* [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
@ 2026-08-19 11:10 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (5 more replies)
0 siblings, 6 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
Backport five upstream libssh security fixes to the 0.10.6 recipe on
scarthgap:
- CVE-2026-59843
- CVE-2026-59844
- CVE-2026-59846
- CVE-2026-59848
- CVE-2026-59850
Carry these as focused backports instead of upgrading libssh because
newer releases include API and functional changes outside the security
scope.
CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
code or features absent from 0.10.6. NVD correction requests have been
submitted for these inaccurate affected-version entries; therefore, no
CVE_STATUS entries are added.
The individual commits retain the upstream fix provenance and advisory
references for each CVE.
Testing:
- Applied all five patches to libssh 0.10.6 in series order without
conflicts or fuzz.
- Package build completed successfully.
Hetvi Thakar (5):
libssh: Fix CVE-2026-59843
libssh: Fix CVE-2026-59844
libssh: Fix CVE-2026-59846
libssh: Fix CVE-2026-59848
libssh: Fix CVE-2026-59850
.../libssh/libssh/CVE-2026-59843.patch | 84 +++
.../libssh/libssh/CVE-2026-59844.patch | 52 ++
.../libssh/libssh/CVE-2026-59846.patch | 87 +++
.../libssh/CVE-2026-59848-regression.patch | 45 ++
.../libssh/libssh/CVE-2026-59848.patch | 684 ++++++++++++++++++
.../libssh/libssh/CVE-2026-59850.patch | 40 +
.../recipes-support/libssh/libssh_0.10.6.bb | 6 +
7 files changed, 998 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
--
2.35.6
^ permalink raw reply [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (4 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59843 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919
[2] https://www.libssh.org/security/advisories/CVE-2026-59843.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59843.patch | 84 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 1 +
2 files changed, 85 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
new file mode 100644
index 0000000000..03d3ce6ea2
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
@@ -0,0 +1,84 @@
+From d965eb941a9a83a0643570a93d8997b91e248fc1 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Fri, 6 Mar 2026 13:58:30 +0100
+Subject: [PATCH] CVE-2026-59843 channels: Fail when receiving max packet size
+ 0
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Do this both for SSH2_MSG_CHANNEL_OPEN and for
+SSH2_MSG_CHANNEL_OPEN_CONFIRMATION. Using the
+max packet size 0 would lead to an infinite loop
+in channel_write_common.
+
+Originally reported by Rinku Das on on 23th February.
+Independently reported by Yi Lin on 26th February and
+Haruto Kimura on 22nd March.
+
+We do not consider this as a security issue as connecting
+to untrusted servers on the internet brings much worse
+security consequences than hanging your clinet.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59843
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919]
+
+(cherry picked from commit 44b186fa17aff497dae420c59c003222e438103c)
+(cherry picked from commit 687ef1c44b646b9db0b1c6e8f987edb7c9e4d919)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/channels.c | 7 +++++++
+ src/messages.c | 19 +++++++++++++++----
+ 2 files changed, 22 insertions(+), 4 deletions(-)
+
+diff --git a/src/channels.c b/src/channels.c
+index 8290dbd1..3afdcf11 100644
+--- a/src/channels.c
++++ b/src/channels.c
+@@ -192,6 +192,13 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open_conf){
+ if (rc != SSH_OK)
+ goto error;
+
++ if (channel->remote_maxpacket == 0) {
++ SSH_LOG(SSH_LOG_RARE,
++ "Invalid maximum packet size 0 in "
++ "SSH2_MSG_CHANNEL_OPEN_CONFIRMATION");
++ goto error;
++ }
++
+ SSH_LOG(SSH_LOG_PROTOCOL,
+ "Received a CHANNEL_OPEN_CONFIRMATION for channel %d:%d",
+ channel->local_channel,
+diff --git a/src/messages.c b/src/messages.c
+index 6dadabf0..e79ecec2 100644
+--- a/src/messages.c
++++ b/src/messages.c
+@@ -1160,10 +1160,21 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open){
+ SSH_LOG(SSH_LOG_PACKET,
+ "Clients wants to open a %s channel", type_c);
+
+- ssh_buffer_unpack(packet,"ddd",
+- &msg->channel_request_open.sender,
+- &msg->channel_request_open.window,
+- &msg->channel_request_open.packet_size);
++ rc = ssh_buffer_unpack(packet,
++ "ddd",
++ &msg->channel_request_open.sender,
++ &msg->channel_request_open.window,
++ &msg->channel_request_open.packet_size);
++ if (rc != SSH_OK){
++ goto error;
++ }
++
++ if (msg->channel_request_open.packet_size == 0) {
++ ssh_set_error(session,
++ SSH_FATAL,
++ "Invalid maximum packet size 0 in SSH2_MSG_CHANNEL_OPEN");
++ goto error;
++ }
+
+ if (session->session_state != SSH_SESSION_STATE_AUTHENTICATED){
+ ssh_set_error(session,SSH_FATAL, "Invalid state when receiving channel open request (must be authenticated)");
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 1f64920a50..381b3efc7d 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -32,6 +32,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0968-2.patch \
file://CVE-2026-0967.patch \
file://CVE-2026-0965.patch \
+ file://CVE-2026-59843.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (3 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59844 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9
[2] https://www.libssh.org/security/advisories/CVE-2026-59844.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59844.patch | 52 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 1 +
2 files changed, 53 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
new file mode 100644
index 0000000000..ac380622d9
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
@@ -0,0 +1,52 @@
+From ef7cd6d4aef6d18ca8bf15cb0398b630284f46f4 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Fri, 6 Mar 2026 18:05:29 +0100
+Subject: [PATCH] CVE-2026-59844 sftpserver: cap accepted values of len in
+ SSH_FXP_READ
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The client-provided length is directly used in
+a malloc in process_read(), so not restricting it
+leads to allocations bounded only by UINT32_MAX.
+
+The new cap is the same as the one currently used
+by OpenSSH.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59844
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9]
+
+Backport Changes:
+- Replace the upstream goto error path with equivalent direct message cleanup
+ and return because libssh 0.10.6 does not have the refactored
+ sftp_make_client_message() error label.
+
+(cherry picked from commit 6dba2e06f0713c04ad5eca7d4315d0104be7e627)
+(cherry picked from commit e31f06e5380be4e714d5ad6965981fbf30738da9)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/sftpserver.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/sftpserver.c b/src/sftpserver.c
+index 528ef6f9..77290068 100644
+--- a/src/sftpserver.c
++++ b/src/sftpserver.c
+@@ -105,6 +105,13 @@ sftp_client_message sftp_get_client_message(sftp_session sftp) {
+ sftp_client_message_free(msg);
+ return NULL;
+ }
++ if (msg->len > MAX_PACKET_LEN - 1024) {
++ ssh_set_error(sftp->session, SSH_FATAL,
++ "Too large SSH_FXP_READ length: %" PRIu32,
++ msg->len);
++ sftp_client_message_free(msg);
++ return NULL;
++ }
+ break;
+ case SSH_FXP_WRITE:
+ rc = ssh_buffer_unpack(payload,
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 381b3efc7d..a9d7729f2c 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -33,6 +33,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0967.patch \
file://CVE-2026-0965.patch \
file://CVE-2026-59843.patch \
+ file://CVE-2026-59844.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (2 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
libssh 0.10.6 predates the username-validation helper used by the
stable-0.11 fix, so the upstream commit in [1] cannot be applied as-is.
Adapt the same dangerous-character check directly at the ProxyCommand %r
expansion sink and add focused regression coverage.
The upstream advisory [2] identifies libssh 0.11.5 and 0.12.1 as the
fixed releases.
[1] https://gitlab.com/libssh/libssh-mirror/-/commit/56ce3c193eb06af5bf3b07ec0b4c7308b5c72130
[2] https://www.libssh.org/security/advisories/CVE-2026-59846.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59846.patch | 87 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 5 ++
2 files changed, 92 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
new file mode 100644
index 0000000000..9c626d113d
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
@@ -0,0 +1,87 @@
+From 19fe4c9fc7b3bd3553250bf9ddea03ed1dcf044f Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Thu, 2 Apr 2026 15:39:25 +0200
+Subject: [PATCH] CVE-2026-59846 Block shell metacharacters from usernames
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+When an attacker could sneak the dollar sign or backslash into the username
+expanded for example in proxy command, it can result in printing environment
+variables that might contain secrets.
+
+This is a fixup of CVE-2023-6004 which fixed this for hostnames, but these
+two metacharacters were left out from the username filter.
+
+This keeps the list in one place to simplify maintenance.
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+(cherry picked from commit 6309df220e3431deb41946f892f4bb5af8b59dba)
+
+CVE: CVE-2026-59846
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=56ce3c193eb06af5bf3b07ec0b4c7308b5c72130]
+
+Backport Changes:
+- libssh 0.10.6 predates ssh_check_username_syntax() and the centralized
+ SSH_DANGEROUS_SHELL_CHARS definition, so enforce the same character list
+ directly at the %r expansion sink in ssh_path_expand_escape().
+- Add focused regression coverage to the existing path-expansion unit test
+ for dollar-sign, backslash, and command-separator usernames.
+
+(cherry picked from commit 56ce3c193eb06af5bf3b07ec0b4c7308b5c72130)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/misc.c | 9 +++++++++
+ tests/unittests/torture_misc.c | 18 ++++++++++++++++++
+ 2 files changed, 27 insertions(+)
+
+diff --git a/src/misc.c b/src/misc.c
+index e78c92ba..15b427d7 100644
+--- a/src/misc.c
++++ b/src/misc.c
+@@ -1262,6 +1262,15 @@ char *ssh_path_expand_escape(ssh_session session, const char *s)
+ break;
+ case 'r':
+ if (session->opts.username) {
++ if (strpbrk(session->opts.username,
++ "'`\";&<>|(){}$\\,") != NULL) {
++ ssh_set_error(session,
++ SSH_FATAL,
++ "Invalid shell metacharacter in username");
++ free(buf);
++ free(r);
++ return NULL;
++ }
+ x = strdup(session->opts.username);
+ } else {
+ ssh_set_error(session, SSH_FATAL,
+diff --git a/tests/unittests/torture_misc.c b/tests/unittests/torture_misc.c
+index 82d6cf16..66d392ed 100644
+--- a/tests/unittests/torture_misc.c
++++ b/tests/unittests/torture_misc.c
+@@ -194,6 +194,24 @@ static void torture_path_expand_escape(void **state) {
+ assert_non_null(e);
+ assert_string_equal(e, "guru/meditation/222/by/root");
+ ssh_string_free_char(e);
++
++ free(session->opts.username);
++ session->opts.username = strdup("root$HOME");
++ assert_non_null(session->opts.username);
++ e = ssh_path_expand_escape(session, s);
++ assert_null(e);
++
++ free(session->opts.username);
++ session->opts.username = strdup("root\\user");
++ assert_non_null(session->opts.username);
++ e = ssh_path_expand_escape(session, s);
++ assert_null(e);
++
++ free(session->opts.username);
++ session->opts.username = strdup("root;id");
++ assert_non_null(session->opts.username);
++ e = ssh_path_expand_escape(session, s);
++ assert_null(e);
+ }
+
+ static void torture_path_expand_known_hosts(void **state) {
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index a9d7729f2c..8e86073fd3 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -34,6 +34,11 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0965.patch \
file://CVE-2026-59843.patch \
file://CVE-2026-59844.patch \
+<<<<<<< HEAD
+=======
+ file://CVE-2026-59845.patch \
+ file://CVE-2026-59846.patch \
+>>>>>>> b782f294a0 (libssh: Fix CVE-2026-59846)
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (2 preceding siblings ...)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the primary upstream fix selected
for this backport. Commit [2] corrects the request-queue pointer state
introduced by [1], so it is carried immediately afterward as a regression
fix. The upstream advisory [3] documents CVE-2026-59848 and identifies
libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497
[2] https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be
[3] https://www.libssh.org/security/advisories/CVE-2026-59848.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/CVE-2026-59848-regression.patch | 45 ++
.../libssh/libssh/CVE-2026-59848.patch | 684 ++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 6 +-
3 files changed, 731 insertions(+), 4 deletions(-)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
new file mode 100644
index 0000000000..161271264f
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
@@ -0,0 +1,45 @@
+From dddd93ac995ac382e4ec9496509f24003bd72c30 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Wed, 3 Jun 2026 12:56:09 +0200
+Subject: [PATCH] CVE-2026-59848 sftp: Initialize sftp_request_queue ptr in
+ sftp_free
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59848
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be]
+
+Backport Changes:
+- Adjusted hunk context for the consolidated libssh 0.10.6 SFTP
+ implementation; the pointer initialization is unchanged from upstream.
+- Omitted the upstream tests/client/torture_sftp_request_id.c follow-up hunk
+ because CVE-2026-59848.patch introduces the backported regression test
+ directly with sftp_read_and_dispatch(); there is no intermediate
+ sftp_recv_response_msg() version to update.
+
+(cherry picked from commit 00876f7658fd265682708572122502188fa22076)
+(cherry picked from commit 5309aefd99e1775db40bf20869f1fb1cc6c787be)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/sftp.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/sftp.c b/src/sftp.c
+index e6755e2b..ff6e5200 100644
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -371,7 +371,7 @@ void sftp_server_free(sftp_session sftp)
+
+ void sftp_free(sftp_session sftp)
+ {
+- sftp_request_queue ptr;
++ sftp_request_queue ptr = NULL;
+ struct ssh_iterator *id_it = NULL;
+
+ if (sftp == NULL) {
+--
+2.35.6
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
new file mode 100644
index 0000000000..2f4efb22f1
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
@@ -0,0 +1,684 @@
+From ef75e652dd2808c27251da4d03feef84d158c1de Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Mon, 1 Jun 2026 16:33:03 +0200
+Subject: [PATCH] CVE-2026-59848 sftp: handle responses with unknown request
+ IDs
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+This adds a new field to sftp_session_struct,
+containing a list of outstanding request IDs.
+An ID is added to the list when a request
+is constructed and removed when the corresponding
+request is received. If a client receives a response
+with an unknown request ID, it reports an error.
+
+Storing responses with unknown request IDs in
+the response queue could be abused by a malicious
+SFTP server which could deplete client memory
+this way.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59848
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497]
+
+Backport Changes:
+- Consolidated the upstream src/sftp_common.c and src/sftp_aio.c changes
+ into src/sftp.c, where libssh 0.10.6 implements response dispatch,
+ request-ID allocation, and asynchronous SFTP reads.
+- Kept sftp_get_new_id() static instead of exporting it through
+ sftp_priv.h because all 20 request-producing call sites in 0.10.6 are
+ in src/sftp.c; newer-only SFTP API call sites are absent.
+- Retained the 0.10.6 request construction order and free the existing
+ request buffer when request-ID tracking fails.
+- Adapted the unknown-ID regression test to call
+ sftp_read_and_dispatch() and verify the response queue remains empty;
+ 0.10.6 does not provide sftp_recv_response_msg().
+
+(cherry picked from commit 26147eb4767937c797f97ff3b1b1663384232417)
+(cherry picked from commit a30a51003205744c10ba4439306f555206ae8497)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ include/libssh/sftp.h | 1 +
+ src/sftp.c | 210 ++++++++++++++++++++++---
+ tests/client/CMakeLists.txt | 1 +
+ tests/client/torture_sftp_request_id.c | 183 +++++++++++++++++++++
+ 4 files changed, 369 insertions(+), 26 deletions(-)
+ create mode 100644 tests/client/torture_sftp_request_id.c
+
+diff --git a/include/libssh/sftp.h b/include/libssh/sftp.h
+index c713466e..984c4eb7 100644
+--- a/include/libssh/sftp.h
++++ b/include/libssh/sftp.h
+@@ -90,6 +90,7 @@ struct sftp_session_struct {
+ void **handles;
+ sftp_ext ext;
+ sftp_packet read_packet;
++ struct ssh_list *outstanding_ids;
+ };
+
+ struct sftp_packet_struct {
+diff --git a/src/sftp.c b/src/sftp.c
+index 2194a9ef..e6755e2b 100644
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -149,6 +149,12 @@ sftp_session sftp_new(ssh_session session)
+ goto error;
+ }
+
++ sftp->outstanding_ids = ssh_list_new();
++ if (sftp->outstanding_ids == NULL) {
++ ssh_set_error_oom(session);
++ goto error;
++ }
++
+ if (ssh_channel_open_session(sftp->channel)) {
+ goto error;
+ }
+@@ -165,6 +171,7 @@ error:
+ if (sftp->channel != NULL) {
+ ssh_channel_free(sftp->channel);
+ }
++ ssh_list_free(sftp->outstanding_ids);
+ if (sftp->read_packet != NULL) {
+ if (sftp->read_packet->payload != NULL) {
+ SSH_BUFFER_FREE(sftp->read_packet->payload);
+@@ -196,6 +203,12 @@ sftp_new_channel(ssh_session session, ssh_channel channel)
+ goto error;
+ }
+
++ sftp->outstanding_ids = ssh_list_new();
++ if (sftp->outstanding_ids == NULL) {
++ ssh_set_error_oom(session);
++ goto error;
++ }
++
+ sftp->read_packet = calloc(1, sizeof(struct sftp_packet_struct));
+ if (sftp->read_packet == NULL) {
+ ssh_set_error_oom(session);
+@@ -217,6 +230,7 @@ error:
+ if (sftp->ext != NULL) {
+ sftp_ext_free(sftp->ext);
+ }
++ ssh_list_free(sftp->outstanding_ids);
+ if (sftp->read_packet != NULL) {
+ if (sftp->read_packet->payload != NULL) {
+ SSH_BUFFER_FREE(sftp->read_packet->payload);
+@@ -358,6 +372,7 @@ void sftp_server_free(sftp_session sftp)
+ void sftp_free(sftp_session sftp)
+ {
+ sftp_request_queue ptr;
++ struct ssh_iterator *id_it = NULL;
+
+ if (sftp == NULL) {
+ return;
+@@ -384,6 +399,12 @@ void sftp_free(sftp_session sftp)
+
+ sftp_ext_free(sftp->ext);
+
++ id_it = ssh_list_get_iterator(sftp->outstanding_ids);
++ for (; id_it != NULL; id_it = id_it->next) {
++ free((uint32_t *)id_it->data);
++ }
++ ssh_list_free(sftp->outstanding_ids);
++
+ SAFE_FREE(sftp);
+ }
+
+@@ -571,6 +592,8 @@ static sftp_message sftp_get_message(sftp_packet packet)
+ {
+ sftp_session sftp = packet->sftp;
+ sftp_message msg = NULL;
++ struct ssh_iterator *id_it = NULL;
++ bool id_found = false;
+ int rc;
+
+ switch(packet->type) {
+@@ -618,6 +641,28 @@ static sftp_message sftp_get_message(sftp_packet packet)
+ msg->id,
+ msg->packet_type);
+
++ /* Validate that this ID is in our outstanding requests list */
++ id_it = ssh_list_get_iterator(sftp->outstanding_ids);
++ for (; id_it != NULL; id_it = id_it->next) {
++ uint32_t *stored_id = (uint32_t *)id_it->data;
++ if (*stored_id == msg->id) {
++ id_found = true;
++ ssh_list_remove(sftp->outstanding_ids, id_it);
++ free(stored_id);
++ break;
++ }
++ }
++
++ if (!id_found) {
++ ssh_set_error(packet->sftp->session,
++ SSH_FATAL,
++ "Unknown request ID %" PRIu32,
++ msg->id);
++ sftp_message_free(msg);
++ sftp_set_error(packet->sftp, SSH_FX_FAILURE);
++ return NULL;
++ }
++
+ return msg;
+ }
+
+@@ -902,13 +947,46 @@ static sftp_message sftp_dequeue(sftp_session sftp, uint32_t id){
+ return NULL;
+ }
+
+-/*
+- * Assigns a new SFTP ID for new requests and assures there is no collision
+- * between them.
+- * Returns a new ID ready to use in a request
++/**
++ * @brief Assigns a new SFTP ID for new requests and assures there is no
++ * collision between them.
++ *
++ * @param sftp The sftp session handle.
++ * @param id_out Pointer to store the new ID.
++ *
++ * @returns SSH_OK on success with the new ID stored in *id
++ * @returns SSH_ERROR on failure with the sftp and ssh errors set
+ */
+-static inline uint32_t sftp_get_new_id(sftp_session session) {
+- return ++session->id_counter;
++static int sftp_get_new_id(sftp_session sftp, uint32_t *id_out)
++{
++ uint32_t *id = NULL;
++ int rc;
++
++ if (id_out == NULL) {
++ ssh_set_error_invalid(sftp->session);
++ sftp_set_error(sftp, SSH_FX_FAILURE);
++ return SSH_ERROR;
++ }
++
++ id = malloc(sizeof(uint32_t));
++ if (id == NULL) {
++ ssh_set_error_oom(sftp->session);
++ sftp_set_error(sftp, SSH_FX_FAILURE);
++ return SSH_ERROR;
++ }
++
++ *id = ++sftp->id_counter;
++ rc = ssh_list_append(sftp->outstanding_ids, id);
++ if (rc != SSH_OK) {
++ free(id);
++ ssh_set_error_oom(sftp->session);
++ sftp_set_error(sftp, SSH_FX_FAILURE);
++ return SSH_ERROR;
++ }
++
++ *id_out = *id;
++
++ return SSH_OK;
+ }
+
+ static sftp_status_message parse_status_msg(sftp_message msg){
+@@ -1029,7 +1107,11 @@ sftp_dir sftp_opendir(sftp_session sftp, const char *path)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(payload);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(payload,
+ "ds",
+@@ -1571,7 +1653,11 @@ sftp_attributes sftp_readdir(sftp_session sftp, sftp_dir dir)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(payload);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(payload,
+ "dS",
+@@ -1704,7 +1790,11 @@ static int sftp_handle_close(sftp_session sftp, ssh_string handle)
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dS",
+@@ -1835,7 +1925,11 @@ sftp_file sftp_open(sftp_session sftp,
+ sftp_flags |= SSH_FXF_APPEND;
+ }
+ SSH_LOG(SSH_LOG_PACKET,"Opening file %s with sftp flags %x",file,sftp_flags);
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dsd",
+@@ -1946,7 +2040,11 @@ ssize_t sftp_read(sftp_file handle, void *buf, size_t count) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(handle->sftp);
++ rc = sftp_get_new_id(handle->sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dSqd",
+@@ -2047,7 +2145,11 @@ int sftp_async_read_begin(sftp_file file, uint32_t len){
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dSqd",
+@@ -2173,7 +2275,11 @@ ssize_t sftp_write(sftp_file file, const void *buf, size_t count) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(file->sftp);
++ rc = sftp_get_new_id(file->sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dSqdP",
+@@ -2291,7 +2397,11 @@ int sftp_unlink(sftp_session sftp, const char *file) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2366,7 +2476,11 @@ int sftp_rmdir(sftp_session sftp, const char *directory) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2443,7 +2557,11 @@ int sftp_mkdir(sftp_session sftp, const char *directory, mode_t mode)
+ attr.permissions = mode;
+ attr.flags = SSH_FILEXFER_ATTR_PERMISSIONS;
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2538,7 +2656,11 @@ int sftp_rename(sftp_session sftp, const char *original, const char *newname) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dss",
+@@ -2622,7 +2744,11 @@ int sftp_setstat(sftp_session sftp, const char *file, sftp_attributes attr)
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2752,7 +2878,11 @@ int sftp_symlink(sftp_session sftp, const char *target, const char *dest) {
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ /* TODO check for version number if they ever fix it. */
+ if (ssh_get_openssh_version(sftp->session)) {
+@@ -2850,7 +2980,11 @@ char *sftp_readlink(sftp_session sftp, const char *path)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -2976,7 +3110,11 @@ sftp_statvfs_t sftp_statvfs(sftp_session sftp, const char *path)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dss",
+@@ -3051,7 +3189,11 @@ int sftp_fsync(sftp_file file)
+ return -1;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return -1;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dsS",
+@@ -3151,7 +3293,11 @@ sftp_statvfs_t sftp_fstatvfs(sftp_file file)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dsS",
+@@ -3238,7 +3384,11 @@ char *sftp_canonicalize_path(sftp_session sftp, const char *path)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -3329,7 +3479,11 @@ static sftp_attributes sftp_xstat(sftp_session sftp,
+ return NULL;
+ }
+
+- id = sftp_get_new_id(sftp);
++ rc = sftp_get_new_id(sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "ds",
+@@ -3407,7 +3561,11 @@ sftp_attributes sftp_fstat(sftp_file file)
+ return NULL;
+ }
+
+- id = sftp_get_new_id(file->sftp);
++ rc = sftp_get_new_id(file->sftp, &id);
++ if (rc != SSH_OK) {
++ SSH_BUFFER_FREE(buffer);
++ return NULL;
++ }
+
+ rc = ssh_buffer_pack(buffer,
+ "dS",
+diff --git a/tests/client/CMakeLists.txt b/tests/client/CMakeLists.txt
+index 71e5182e..864478a7 100644
+--- a/tests/client/CMakeLists.txt
++++ b/tests/client/CMakeLists.txt
+@@ -49,6 +49,7 @@ if (WITH_SFTP)
+ torture_sftp_dir
+ torture_sftp_read
+ torture_sftp_fsync
++ torture_sftp_request_id
+ ${SFTP_BENCHMARK_TESTS})
+ endif (WITH_SFTP)
+
+diff --git a/tests/client/torture_sftp_request_id.c b/tests/client/torture_sftp_request_id.c
+new file mode 100644
+index 00000000..fe6d3f91
+--- /dev/null
++++ b/tests/client/torture_sftp_request_id.c
+@@ -0,0 +1,183 @@
++#include "config.h"
++
++#define LIBSSH_STATIC
++
++#include "sftp.c"
++#include "torture.h"
++
++#include <pwd.h>
++#include <sys/types.h>
++
++static int sshd_setup(void **state)
++{
++ torture_setup_sshd_server(state, false);
++
++ return 0;
++}
++
++static int sshd_teardown(void **state)
++{
++ torture_teardown_sshd_server(state);
++
++ return 0;
++}
++
++static int session_setup(void **state)
++{
++ struct torture_state *s = *state;
++ struct passwd *pwd = NULL;
++ int rc;
++
++ pwd = getpwnam("bob");
++ assert_non_null(pwd);
++
++ rc = setuid(pwd->pw_uid);
++ assert_return_code(rc, errno);
++
++ s->ssh.session = torture_ssh_session(s,
++ TORTURE_SSH_SERVER,
++ NULL,
++ TORTURE_SSH_USER_ALICE,
++ NULL);
++ assert_non_null(s->ssh.session);
++
++ s->ssh.tsftp = torture_sftp_session(s->ssh.session);
++ assert_non_null(s->ssh.tsftp);
++
++ return 0;
++}
++
++static int session_teardown(void **state)
++{
++ struct torture_state *s = *state;
++
++ torture_rmdirs(s->ssh.tsftp->testdir);
++ torture_sftp_close(s->ssh.tsftp);
++ ssh_disconnect(s->ssh.session);
++ ssh_free(s->ssh.session);
++
++ return 0;
++}
++
++static void torture_sftp_request_id_null(void **state)
++{
++ struct torture_state *s = *state;
++ struct torture_sftp *t = s->ssh.tsftp;
++ sftp_session sftp = t->sftp;
++ int rc;
++
++ rc = sftp_get_new_id(sftp, NULL);
++ assert_int_equal(rc, SSH_ERROR);
++}
++
++static void torture_sftp_request_id_add(void **state)
++{
++ struct torture_state *s = *state;
++ struct torture_sftp *t = s->ssh.tsftp;
++ sftp_session sftp = t->sftp;
++ uint32_t id1, id2;
++ int rc;
++ size_t count;
++
++ /* The list of IDs should be empty at first */
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 0);
++
++ /* Request a new ID */
++ rc = sftp_get_new_id(sftp, &id1);
++ assert_int_equal(rc, SSH_OK);
++
++ /* Check that the list has one ID now */
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 1);
++
++ /* Request another ID */
++ rc = sftp_get_new_id(sftp, &id2);
++ assert_int_equal(rc, SSH_OK);
++
++ /* Check that the IDs differ */
++ assert_int_not_equal(id1, id2);
++
++ /* Check that the list has two IDs now */
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 2);
++}
++
++static void torture_sftp_request_id_remove(void **state)
++{
++ struct torture_state *s = *state;
++ struct torture_sftp *t = s->ssh.tsftp;
++ sftp_session sftp = t->sftp;
++ sftp_attributes attr = NULL;
++ size_t count;
++
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 0);
++
++ /* We send a request and receive a response */
++ attr = sftp_stat(sftp, SSH_EXECUTABLE);
++ assert_non_null(attr);
++
++ /* The number of outstanding requests should be back to 0 */
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 0);
++
++ sftp_attributes_free(attr);
++}
++
++static void torture_sftp_request_id_unknown(void **state)
++{
++ struct torture_state *s = *state;
++ struct torture_sftp *t = s->ssh.tsftp;
++ sftp_session sftp = t->sftp;
++ ssh_buffer buffer = NULL;
++ uint32_t id = 0;
++ int rc;
++ size_t count;
++
++ count = ssh_list_count(sftp->outstanding_ids);
++ assert_int_equal(count, 0);
++
++ buffer = ssh_buffer_new();
++ assert_non_null(buffer);
++
++ rc = ssh_buffer_pack(buffer, "ds", id, "/tmp");
++ assert_int_equal(rc, SSH_OK);
++
++ /* Send a request without saving the request ID */
++ rc = sftp_packet_write(sftp, SSH_FXP_OPENDIR, buffer);
++ assert_int_not_equal(rc, -1);
++ SSH_BUFFER_FREE(buffer);
++
++ /* An attempt to receive the response should fail without queuing it */
++ rc = sftp_read_and_dispatch(sftp);
++ assert_int_equal(rc, -1);
++ assert_null(sftp->queue);
++}
++
++int torture_run_tests(void)
++{
++ int rc;
++ struct CMUnitTest tests[] = {
++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_null,
++ session_setup,
++ session_teardown),
++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_add,
++ session_setup,
++ session_teardown),
++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_remove,
++ session_setup,
++ session_teardown),
++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_unknown,
++ session_setup,
++ session_teardown),
++ };
++
++ ssh_init();
++
++ torture_filter_tests(tests);
++ rc = cmocka_run_group_tests(tests, sshd_setup, sshd_teardown);
++ ssh_finalize();
++
++ return rc;
++}
+--
+2.35.6
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 8e86073fd3..1a5f521f6a 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -34,11 +34,9 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0965.patch \
file://CVE-2026-59843.patch \
file://CVE-2026-59844.patch \
-<<<<<<< HEAD
-=======
- file://CVE-2026-59845.patch \
file://CVE-2026-59846.patch \
->>>>>>> b782f294a0 (libssh: Fix CVE-2026-59846)
+ file://CVE-2026-59848.patch \
+ file://CVE-2026-59848-regression.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (3 preceding siblings ...)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59850 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.
[1] https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2
[2] https://www.libssh.org/security/advisories/CVE-2026-59850.txt
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../libssh/libssh/CVE-2026-59850.patch | 40 +++++++++++++++++++
.../recipes-support/libssh/libssh_0.10.6.bb | 1 +
2 files changed, 41 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
new file mode 100644
index 0000000000..61e502c796
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
@@ -0,0 +1,40 @@
+From a207ee3b4244c0e5da902245f8b81f3617b416f3 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Wed, 1 Jul 2026 16:43:08 +0200
+Subject: [PATCH] CVE-2026-59850 channels: Avoid processing DATA packets on
+ closed channels
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+
+CVE: CVE-2026-59850
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2]
+
+(cherry picked from commit a8a3fa352bb5213e08a35e4494c6e44360e2e38a)
+(cherry picked from commit 6edfb52b3b364577d2db0334c0514a977efceed2)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/channels.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/channels.c b/src/channels.c
+index 3afdcf11..1543c792 100644
+--- a/src/channels.c
++++ b/src/channels.c
+@@ -575,6 +575,13 @@ SSH_PACKET_CALLBACK(channel_rcv_data){
+ channel->local_window,
+ channel->remote_window);
+
++ if (channel->flags & SSH_CHANNEL_FLAG_CLOSED_REMOTE) {
++ SSH_LOG(SSH_LOG_WARNING, "Received data on (remotely) closed channel");
++ ssh_set_error(session, SSH_FATAL, "Received data on (remotely) closed channel");
++ SSH_STRING_FREE(str);
++ return SSH_PACKET_USED;
++ }
++
+ /* What shall we do in this case? Let's accept it anyway */
+ if (len > channel->local_window) {
+ SSH_LOG(SSH_LOG_RARE,
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 1a5f521f6a..cc957d62ca 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -37,6 +37,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-59846.patch \
file://CVE-2026-59848.patch \
file://CVE-2026-59848-regression.patch \
+ file://CVE-2026-59850.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
--
2.35.6
^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (4 preceding siblings ...)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-01 1:37 ` Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
5 siblings, 1 reply; 8+ messages in thread
From: Anuj Mittal @ 2026-09-01 1:37 UTC (permalink / raw)
To: hthakar; +Cc: openembedded-devel, xe-linux-external
On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
PRIVATE LIMITED at Cisco) via lists.openembedded.org
<hthakar=cisco.com@lists.openembedded.org> wrote:
>
> From: Hetvi Thakar <hthakar@cisco.com>
>
> Backport five upstream libssh security fixes to the 0.10.6 recipe on
> scarthgap:
>
> - CVE-2026-59843
> - CVE-2026-59844
> - CVE-2026-59846
> - CVE-2026-59848
> - CVE-2026-59850
>
> Carry these as focused backports instead of upgrading libssh because
> newer releases include API and functional changes outside the security
> scope.
>
> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
> code or features absent from 0.10.6. NVD correction requests have been
> submitted for these inaccurate affected-version entries; therefore, no
> CVE_STATUS entries are added.
>
> The individual commits retain the upstream fix provenance and advisory
> references for each CVE.
>
> Testing:
> - Applied all five patches to libssh 0.10.6 in series order without
> conflicts or fuzz.
> - Package build completed successfully.
>
> Hetvi Thakar (5):
> libssh: Fix CVE-2026-59843
> libssh: Fix CVE-2026-59844
> libssh: Fix CVE-2026-59846
> libssh: Fix CVE-2026-59848
> libssh: Fix CVE-2026-59850
3/5 is adding unresolved merge markers to recipe that 4/5 is then
removing. Please fix the patches, rebase them on current scarthgap and
resend.
Thanks,
Anuj
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
@ 2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-01 8:23 UTC (permalink / raw)
To: openembedded-devel
[-- Attachment #1: Type: text/plain, Size: 1811 bytes --]
On Tue, Sep 1, 2026 at 07:07 AM, Anuj Mittal wrote:
>
> On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
> PRIVATE LIMITED at Cisco) via lists.openembedded.org
> <hthakar=cisco.com@lists.openembedded.org> wrote:
>
>> From: Hetvi Thakar <hthakar@cisco.com>
>>
>> Backport five upstream libssh security fixes to the 0.10.6 recipe on
>> scarthgap:
>>
>> - CVE-2026-59843
>> - CVE-2026-59844
>> - CVE-2026-59846
>> - CVE-2026-59848
>> - CVE-2026-59850
>>
>> Carry these as focused backports instead of upgrading libssh because
>> newer releases include API and functional changes outside the security
>> scope.
>>
>> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
>> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
>> code or features absent from 0.10.6. NVD correction requests have been
>> submitted for these inaccurate affected-version entries; therefore, no
>> CVE_STATUS entries are added.
>>
>> The individual commits retain the upstream fix provenance and advisory
>> references for each CVE.
>>
>> Testing:
>> - Applied all five patches to libssh 0.10.6 in series order without
>> conflicts or fuzz.
>> - Package build completed successfully.
>>
>> Hetvi Thakar (5):
>> libssh: Fix CVE-2026-59843
>> libssh: Fix CVE-2026-59844
>> libssh: Fix CVE-2026-59846
>> libssh: Fix CVE-2026-59848
>> libssh: Fix CVE-2026-59850
>
> 3/5 is adding unresolved merge markers to recipe that 4/5 is then
> removing. Please fix the patches, rebase them on current scarthgap and
> resend.
>
> Thanks,
>
> Anuj
Hi,
Thanks for pointing this out.
I will fix the unresolved merge markers, rebase the patch series on
the current scarthgap branch, and resend the updated series.
Regards,
Hetvi
[-- Attachment #2: Type: text/html, Size: 2109 bytes --]
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-01 8:24 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox