On Tue, Sep 1, 2026 at 07:07 AM, Anuj Mittal wrote:
On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
PRIVATE LIMITED at Cisco) via lists.openembedded.org
<hthakar=cisco.com@lists.openembedded.org> wrote:
From: Hetvi Thakar <hthakar@cisco.com>

Backport five upstream libssh security fixes to the 0.10.6 recipe on
scarthgap:

- CVE-2026-59843
- CVE-2026-59844
- CVE-2026-59846
- CVE-2026-59848
- CVE-2026-59850

Carry these as focused backports instead of upgrading libssh because
newer releases include API and functional changes outside the security
scope.

CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
code or features absent from 0.10.6. NVD correction requests have been
submitted for these inaccurate affected-version entries; therefore, no
CVE_STATUS entries are added.

The individual commits retain the upstream fix provenance and advisory
references for each CVE.

Testing:
- Applied all five patches to libssh 0.10.6 in series order without
conflicts or fuzz.
- Package build completed successfully.

Hetvi Thakar (5):
libssh: Fix CVE-2026-59843
libssh: Fix CVE-2026-59844
libssh: Fix CVE-2026-59846
libssh: Fix CVE-2026-59848
libssh: Fix CVE-2026-59850
3/5 is adding unresolved merge markers to recipe that 4/5 is then
removing. Please fix the patches, rebase them on current scarthgap and
resend.

Thanks,

Anuj

Hi,

Thanks for pointing this out.

I will fix the unresolved merge markers, rebase the patch series on
the current scarthgap branch, and resend the updated series.

Regards,
Hetvi