* [wrynose][PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035
@ 2026-08-03 8:41 Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 1/3] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Jaipaul Cheernam @ 2026-08-03 8:41 UTC (permalink / raw)
To: openembedded-core; +Cc: Jaipaul Cheernam
Fix three CVEs in libssh2 1.11.1 by backporting upstream fixes:
- CVE-2026-66033: potential OOB read/write with AES-GCM in ssh2_cipher_crypt()
- CVE-2026-66034: potential OOB read in libssh2_publickey_list_fetch()
- CVE-2026-66035: potential heap overflow on ETM decrypt
Backport adaptations:
- CVE-2026-66034: upstream uses ssh2_err() which is not available in
1.11.1, replaced with _libssh2_error().
- CVE-2026-66035: upstream uses SSH2_SAFEFREE() (not in 1.11.1),
replaced with LIBSSH2_FREE() + NULL reset. Also upstream renames
decrypt() to transport_decrypt(), retained original name.
libssh2 ptest results (qemux86-64):
before: PASSED: 1 FAILED: 0 SKIPPED: 0
after: PASSED: 1 FAILED: 0 SKIPPED: 0
Jaipaul Cheernam (3):
libssh2: fix CVE-2026-66033
libssh2: fix CVE-2026-66034
libssh2: fix CVE-2026-66035
.../libssh2/libssh2/CVE-2026-66033.patch | 45 +++++++++++++++
.../libssh2/libssh2/CVE-2026-66034.patch | 40 +++++++++++++
.../libssh2/libssh2/CVE-2026-66035.patch | 56 +++++++++++++++++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 3 +
4 files changed, 144 insertions(+)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch
^ permalink raw reply [flat|nested] 4+ messages in thread
* [wrynose][PATCH 1/3] libssh2: fix CVE-2026-66033
2026-08-03 8:41 [wrynose][PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
@ 2026-08-03 8:41 ` Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 2/3] libssh2: fix CVE-2026-66034 Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 3/3] libssh2: fix CVE-2026-66035 Jaipaul Cheernam
2 siblings, 0 replies; 4+ messages in thread
From: Jaipaul Cheernam @ 2026-08-03 8:41 UTC (permalink / raw)
To: openembedded-core; +Cc: Jaipaul Cheernam
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-66033
https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6
libssh2 ptest results (qemux86-64):
before: PASSED: 1 FAILED: 0 SKIPPED: 0
after: PASSED: 1 FAILED: 0 SKIPPED: 0
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../libssh2/libssh2/CVE-2026-66033.patch | 45 +++++++++++++++++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 1 +
2 files changed, 46 insertions(+)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
new file mode 100644
index 0000000000..bb046a6eae
--- /dev/null
+++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch
@@ -0,0 +1,45 @@
+From d1b6996c3b31ce6b60d5a820ecc33880e61ef0ae Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Thu, 23 Jul 2026 10:32:04 +0200
+Subject: [PATCH] openssl: fix potential OOB read/write with AES-GCM in
+ `ssh2_cipher_crypt()`
+
+By applying two bounds checks to non-debug builds.
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-c4f7-cvfc-33j7
+Follow-up to 3c953c05d67eb1ebcfd3316f279f12c4b1d600b4 #797
+
+Closes #2401
+
+CVE: CVE-2026-66033
+Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/openssl.c | 10 ++++++----
+ 1 file changed, 6 insertions(+), 4 deletions(-)
+
+diff --git a/src/openssl.c b/src/openssl.c
+index eba05031..28ae1cc0 100644
+--- a/src/openssl.c
++++ b/src/openssl.c
+@@ -1042,13 +1042,15 @@ _libssh2_cipher_crypt(_libssh2_cipher_ctx * ctx,
+ const int aadlen = (is_aesgcm && IS_FIRST(firstlast)) ? 4 : 0;
+ /* size of AT, if present */
+ const int authenticationtag = IS_LAST(firstlast) ? authlen : 0;
+- /* length to encrypt */
+- const int cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
++ unsigned int cryptlen; /* length to encrypt */
+
+ (void)algo;
+
+- assert(blocksize <= sizeof(buf));
+- assert(cryptlen >= 0);
++ if(blocksize > sizeof(buf) ||
++ blocksize < (size_t)(aadlen + authenticationtag))
++ return 1;
++
++ cryptlen = (unsigned int)blocksize - aadlen - authenticationtag;
+
+ #if LIBSSH2_AES_GCM
+ /* First block */
diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
index 32e1ad6c16..7e320ed0f8 100644
--- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb
+++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
@@ -16,6 +16,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
file://CVE-2025-15661-1.patch \
file://CVE-2025-15661-2.patch \
file://CVE-2025-15661-3.patch \
+ file://CVE-2026-66033.patch \
"
SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [wrynose][PATCH 2/3] libssh2: fix CVE-2026-66034
2026-08-03 8:41 [wrynose][PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 1/3] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
@ 2026-08-03 8:41 ` Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 3/3] libssh2: fix CVE-2026-66035 Jaipaul Cheernam
2 siblings, 0 replies; 4+ messages in thread
From: Jaipaul Cheernam @ 2026-08-03 8:41 UTC (permalink / raw)
To: openembedded-core; +Cc: Jaipaul Cheernam
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-66034
https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99804cd898d9
libssh2 ptest results (qemux86-64):
before: PASSED: 1 FAILED: 0 SKIPPED: 0
after: PASSED: 1 FAILED: 0 SKIPPED: 0
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../libssh2/libssh2/CVE-2026-66034.patch | 40 +++++++++++++++++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 1 +
2 files changed, 41 insertions(+)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch
diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch
new file mode 100644
index 0000000000..906356baf2
--- /dev/null
+++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch
@@ -0,0 +1,40 @@
+From 16720054e0b3f02e36f31dd04add534d73d4a18d Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Sat, 4 Jul 2026 11:19:49 +0200
+Subject: [PATCH] publickey: fix potential OOB read in
+ `libssh2_publickey_list_fetch()`
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-w6g9-cpfp-22gc
+
+Closes #2202
+
+Backport adaptations:
+- The upstream fix uses ssh2_err() which is not available in libssh2
+ 1.11.1. Replace with the equivalent _libssh2_error() call.
+
+CVE: CVE-2026-66034
+Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99804cd898d9]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/publickey.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/publickey.c b/src/publickey.c
+index 9c9fa618..f3776d2d 100644
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -988,6 +988,13 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys,
+ }
+
+ if(comment_len) {
++ if(pkey->listFetch_s + comment_len >
++ pkey->listFetch_data + pkey->listFetch_data_len) {
++ _libssh2_error(session, LIBSSH2_ERROR_BUFFER_TOO_SMALL,
++ "ListFetch data too short");
++ goto err_exit;
++ }
++
+ list[keys].num_attrs = 1;
+ list[keys].attrs =
+ LIBSSH2_ALLOC(session,
diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
index 7e320ed0f8..54022aa879 100644
--- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb
+++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
@@ -17,6 +17,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
file://CVE-2025-15661-2.patch \
file://CVE-2025-15661-3.patch \
file://CVE-2026-66033.patch \
+ file://CVE-2026-66034.patch \
"
SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [wrynose][PATCH 3/3] libssh2: fix CVE-2026-66035
2026-08-03 8:41 [wrynose][PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 1/3] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 2/3] libssh2: fix CVE-2026-66034 Jaipaul Cheernam
@ 2026-08-03 8:41 ` Jaipaul Cheernam
2 siblings, 0 replies; 4+ messages in thread
From: Jaipaul Cheernam @ 2026-08-03 8:41 UTC (permalink / raw)
To: openembedded-core; +Cc: Jaipaul Cheernam
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-66035
https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
libssh2 ptest results (qemux86-64):
before: PASSED: 1 FAILED: 0 SKIPPED: 0
after: PASSED: 1 FAILED: 0 SKIPPED: 0
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../libssh2/libssh2/CVE-2026-66035.patch | 56 +++++++++++++++++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 1 +
2 files changed, 57 insertions(+)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch
diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch
new file mode 100644
index 0000000000..7c15f92fb6
--- /dev/null
+++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch
@@ -0,0 +1,56 @@
+From 6671019836476649792eea12868a370133be1abe Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Fri, 3 Jul 2026 18:22:55 +0200
+Subject: [PATCH] transport: fix potential heap overflow on ETM decrypt
+
+Reported-by: Vladimir Eli Tokarev
+Fixes GHSA-6c79-444r-wx26
+
+Closes #2198
+
+Backport adaptations:
+- The upstream fix uses SSH2_SAFEFREE() to safely release allocated
+ memory and reset the pointer. Since SSH2_SAFEFREE() is not available
+ in libssh2 1.11.1, replace its usage with the equivalent NULL check,
+ LIBSSH2_FREE(), and pointer reset sequence.
+- The upstream fix renames decrypt() to transport_decrypt(). Since this
+ rename is not present in libssh2 1.11.1, retain the original
+ decrypt() function name.
+
+CVE: CVE-2026-66035
+Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/transport.c | 12 +++++++++++-
+ 1 file changed, 11 insertions(+), 1 deletion(-)
+
+diff --git a/src/transport.c b/src/transport.c
+index d147505b..9f386e75 100644
+--- a/src/transport.c
++++ b/src/transport.c
+@@ -242,6 +242,17 @@ fullpacket(LIBSSH2_SESSION * session, int encrypted /* 1 or 0 */ )
+ unsigned char *decrypt_buffer;
+ int blocksize = session->remote.crypt->blocksize;
+
++ if(p->total_num < mac_len + 4 + (size_t)blocksize) {
++ if(p->payload) {
++ LIBSSH2_FREE(session, p->payload);
++ p->payload = NULL;
++ }
++ return LIBSSH2_ERROR_DECRYPT;
++ }
++ decrypt_size = (ssize_t)(p->total_num - mac_len - 4);
++
++ first_block[0] = 0;
++
+ rc = decrypt(session, p->payload + 4,
+ first_block, blocksize, FIRST_BLOCK);
+ if(rc) {
+@@ -249,7 +260,6 @@ fullpacket(LIBSSH2_SESSION * session, int encrypted /* 1 or 0 */ )
+ }
+
+ /* we need buffer for decrypt */
+- decrypt_size = p->total_num - mac_len - 4;
+ decrypt_buffer = LIBSSH2_ALLOC(session, decrypt_size);
+ if(!decrypt_buffer) {
+ return LIBSSH2_ERROR_ALLOC;
diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
index 54022aa879..dad363cac5 100644
--- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb
+++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
@@ -18,6 +18,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
file://CVE-2025-15661-3.patch \
file://CVE-2026-66033.patch \
file://CVE-2026-66034.patch \
+ file://CVE-2026-66035.patch \
"
SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"
^ permalink raw reply related [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-03 8:42 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-03 8:41 [wrynose][PATCH 0/3] libssh2: fix CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 1/3] libssh2: fix CVE-2026-66033 Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 2/3] libssh2: fix CVE-2026-66034 Jaipaul Cheernam
2026-08-03 8:41 ` [wrynose][PATCH 3/3] libssh2: fix CVE-2026-66035 Jaipaul Cheernam
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox