Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Titouan Christophe via buildroot <buildroot@buildroot.org>
To: Bernd Kuhls <bernd@kuhls.net>, buildroot@buildroot.org
Subject: Re: [Buildroot] [PATCH 1/1] package/openssh: security bump to version 10.5p1
Date: Sat, 22 Aug 2026 14:39:44 +0200	[thread overview]
Message-ID: <0732adad-be52-4a94-94f6-e9fd6c8f55eb@mind.be> (raw)
In-Reply-To: <20260816075345.1844714-1-bernd@kuhls.net>

On 16/08/26 09:53, Bernd Kuhls wrote:
> https://www.openssh.org/releasenotes.html#10.5p1
>
> Changes since OpenSSH 10.4
> ==========================
>
> This release contains a number of security fixes and small bugfixes.
>
> Security
> ========
>
>   * ssh-agent(1): fix an interaction between agent locking and the
>     session-bind@openssh.com extension that is used to identify
>     forwarded agents. These binding requests were refused when the
>     agent was locked, with the result that operations that were
>     intended to be limited to local use only could be performed
>     remotely, including the ability to add PKCS#11 tokens and make
>     use of keys that had destination restrictions applied.
>     Reported by sn0x-sharma
>
>   * ssh(1): avoid potential realloc use-after-free in the client if a
>     remote forwarding is added via the local session multiplexing
>     socket while a remote forwarding open request is pending with the
>     server. Report and fix from Brian Mingus of Cognatory
>
>   * sshd(8): make the authorized_keys "restrict" keyword apply
>     correctly to tunnel forwarding too (which is administratively
>     disabled by default). Reported by Erichen, Institute of Computing
>     Technology, Chinese Academy of Sciences
> [...]
>
> Signed-off-by: Bernd Kuhls <bernd@kuhls.net>

Applied to 2026.05.x, thanks !
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

      parent reply	other threads:[~2026-08-22 12:39 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-16  7:53 [Buildroot] [PATCH 1/1] package/openssh: security bump to version 10.5p1 Bernd Kuhls
2026-08-16  8:29 ` Julien Olivain via buildroot
2026-08-22 12:39 ` Titouan Christophe via buildroot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=0732adad-be52-4a94-94f6-e9fd6c8f55eb@mind.be \
    --to=buildroot@buildroot.org \
    --cc=bernd@kuhls.net \
    --cc=titouan.christophe@mind.be \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox