On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
PRIVATE LIMITED at Cisco) via lists.openembedded.org
<hthakar=cisco.com@lists.openembedded.org> wrote:
From: Hetvi Thakar <hthakar@cisco.com>3/5 is adding unresolved merge markers to recipe that 4/5 is then
Backport five upstream libssh security fixes to the 0.10.6 recipe on
scarthgap:
- CVE-2026-59843
- CVE-2026-59844
- CVE-2026-59846
- CVE-2026-59848
- CVE-2026-59850
Carry these as focused backports instead of upgrading libssh because
newer releases include API and functional changes outside the security
scope.
CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
code or features absent from 0.10.6. NVD correction requests have been
submitted for these inaccurate affected-version entries; therefore, no
CVE_STATUS entries are added.
The individual commits retain the upstream fix provenance and advisory
references for each CVE.
Testing:
- Applied all five patches to libssh 0.10.6 in series order without
conflicts or fuzz.
- Package build completed successfully.
Hetvi Thakar (5):
libssh: Fix CVE-2026-59843
libssh: Fix CVE-2026-59844
libssh: Fix CVE-2026-59846
libssh: Fix CVE-2026-59848
libssh: Fix CVE-2026-59850
removing. Please fix the patches, rebase them on current scarthgap and
resend.
Thanks,
Anuj
Hi,
Thanks for pointing this out.
I will fix the unresolved merge markers, rebase the patch series on
the current scarthgap branch, and resend the updated series.
Regards,
Hetvi