From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-devel@lists.openembedded.org
Cc: xe-linux-external@cisco.com, Hetvi Thakar <hthakar@cisco.com>
Subject: [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
Date: Wed, 19 Aug 2026 04:10:42 -0700 [thread overview]
Message-ID: <20260819111047.44043-1-hthakar@cisco.com> (raw)
From: Hetvi Thakar <hthakar@cisco.com>
Backport five upstream libssh security fixes to the 0.10.6 recipe on
scarthgap:
- CVE-2026-59843
- CVE-2026-59844
- CVE-2026-59846
- CVE-2026-59848
- CVE-2026-59850
Carry these as focused backports instead of upgrading libssh because
newer releases include API and functional changes outside the security
scope.
CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
code or features absent from 0.10.6. NVD correction requests have been
submitted for these inaccurate affected-version entries; therefore, no
CVE_STATUS entries are added.
The individual commits retain the upstream fix provenance and advisory
references for each CVE.
Testing:
- Applied all five patches to libssh 0.10.6 in series order without
conflicts or fuzz.
- Package build completed successfully.
Hetvi Thakar (5):
libssh: Fix CVE-2026-59843
libssh: Fix CVE-2026-59844
libssh: Fix CVE-2026-59846
libssh: Fix CVE-2026-59848
libssh: Fix CVE-2026-59850
.../libssh/libssh/CVE-2026-59843.patch | 84 +++
.../libssh/libssh/CVE-2026-59844.patch | 52 ++
.../libssh/libssh/CVE-2026-59846.patch | 87 +++
.../libssh/CVE-2026-59848-regression.patch | 45 ++
.../libssh/libssh/CVE-2026-59848.patch | 684 ++++++++++++++++++
.../libssh/libssh/CVE-2026-59850.patch | 40 +
.../recipes-support/libssh/libssh_0.10.6.bb | 6 +
7 files changed, 998 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
--
2.35.6
next reply other threads:[~2026-08-19 11:10 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 11:10 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260819111047.44043-1-hthakar@cisco.com \
--to=hthakar@cisco.com \
--cc=openembedded-devel@lists.openembedded.org \
--cc=xe-linux-external@cisco.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox