Openembedded Core Discussions
 help / color / mirror / Atom feed
* [PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035
@ 2026-08-03  8:22 Jaipaul Cheernam
  2026-08-03  8:22 ` [PATCH 1/3] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Jaipaul Cheernam @ 2026-08-03  8:22 UTC (permalink / raw)
  To: openembedded-core; +Cc: Jaipaul Cheernam

Fix three CVEs in libssh2 1.11.1 by backporting upstream fixes:

- CVE-2026-66033: potential OOB read/write with AES-GCM in ssh2_cipher_crypt()
- CVE-2026-66034: potential OOB read in libssh2_publickey_list_fetch()
- CVE-2026-66035: potential heap overflow on ETM decrypt

Backport adaptations:
- CVE-2026-66034: upstream uses ssh2_err() which is not available in
  1.11.1, replaced with _libssh2_error().
- CVE-2026-66035: upstream uses SSH2_SAFEFREE() (not in 1.11.1),
  replaced with LIBSSH2_FREE() + NULL reset. Also upstream renames
  decrypt() to transport_decrypt(), retained original name.

libssh2 ptest results (qemux86-64):
  before: PASSED: 1 FAILED: 0 SKIPPED: 0
  after:  PASSED: 1 FAILED: 0 SKIPPED: 0

Jaipaul Cheernam (3):
  libssh2: fix CVE-2026-66033
  libssh2: fix CVE-2026-66034
  libssh2: fix CVE-2026-66035

 .../libssh2/libssh2/CVE-2026-66033.patch      | 45 +++++++++++++++
 .../libssh2/libssh2/CVE-2026-66034.patch      | 40 +++++++++++++
 .../libssh2/libssh2/CVE-2026-66035.patch      | 56 +++++++++++++++++++
 .../recipes-support/libssh2/libssh2_1.11.1.bb |  3 +
 4 files changed, 144 insertions(+)
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch
 create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-08-03  8:23 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-03  8:22 [PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
2026-08-03  8:22 ` [PATCH 1/3] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
2026-08-03  8:22 ` [PATCH 2/3] libssh2: fix CVE-2026-66034 Jaipaul Cheernam
2026-08-03  8:22 ` [PATCH 3/3] libssh2: fix CVE-2026-66035 Jaipaul Cheernam

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox