From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-devel@lists.openembedded.org
Subject: Re: [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
Date: Tue, 01 Sep 2026 01:23:55 -0700 [thread overview]
Message-ID: <2992798.1788251035800302150@lists.openembedded.org> (raw)
In-Reply-To: <CA+s=J=wUKLeAd2UNi-krDvXyyQG73H_XXcm9oLU4D1jQeTwf8Q@mail.gmail.com>
[-- Attachment #1: Type: text/plain, Size: 1811 bytes --]
On Tue, Sep 1, 2026 at 07:07 AM, Anuj Mittal wrote:
>
> On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
> PRIVATE LIMITED at Cisco) via lists.openembedded.org
> <hthakar=cisco.com@lists.openembedded.org> wrote:
>
>> From: Hetvi Thakar <hthakar@cisco.com>
>>
>> Backport five upstream libssh security fixes to the 0.10.6 recipe on
>> scarthgap:
>>
>> - CVE-2026-59843
>> - CVE-2026-59844
>> - CVE-2026-59846
>> - CVE-2026-59848
>> - CVE-2026-59850
>>
>> Carry these as focused backports instead of upgrading libssh because
>> newer releases include API and functional changes outside the security
>> scope.
>>
>> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
>> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
>> code or features absent from 0.10.6. NVD correction requests have been
>> submitted for these inaccurate affected-version entries; therefore, no
>> CVE_STATUS entries are added.
>>
>> The individual commits retain the upstream fix provenance and advisory
>> references for each CVE.
>>
>> Testing:
>> - Applied all five patches to libssh 0.10.6 in series order without
>> conflicts or fuzz.
>> - Package build completed successfully.
>>
>> Hetvi Thakar (5):
>> libssh: Fix CVE-2026-59843
>> libssh: Fix CVE-2026-59844
>> libssh: Fix CVE-2026-59846
>> libssh: Fix CVE-2026-59848
>> libssh: Fix CVE-2026-59850
>
> 3/5 is adding unresolved merge markers to recipe that 4/5 is then
> removing. Please fix the patches, rebase them on current scarthgap and
> resend.
>
> Thanks,
>
> Anuj
Hi,
Thanks for pointing this out.
I will fix the unresolved merge markers, rebase the patch series on
the current scarthgap branch, and resend the updated series.
Regards,
Hetvi
[-- Attachment #2: Type: text/html, Size: 2109 bytes --]
prev parent reply other threads:[~2026-09-01 8:24 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2992798.1788251035800302150@lists.openembedded.org \
--to=hthakar@cisco.com \
--cc=openembedded-devel@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox