file, uint32_t len){
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dSqd",
+@@ -2173,7 +2275,11 @@ ssize_t sftp_write(sftp_file file, const void *buf, size_t count) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(file->sftp);
++ rc = sftp_get_new_id(file->sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dSqdP",
+@@ -2291,7 +2397,11 @@ int sftp_unlink(sftp_session sftp, const char *file) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2366,7 +2476,11 @@ int sftp_rmdir(sftp_session sftp, const char *directory) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2443,7 +2557,11 @@ int sftp_mkdir(sftp_session sftp, const char *directory, mode_t mode)
+ attr.permissions = mode;
+ attr.flags = SSH_FILEXFER_ATTR_PERMISSIONS;
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2538,7 +2656,11 @@ int sftp_rename(sftp_session sftp, const char *original, const char *newname) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dss",
+@@ -2622,7 +2744,11 @@ int sftp_setstat(sftp_session sftp, const char *file, sftp_attributes attr)
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2752,7 +2878,11 @@ int sftp_symlink(sftp_session sftp, const char *target, const char *dest) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ /* TODO check for version number if they ever fix it. */
+ if (ssh_get_openssh_version(sftp->session)) {
+@@ -2850,7 +2980,11 @@ char *sftp_readlink(sftp_session sftp, const char *path)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2976,7 +3110,11 @@ sftp_statvfs_t sftp_statvfs(sftp_session sftp, const char *path)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dss",
+@@ -3051,7 +3189,11 @@ int sftp_fsync(sftp_file file)
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dsS",
+@@ -3151,7 +3293,11 @@ sftp_statvfs_t sftp_fstatvfs(sftp_file file)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dsS",
+@@ -3238,7 +3384,11 @@ char *sftp_canonicalize_path(sftp_session sftp, const char *path)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -3329,7 +3479,11 @@ static sftp_attributes sftp_xstat(sftp_session sftp,
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -3407,7 +3561,11 @@ sftp_attributes sftp_fstat(sftp_file file)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(file->sftp);
++ rc = sftp_get_new_id(file->sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dS",
+diff --git a/tests/client/CMakeLists.txt b/tests/client/CMakeLists.txt
+index 71e5182e..864478a7 100644
+--- a/tests/client/CMakeLists.txt
++++ b/tests/client/CMakeLists.txt
+@@ -49,6 +49,7 @@ if (WITH_SFTP)
+ torture_sftp_dir
+ torture_sftp_read
+ torture_sftp_fsync
++ torture_sftp_request_id
+ ${SFTP_BENCHMARK_TESTS})
+ endif (WITH_SFTP)
+
+diff --git a/tests/client/torture_sftp_request_id.c b/tests/client/torture_sftp_request_id.c
+new file mode 100644
+index 00000000..fe6d3f91
+--- /dev/null
++++ b/tests/client/torture_sftp_request_id.c
+@@ -0,0 +1,183 @@
++#include "config.h"
++
++#define LIBSSH_STATIC
++
++#include "sftp.c"
++#include "torture.h"
++
++#include <pwd.h>
++#include <sys/types.h>
++
++static int sshd_setup(void **state)
++{
++ torture_setup_sshd_server(state, false);
++
++ return 0;
++}
++
++static int sshd_teardown(void **state)
++{
++ torture_teardown_sshd_server(state);
++
++ return 0;
++}
++
++static int session_setup(void **state)
++{
++ struct torture_state *s = *state;
++ struct passwd *pwd = NULL;
++ int rc;
++
++ pwd = getpwnam("bob");
++ assert_non_null(pwd);
++
++ rc = setuid(pwd->pw_uid);
++ assert_return_code(rc, errno);
++
++ s->ssh.session = torture_ssh_session(s,
++ TORTURE_SSH_SERVER,
++ NULL,
++ TORTURE_SSH_USER_ALICE,
++ NULL);
++ assert_non_null(s->ssh.session);
++
++ s->ssh.tsftp = torture_sftp_session(s->ssh.session);
++ assert_non_null(s->ssh.tsftp);
++
++ return 0;
++}
++
++static int session_teardown(void **state)
++{
++ struct torture_state *s = *state;
++
++ torture_rmdirs(s->ssh.tsftp->testdir);
++ torture_sftp_close(s->ssh.tsftp);
++ ssh_disconnect(s->ssh.session);
++ ssh_free(s->ssh.session);
++
++ return 0;
++}
++
++static void torture_sftp_request_id_null(void **state)
++{
++ struct torture_state *s = *state;
++ struct torture_sftp *t = s->ssh.tsftp;
++ sftp_session sftp = t->sftp;
++ int rc;
++
++ rc = sftp_get_new_id(sftp, NULL);
++ assert_int_equal(rc, SSH_ERROR);
++}
++
++static void torture_sftp_request_id_add(void **state)
++{
++ struct torture_state *s = *state;
++ struct torture_sftp *t = s->ssh.tsftp;
++ sftp_session sftp = t->sftp;
++ uint32_t id1, id2;
++ int rc;
++ size_t count;
++
++ /* The list of IDs should be empty at first */
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 0);
++
++ /* Request a new ID */
++ rc = sftp_get_new_id(sftp, &id1);
++ assert_int_equal(rc, SSH_OK);
++
++ /* Check that the list has one ID now */
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 1);
++
++ /* Request another ID */
++ rc = sftp_get_new_id(sftp, &id2);
++ assert_int_equal(rc, SSH_OK);
++
++ /* Check that the IDs differ */
++ assert_int_not_equal(id1, id2);
++
++ /* Check that the list has two IDs now */
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 2);
++}
++
++static void torture_sftp_request_id_remove(void **state)
++{
++ struct torture_state *s = *state;
++ struct torture_sftp *t = s->ssh.tsftp;
++ sftp_session sftp = t->sftp;
++ sftp_attributes attr = NULL;
++ size_t count;
++
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 0);
++
++ /* We send a request and receive a response */
++ attr = sftp_stat(sftp, SSH_EXECUTABLE);
++ assert_non_null(attr);
++
++ /* The number of outstanding requests should be back to 0 */
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 0);
++
++ sftp_attributes_free(attr);
++}
++
++static void torture_sftp_request_id_unknown(void **state)
++{
++ struct torture_state *s = *state;
++ struct torture_sftp *t = s->ssh.tsftp;
++ sftp_session sftp = t->sftp;
++ ssh_buffer buffer = NULL;
++ uint32_t id = 0;
++ int rc;
++ size_t count;
++
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 0);
++
++ buffer = ssh_buffer_new();
++ assert_non_null(buffer);
++
++ rc = ssh_buffer_pack(buffer, "ds", id, "/tmp");
++ assert_int_equal(rc, SSH_OK);
++
++ /* Send a request without saving the request ID */
++ rc = sftp_packet_write(sftp, SSH_FXP_OPENDIR, buffer);
++ assert_int_not_equal(rc, -1);
++ SSH_BUFFER_FREE(buffer);
++
++ /* An attempt to receive the response should fail without queuing it */
++ rc = sftp_read_and_dispatch(sftp);
++ assert_int_equal(rc, -1);
++ assert_null(sftp->queue);
++}
++
++int torture_run_tests(void)
++{
++ int rc;
++ struct CMUnitTest tests[] = {
++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_null,
++ session_setup,
++ session_teardown),
++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_add,
++ session_setup,
++ session_teardown),
++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_remove,
++ session_setup,
++ session_teardown),
++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_unknown,
++ session_setup,
++ session_teardown),
++ };
++
++ ssh_init();
++
++ torture_filter_tests(tests);
++ rc = cmocka_run_group_tests(tests, sshd_setup, sshd_teardown);
++ ssh_finalize();
++
++ return rc;
++}
+--
+2.35.6
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 8e86073fd3..1a5f521f6a 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -34,11 +34,9 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0965.patch \
file://CVE-2026-59843.patch \
file://CVE-2026-59844.patch \
-<<<<<<< HEAD
-=======
- file://CVE-2026-59845.patch \
file://CVE-2026-59846.patch \
->>>>>>> b782f294a0 (libssh: Fix CVE-2026-59846)
+ file://CVE-2026-59848.patch \
+ file://CVE-2026-59848-regression.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (3 preceding siblings ...)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59850 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2
[2] https://www.libssh.org/security/advisories/CVE-2026-59850.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59850.patch | 40 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 1 +
2 files changed, 41 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
new file mode 100644
index 0000000000..61e502c796
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
@@ -0,0 +1,40 @@
+From a207ee3b4244c0e5da902245f8b81f3617b416f3 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Wed, 1 Jul 2026 16:43:08 +0200
+Subject: [PATCH] CVE-2026-59850 channels: Avoid processing DATA packets on
+ closed channels
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+
+CVE: CVE-2026-59850
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2]
+
+(cherry picked from commit a8a3fa352bb5213e08a35e4494c6e44360e2e38a)
+(cherry picked from commit 6edfb52b3b364577d2db0334c0514a977efceed2)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/channels.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/channels.c b/src/channels.c
+index 3afdcf11..1543c792 100644
+--- a/src/channels.c
++++ b/src/channels.c
+@@ -575,6 +575,13 @@ SSH_PACKET_CALLBACK(channel_rcv_data){
+ channel->local_window,
+ channel->remote_window);
+
++ if (channel->flags & SSH_CHANNEL_FLAG_CLOSED_REMOTE) {
++ SSH_LOG(SSH_LOG_WARNING, "Received data on (remotely) closed channel");
++ ssh_set_error(session, SSH_FATAL, "Received data on (remotely) closed channel");
++ SSH_STRING_FREE(str);
++ return SSH_PACKET_USED;
++ }
++
+ /* What shall we do in this case? Let's accept it anyway */
+ if (len > channel->local_window) {
+ SSH_LOG(SSH_LOG_RARE,
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 1a5f521f6a..cc957d62ca 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -37,6 +37,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-59846.patch \
file://CVE-2026-59848.patch \
file://CVE-2026-59848-regression.patch \
+ file://CVE-2026-59850.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (4 preceding siblings ...)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-01 1:37 ` Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
5 siblings, 1 reply; 8+ messages in thread
From: Anuj Mittal @ 2026-09-01 1:37 UTC (permalink / raw)
To: hthakar; +Cc: openembedded-devel, xe-linux-external
On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
PRIVATE LIMITED at Cisco) via lists.openembedded.org
<hthakar=cisco.com@lists.openembedded.org> wrote:
>
> From: Hetvi Thakar <hthakar@cisco.com>
>
> Backport five upstream libssh security fixes to the 0.10.6 recipe on
> scarthgap:
>
> - CVE-2026-59843
> - CVE-2026-59844
> - CVE-2026-59846
> - CVE-2026-59848
> - CVE-2026-59850
>
> Carry these as focused backports instead of upgrading libssh because
> newer releases include API and functional changes outside the security
> scope.
>
> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
> code or features absent from 0.10.6. NVD correction requests have been
> submitted for these inaccurate affected-version entries; therefore, no
> CVE_STATUS entries are added.
>
> The individual commits retain the upstream fix provenance and advisory
> references for each CVE.
>
> Testing:
> - Applied all five patches to libssh 0.10.6 in series order without
> conflicts or fuzz.
> - Package build completed successfully.
>
> Hetvi Thakar (5):
> libssh: Fix CVE-2026-59843
> libssh: Fix CVE-2026-59844
> libssh: Fix CVE-2026-59846
> libssh: Fix CVE-2026-59848
> libssh: Fix CVE-2026-59850
3/5 is adding unresolved merge markers to recipe that 4/5 is then
removing. Please fix the patches, rebase them on current scarthgap and
resend.
Thanks,
Anuj
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
@ 2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-01 8:23 UTC (permalink / raw)
To: openembedded-devel
[-- Attachment #1: Type: text/plain, Size: 1811 bytes --]
On Tue, Sep 1, 2026 at 07:07 AM, Anuj Mittal wrote:
>
> On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
> PRIVATE LIMITED at Cisco) via lists.openembedded.org
> <hthakar=cisco.com@lists.openembedded.org> wrote:
>
>> From: Hetvi Thakar <hthakar@cisco.com>
>>
>> Backport five upstream libssh security fixes to the 0.10.6 recipe on
>> scarthgap:
>>
>> - CVE-2026-59843
>> - CVE-2026-59844
>> - CVE-2026-59846
>> - CVE-2026-59848
>> - CVE-2026-59850
>>
>> Carry these as focused backports instead of upgrading libssh because
>> newer releases include API and functional changes outside the security
>> scope.
>>
>> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
>> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
>> code or features absent from 0.10.6. NVD correction requests have been
>> submitted for these inaccurate affected-version entries; therefore, no
>> CVE_STATUS entries are added.
>>
>> The individual commits retain the upstream fix provenance and advisory
>> references for each CVE.
>>
>> Testing:
>> - Applied all five patches to libssh 0.10.6 in series order without
>> conflicts or fuzz.
>> - Package build completed successfully.
>>
>> Hetvi Thakar (5):
>> libssh: Fix CVE-2026-59843
>> libssh: Fix CVE-2026-59844
>> libssh: Fix CVE-2026-59846
>> libssh: Fix CVE-2026-59848
>> libssh: Fix CVE-2026-59850
>
> 3/5 is adding unresolved merge markers to recipe that 4/5 is then
> removing. Please fix the patches, rebase them on current scarthgap and
> resend.
>
> Thanks,
>
> Anuj
Hi,
Thanks for pointing this out.
I will fix the unresolved merge markers, rebase the patch series on
the current scarthgap branch, and resend the updated series.
Regards,
Hetvi
[-- Attachment #2: Type: text/html, Size: 2109 bytes --]
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-01 8:24 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.