Openembedded Devel Discussions
 help / color / mirror / Atom feed
* [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
@ 2026-08-19 11:10 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
                   ` (5 more replies)
  0 siblings, 6 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
  To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar

From: Hetvi Thakar <hthakar@cisco.com>

Backport five upstream libssh security fixes to the 0.10.6 recipe on
 scarthgap:

 - CVE-2026-59843
 - CVE-2026-59844
 - CVE-2026-59846
 - CVE-2026-59848
 - CVE-2026-59850

Carry these as focused backports instead of upgrading libssh because
newer releases include API and functional changes outside the security
scope.

CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
code or features absent from 0.10.6. NVD correction requests have been
submitted for these inaccurate affected-version entries; therefore, no
CVE_STATUS entries are added.

The individual commits retain the upstream fix provenance and advisory
references for each CVE.

Testing:
- Applied all five patches to libssh 0.10.6 in series order without
  conflicts or fuzz.
- Package build completed successfully.

Hetvi Thakar (5):
  libssh: Fix CVE-2026-59843
  libssh: Fix CVE-2026-59844
  libssh: Fix CVE-2026-59846
  libssh: Fix CVE-2026-59848
  libssh: Fix CVE-2026-59850

 .../libssh/libssh/CVE-2026-59843.patch        |  84 +++
 .../libssh/libssh/CVE-2026-59844.patch        |  52 ++
 .../libssh/libssh/CVE-2026-59846.patch        |  87 +++
 .../libssh/CVE-2026-59848-regression.patch    |  45 ++
 .../libssh/libssh/CVE-2026-59848.patch        | 684 ++++++++++++++++++
 .../libssh/libssh/CVE-2026-59850.patch        |  40 +
 .../recipes-support/libssh/libssh_0.10.6.bb   |   6 +
 7 files changed, 998 insertions(+)
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch

-- 
2.35.6



^ permalink raw reply	[flat|nested] 8+ messages in thread

* [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843
  2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
                   ` (4 subsequent siblings)
  5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
  To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar

From: Hetvi Thakar <hthakar@cisco.com>

The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59843 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.

[1] https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919
[2] https://www.libssh.org/security/advisories/CVE-2026-59843.txt

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
 .../libssh/libssh/CVE-2026-59843.patch        | 84 +++++++++++++++++++
 .../recipes-support/libssh/libssh_0.10.6.bb   |  1 +
 2 files changed, 85 insertions(+)
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch

diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
new file mode 100644
index 0000000000..03d3ce6ea2
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
@@ -0,0 +1,84 @@
+From d965eb941a9a83a0643570a93d8997b91e248fc1 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Fri, 6 Mar 2026 13:58:30 +0100
+Subject: [PATCH] CVE-2026-59843 channels: Fail when receiving max packet size
+ 0
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Do this both for SSH2_MSG_CHANNEL_OPEN and for
+SSH2_MSG_CHANNEL_OPEN_CONFIRMATION. Using the
+max packet size 0 would lead to an infinite loop
+in channel_write_common.
+
+Originally reported by Rinku Das on on 23th February.
+Independently reported by Yi Lin on 26th February and
+Haruto Kimura on 22nd March.
+
+We do not consider this as a security issue as connecting
+to untrusted servers on the internet brings much worse
+security consequences than hanging your clinet.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59843
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919]
+
+(cherry picked from commit 44b186fa17aff497dae420c59c003222e438103c)
+(cherry picked from commit 687ef1c44b646b9db0b1c6e8f987edb7c9e4d919)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/channels.c |  7 +++++++
+ src/messages.c | 19 +++++++++++++++----
+ 2 files changed, 22 insertions(+), 4 deletions(-)
+
+diff --git a/src/channels.c b/src/channels.c
+index 8290dbd1..3afdcf11 100644
+--- a/src/channels.c
++++ b/src/channels.c
+@@ -192,6 +192,13 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open_conf){
+   if (rc != SSH_OK)
+       goto error;
+ 
++  if (channel->remote_maxpacket == 0) {
++      SSH_LOG(SSH_LOG_RARE,
++              "Invalid maximum packet size 0 in "
++              "SSH2_MSG_CHANNEL_OPEN_CONFIRMATION");
++      goto error;
++  }
++
+   SSH_LOG(SSH_LOG_PROTOCOL,
+       "Received a CHANNEL_OPEN_CONFIRMATION for channel %d:%d",
+       channel->local_channel,
+diff --git a/src/messages.c b/src/messages.c
+index 6dadabf0..e79ecec2 100644
+--- a/src/messages.c
++++ b/src/messages.c
+@@ -1160,10 +1160,21 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open){
+   SSH_LOG(SSH_LOG_PACKET,
+       "Clients wants to open a %s channel", type_c);
+ 
+-  ssh_buffer_unpack(packet,"ddd",
+-          &msg->channel_request_open.sender,
+-          &msg->channel_request_open.window,
+-          &msg->channel_request_open.packet_size);
++  rc = ssh_buffer_unpack(packet,
++                         "ddd",
++                         &msg->channel_request_open.sender,
++                         &msg->channel_request_open.window,
++                         &msg->channel_request_open.packet_size);
++  if (rc != SSH_OK){
++      goto error;
++  }
++
++  if (msg->channel_request_open.packet_size == 0) {
++      ssh_set_error(session,
++                    SSH_FATAL,
++                    "Invalid maximum packet size 0 in SSH2_MSG_CHANNEL_OPEN");
++      goto error;
++  }
+ 
+   if (session->session_state != SSH_SESSION_STATE_AUTHENTICATED){
+     ssh_set_error(session,SSH_FATAL, "Invalid state when receiving channel open request (must be authenticated)");
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 1f64920a50..381b3efc7d 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -32,6 +32,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
            file://CVE-2026-0968-2.patch \
            file://CVE-2026-0967.patch \
            file://CVE-2026-0965.patch \
+           file://CVE-2026-59843.patch \
           "
 SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
 
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844
  2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
                   ` (3 subsequent siblings)
  5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
  To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar

From: Hetvi Thakar <hthakar@cisco.com>

The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59844 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.

[1] https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9
[2] https://www.libssh.org/security/advisories/CVE-2026-59844.txt

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
 .../libssh/libssh/CVE-2026-59844.patch        | 52 +++++++++++++++++++
 .../recipes-support/libssh/libssh_0.10.6.bb   |  1 +
 2 files changed, 53 insertions(+)
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch

diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
new file mode 100644
index 0000000000..ac380622d9
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
@@ -0,0 +1,52 @@
+From ef7cd6d4aef6d18ca8bf15cb0398b630284f46f4 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Fri, 6 Mar 2026 18:05:29 +0100
+Subject: [PATCH] CVE-2026-59844 sftpserver: cap accepted values of len in
+ SSH_FXP_READ
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The client-provided length is directly used in
+a malloc in process_read(), so not restricting it
+leads to allocations bounded only by UINT32_MAX.
+
+The new cap is the same as the one currently used
+by OpenSSH.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59844
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9]
+
+Backport Changes:
+- Replace the upstream goto error path with equivalent direct message cleanup
+  and return because libssh 0.10.6 does not have the refactored
+  sftp_make_client_message() error label.
+
+(cherry picked from commit 6dba2e06f0713c04ad5eca7d4315d0104be7e627)
+(cherry picked from commit e31f06e5380be4e714d5ad6965981fbf30738da9)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/sftpserver.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/sftpserver.c b/src/sftpserver.c
+index 528ef6f9..77290068 100644
+--- a/src/sftpserver.c
++++ b/src/sftpserver.c
+@@ -105,6 +105,13 @@ sftp_client_message sftp_get_client_message(sftp_session sftp) {
+         sftp_client_message_free(msg);
+         return NULL;
+       }
++      if (msg->len > MAX_PACKET_LEN - 1024) {
++        ssh_set_error(sftp->session, SSH_FATAL,
++                      "Too large SSH_FXP_READ length: %" PRIu32,
++                      msg->len);
++        sftp_client_message_free(msg);
++        return NULL;
++      }
+       break;
+     case SSH_FXP_WRITE:
+       rc = ssh_buffer_unpack(payload,
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 381b3efc7d..a9d7729f2c 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -33,6 +33,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
            file://CVE-2026-0967.patch \
            file://CVE-2026-0965.patch \
            file://CVE-2026-59843.patch \
+           file://CVE-2026-59844.patch \
           "
 SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
 
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846
  2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
                   ` (2 subsequent siblings)
  5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
  To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar

From: Hetvi Thakar <hthakar@cisco.com>

libssh 0.10.6 predates the username-validation helper used by the
stable-0.11 fix, so the upstream commit in [1] cannot be applied as-is.
Adapt the same dangerous-character check directly at the ProxyCommand %r
expansion sink and add focused regression coverage.

The upstream advisory [2] identifies libssh 0.11.5 and 0.12.1 as the
fixed releases.

[1] https://gitlab.com/libssh/libssh-mirror/-/commit/56ce3c193eb06af5bf3b07ec0b4c7308b5c72130
[2] https://www.libssh.org/security/advisories/CVE-2026-59846.txt

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
 .../libssh/libssh/CVE-2026-59846.patch        | 87 +++++++++++++++++++
 .../recipes-support/libssh/libssh_0.10.6.bb   |  5 ++
 2 files changed, 92 insertions(+)
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch

diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
new file mode 100644
index 0000000000..9c626d113d
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
@@ -0,0 +1,87 @@
+From 19fe4c9fc7b3bd3553250bf9ddea03ed1dcf044f Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Thu, 2 Apr 2026 15:39:25 +0200
+Subject: [PATCH] CVE-2026-59846 Block shell metacharacters from usernames
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+When an attacker could sneak the dollar sign or backslash into the username
+expanded for example in proxy command, it can result in printing environment
+variables that might contain secrets.
+
+This is a fixup of CVE-2023-6004 which fixed this for hostnames, but these
+two metacharacters were left out from the username filter.
+
+This keeps the list in one place to simplify maintenance.
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+(cherry picked from commit 6309df220e3431deb41946f892f4bb5af8b59dba)
+
+CVE: CVE-2026-59846
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=56ce3c193eb06af5bf3b07ec0b4c7308b5c72130]
+
+Backport Changes:
+- libssh 0.10.6 predates ssh_check_username_syntax() and the centralized
+  SSH_DANGEROUS_SHELL_CHARS definition, so enforce the same character list
+  directly at the %r expansion sink in ssh_path_expand_escape().
+- Add focused regression coverage to the existing path-expansion unit test
+  for dollar-sign, backslash, and command-separator usernames.
+
+(cherry picked from commit 56ce3c193eb06af5bf3b07ec0b4c7308b5c72130)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/misc.c                     |  9 +++++++++
+ tests/unittests/torture_misc.c | 18 ++++++++++++++++++
+ 2 files changed, 27 insertions(+)
+
+diff --git a/src/misc.c b/src/misc.c
+index e78c92ba..15b427d7 100644
+--- a/src/misc.c
++++ b/src/misc.c
+@@ -1262,6 +1262,15 @@ char *ssh_path_expand_escape(ssh_session session, const char *s)
+                 break;
+             case 'r':
+                 if (session->opts.username) {
++                    if (strpbrk(session->opts.username,
++                                "'`\";&<>|(){}$\\,") != NULL) {
++                        ssh_set_error(session,
++                                      SSH_FATAL,
++                                      "Invalid shell metacharacter in username");
++                        free(buf);
++                        free(r);
++                        return NULL;
++                    }
+                     x = strdup(session->opts.username);
+                 } else {
+                     ssh_set_error(session, SSH_FATAL,
+diff --git a/tests/unittests/torture_misc.c b/tests/unittests/torture_misc.c
+index 82d6cf16..66d392ed 100644
+--- a/tests/unittests/torture_misc.c
++++ b/tests/unittests/torture_misc.c
+@@ -194,6 +194,24 @@ static void torture_path_expand_escape(void **state) {
+     assert_non_null(e);
+     assert_string_equal(e, "guru/meditation/222/by/root");
+     ssh_string_free_char(e);
++
++    free(session->opts.username);
++    session->opts.username = strdup("root$HOME");
++    assert_non_null(session->opts.username);
++    e = ssh_path_expand_escape(session, s);
++    assert_null(e);
++
++    free(session->opts.username);
++    session->opts.username = strdup("root\\user");
++    assert_non_null(session->opts.username);
++    e = ssh_path_expand_escape(session, s);
++    assert_null(e);
++
++    free(session->opts.username);
++    session->opts.username = strdup("root;id");
++    assert_non_null(session->opts.username);
++    e = ssh_path_expand_escape(session, s);
++    assert_null(e);
+ }
+ 
+ static void torture_path_expand_known_hosts(void **state) {
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index a9d7729f2c..8e86073fd3 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -34,6 +34,11 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
            file://CVE-2026-0965.patch \
            file://CVE-2026-59843.patch \
            file://CVE-2026-59844.patch \
+<<<<<<< HEAD
+=======
+           file://CVE-2026-59845.patch \
+           file://CVE-2026-59846.patch \
+>>>>>>> b782f294a0 (libssh: Fix CVE-2026-59846)
           "
 SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
 
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848
  2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
                   ` (2 preceding siblings ...)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-09-01  1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
  5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
  To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar

From: Hetvi Thakar <hthakar@cisco.com>

The stable-0.11 commit shown in [1] is the primary upstream fix selected
for this backport. Commit [2] corrects the request-queue pointer state
introduced by [1], so it is carried immediately afterward as a regression
fix. The upstream advisory [3] documents CVE-2026-59848 and identifies
libssh 0.11.5 as the fixed release for the 0.11 series.

[1] https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497
[2] https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be
[3] https://www.libssh.org/security/advisories/CVE-2026-59848.txt

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
 .../libssh/CVE-2026-59848-regression.patch    |  45 ++
 .../libssh/libssh/CVE-2026-59848.patch        | 684 ++++++++++++++++++
 .../recipes-support/libssh/libssh_0.10.6.bb   |   6 +-
 3 files changed, 731 insertions(+), 4 deletions(-)
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch

diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
new file mode 100644
index 0000000000..161271264f
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
@@ -0,0 +1,45 @@
+From dddd93ac995ac382e4ec9496509f24003bd72c30 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Wed, 3 Jun 2026 12:56:09 +0200
+Subject: [PATCH] CVE-2026-59848 sftp: Initialize sftp_request_queue ptr in
+ sftp_free
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59848
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be]
+
+Backport Changes:
+- Adjusted hunk context for the consolidated libssh 0.10.6 SFTP
+  implementation; the pointer initialization is unchanged from upstream.
+- Omitted the upstream tests/client/torture_sftp_request_id.c follow-up hunk
+  because CVE-2026-59848.patch introduces the backported regression test
+  directly with sftp_read_and_dispatch(); there is no intermediate
+  sftp_recv_response_msg() version to update.
+
+(cherry picked from commit 00876f7658fd265682708572122502188fa22076)
+(cherry picked from commit 5309aefd99e1775db40bf20869f1fb1cc6c787be)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/sftp.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/sftp.c b/src/sftp.c
+index e6755e2b..ff6e5200 100644
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -371,7 +371,7 @@ void sftp_server_free(sftp_session sftp)
+ 
+ void sftp_free(sftp_session sftp)
+ {
+-    sftp_request_queue ptr;
++    sftp_request_queue ptr = NULL;
+     struct ssh_iterator *id_it = NULL;
+ 
+     if (sftp == NULL) {
+-- 
+2.35.6
diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
new file mode 100644
index 0000000000..2f4efb22f1
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
@@ -0,0 +1,684 @@
+From ef75e652dd2808c27251da4d03feef84d158c1de Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
+Date: Mon, 1 Jun 2026 16:33:03 +0200
+Subject: [PATCH] CVE-2026-59848 sftp: handle responses with unknown request
+ IDs
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+This adds a new field to sftp_session_struct,
+containing a list of outstanding request IDs.
+An ID is added to the list when a request
+is constructed and removed when the corresponding
+request is received. If a client receives a response
+with an unknown request ID, it reports an error.
+
+Storing responses with unknown request IDs in
+the response queue could be abused by a malicious
+SFTP server which could deplete client memory
+this way.
+
+Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
+Reviewed-by: Jakub Jelen <jjelen@redhat.com>
+
+CVE: CVE-2026-59848
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497]
+
+Backport Changes:
+- Consolidated the upstream src/sftp_common.c and src/sftp_aio.c changes
+  into src/sftp.c, where libssh 0.10.6 implements response dispatch,
+  request-ID allocation, and asynchronous SFTP reads.
+- Kept sftp_get_new_id() static instead of exporting it through
+  sftp_priv.h because all 20 request-producing call sites in 0.10.6 are
+  in src/sftp.c; newer-only SFTP API call sites are absent.
+- Retained the 0.10.6 request construction order and free the existing
+  request buffer when request-ID tracking fails.
+- Adapted the unknown-ID regression test to call
+  sftp_read_and_dispatch() and verify the response queue remains empty;
+  0.10.6 does not provide sftp_recv_response_msg().
+
+(cherry picked from commit 26147eb4767937c797f97ff3b1b1663384232417)
+(cherry picked from commit a30a51003205744c10ba4439306f555206ae8497)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ include/libssh/sftp.h                  |   1 +
+ src/sftp.c                             | 210 ++++++++++++++++++++++---
+ tests/client/CMakeLists.txt            |   1 +
+ tests/client/torture_sftp_request_id.c | 183 +++++++++++++++++++++
+ 4 files changed, 369 insertions(+), 26 deletions(-)
+ create mode 100644 tests/client/torture_sftp_request_id.c
+
+diff --git a/include/libssh/sftp.h b/include/libssh/sftp.h
+index c713466e..984c4eb7 100644
+--- a/include/libssh/sftp.h
++++ b/include/libssh/sftp.h
+@@ -90,6 +90,7 @@ struct sftp_session_struct {
+     void **handles;
+     sftp_ext ext;
+     sftp_packet read_packet;
++    struct ssh_list *outstanding_ids;
+ };
+ 
+ struct sftp_packet_struct {
+diff --git a/src/sftp.c b/src/sftp.c
+index 2194a9ef..e6755e2b 100644
+--- a/src/sftp.c
++++ b/src/sftp.c
+@@ -149,6 +149,12 @@ sftp_session sftp_new(ssh_session session)
+         goto error;
+     }
+ 
++    sftp->outstanding_ids = ssh_list_new();
++    if (sftp->outstanding_ids == NULL) {
++        ssh_set_error_oom(session);
++        goto error;
++    }
++
+     if (ssh_channel_open_session(sftp->channel)) {
+         goto error;
+     }
+@@ -165,6 +171,7 @@ error:
+     if (sftp->channel != NULL) {
+         ssh_channel_free(sftp->channel);
+     }
++    ssh_list_free(sftp->outstanding_ids);
+     if (sftp->read_packet != NULL) {
+         if (sftp->read_packet->payload != NULL) {
+             SSH_BUFFER_FREE(sftp->read_packet->payload);
+@@ -196,6 +203,12 @@ sftp_new_channel(ssh_session session, ssh_channel channel)
+         goto error;
+     }
+ 
++    sftp->outstanding_ids = ssh_list_new();
++    if (sftp->outstanding_ids == NULL) {
++        ssh_set_error_oom(session);
++        goto error;
++    }
++
+     sftp->read_packet = calloc(1, sizeof(struct sftp_packet_struct));
+     if (sftp->read_packet == NULL) {
+         ssh_set_error_oom(session);
+@@ -217,6 +230,7 @@ error:
+     if (sftp->ext != NULL) {
+         sftp_ext_free(sftp->ext);
+     }
++    ssh_list_free(sftp->outstanding_ids);
+     if (sftp->read_packet != NULL) {
+         if (sftp->read_packet->payload != NULL) {
+             SSH_BUFFER_FREE(sftp->read_packet->payload);
+@@ -358,6 +372,7 @@ void sftp_server_free(sftp_session sftp)
+ void sftp_free(sftp_session sftp)
+ {
+     sftp_request_queue ptr;
++    struct ssh_iterator *id_it = NULL;
+ 
+     if (sftp == NULL) {
+         return;
+@@ -384,6 +399,12 @@ void sftp_free(sftp_session sftp)
+ 
+     sftp_ext_free(sftp->ext);
+ 
++    id_it = ssh_list_get_iterator(sftp->outstanding_ids);
++    for (; id_it != NULL; id_it = id_it->next) {
++        free((uint32_t *)id_it->data);
++    }
++    ssh_list_free(sftp->outstanding_ids);
++
+     SAFE_FREE(sftp);
+ }
+ 
+@@ -571,6 +592,8 @@ static sftp_message sftp_get_message(sftp_packet packet)
+ {
+     sftp_session sftp = packet->sftp;
+     sftp_message msg = NULL;
++    struct ssh_iterator *id_it = NULL;
++    bool id_found = false;
+     int rc;
+ 
+     switch(packet->type) {
+@@ -618,6 +641,28 @@ static sftp_message sftp_get_message(sftp_packet packet)
+             msg->id,
+             msg->packet_type);
+ 
++    /* Validate that this ID is in our outstanding requests list */
++    id_it = ssh_list_get_iterator(sftp->outstanding_ids);
++    for (; id_it != NULL; id_it = id_it->next) {
++        uint32_t *stored_id = (uint32_t *)id_it->data;
++        if (*stored_id == msg->id) {
++            id_found = true;
++            ssh_list_remove(sftp->outstanding_ids, id_it);
++            free(stored_id);
++            break;
++        }
++    }
++
++    if (!id_found) {
++        ssh_set_error(packet->sftp->session,
++                      SSH_FATAL,
++                      "Unknown request ID %" PRIu32,
++                      msg->id);
++        sftp_message_free(msg);
++        sftp_set_error(packet->sftp, SSH_FX_FAILURE);
++        return NULL;
++    }
++
+     return msg;
+ }
+ 
+@@ -902,13 +947,46 @@ static sftp_message sftp_dequeue(sftp_session sftp, uint32_t id){
+   return NULL;
+ }
+ 
+-/*
+- * Assigns a new SFTP ID for new requests and assures there is no collision
+- * between them.
+- * Returns a new ID ready to use in a request
++/**
++ * @brief Assigns a new SFTP ID for new requests and assures there is no
++ *        collision between them.
++ *
++ * @param sftp           The sftp session handle.
++ * @param id_out         Pointer to store the new ID.
++ *
++ * @returns SSH_OK on success with the new ID stored in *id
++ * @returns SSH_ERROR on failure with the sftp and ssh errors set
+  */
+-static inline uint32_t sftp_get_new_id(sftp_session session) {
+-  return ++session->id_counter;
++static int sftp_get_new_id(sftp_session sftp, uint32_t *id_out)
++{
++    uint32_t *id = NULL;
++    int rc;
++
++    if (id_out == NULL) {
++        ssh_set_error_invalid(sftp->session);
++        sftp_set_error(sftp, SSH_FX_FAILURE);
++        return SSH_ERROR;
++    }
++
++    id = malloc(sizeof(uint32_t));
++    if (id == NULL) {
++        ssh_set_error_oom(sftp->session);
++        sftp_set_error(sftp, SSH_FX_FAILURE);
++        return SSH_ERROR;
++    }
++
++    *id = ++sftp->id_counter;
++    rc = ssh_list_append(sftp->outstanding_ids, id);
++    if (rc != SSH_OK) {
++        free(id);
++        ssh_set_error_oom(sftp->session);
++        sftp_set_error(sftp, SSH_FX_FAILURE);
++        return SSH_ERROR;
++    }
++
++    *id_out = *id;
++
++    return SSH_OK;
+ }
+ 
+ static sftp_status_message parse_status_msg(sftp_message msg){
+@@ -1029,7 +1107,11 @@ sftp_dir sftp_opendir(sftp_session sftp, const char *path)
+         return NULL;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(payload);
++        return NULL;
++    }
+ 
+     rc = ssh_buffer_pack(payload,
+                          "ds",
+@@ -1571,7 +1653,11 @@ sftp_attributes sftp_readdir(sftp_session sftp, sftp_dir dir)
+             return NULL;
+         }
+ 
+-        id = sftp_get_new_id(sftp);
++        rc = sftp_get_new_id(sftp, &id);
++        if (rc != SSH_OK) {
++            SSH_BUFFER_FREE(payload);
++            return NULL;
++        }
+ 
+         rc = ssh_buffer_pack(payload,
+                              "dS",
+@@ -1704,7 +1790,11 @@ static int sftp_handle_close(sftp_session sftp, ssh_string handle)
+         return -1;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return -1;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "dS",
+@@ -1835,7 +1925,11 @@ sftp_file sftp_open(sftp_session sftp,
+         sftp_flags |= SSH_FXF_APPEND;
+     }
+     SSH_LOG(SSH_LOG_PACKET,"Opening file %s with sftp flags %x",file,sftp_flags);
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return NULL;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "dsd",
+@@ -1946,7 +2040,11 @@ ssize_t sftp_read(sftp_file handle, void *buf, size_t count) {
+     return -1;
+   }
+ 
+-  id = sftp_get_new_id(handle->sftp);
++  rc = sftp_get_new_id(handle->sftp, &id);
++  if (rc != SSH_OK) {
++    SSH_BUFFER_FREE(buffer);
++    return -1;
++  }
+ 
+   rc = ssh_buffer_pack(buffer,
+                        "dSqd",
+@@ -2047,7 +2145,11 @@ int sftp_async_read_begin(sftp_file file, uint32_t len){
+     return -1;
+   }
+ 
+-  id = sftp_get_new_id(sftp);
++  rc = sftp_get_new_id(sftp, &id);
++  if (rc != SSH_OK) {
++    SSH_BUFFER_FREE(buffer);
++    return -1;
++  }
+ 
+   rc = ssh_buffer_pack(buffer,
+                        "dSqd",
+@@ -2173,7 +2275,11 @@ ssize_t sftp_write(sftp_file file, const void *buf, size_t count) {
+     return -1;
+   }
+ 
+-  id = sftp_get_new_id(file->sftp);
++  rc = sftp_get_new_id(file->sftp, &id);
++  if (rc != SSH_OK) {
++    SSH_BUFFER_FREE(buffer);
++    return -1;
++  }
+ 
+   rc = ssh_buffer_pack(buffer,
+                        "dSqdP",
+@@ -2291,7 +2397,11 @@ int sftp_unlink(sftp_session sftp, const char *file) {
+     return -1;
+   }
+ 
+-  id = sftp_get_new_id(sftp);
++  rc = sftp_get_new_id(sftp, &id);
++  if (rc != SSH_OK) {
++    SSH_BUFFER_FREE(buffer);
++    return -1;
++  }
+ 
+   rc = ssh_buffer_pack(buffer,
+                        "ds",
+@@ -2366,7 +2476,11 @@ int sftp_rmdir(sftp_session sftp, const char *directory) {
+     return -1;
+   }
+ 
+-  id = sftp_get_new_id(sftp);
++  rc = sftp_get_new_id(sftp, &id);
++  if (rc != SSH_OK) {
++    SSH_BUFFER_FREE(buffer);
++    return -1;
++  }
+ 
+   rc = ssh_buffer_pack(buffer,
+                        "ds",
+@@ -2443,7 +2557,11 @@ int sftp_mkdir(sftp_session sftp, const char *directory, mode_t mode)
+     attr.permissions = mode;
+     attr.flags = SSH_FILEXFER_ATTR_PERMISSIONS;
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return -1;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "ds",
+@@ -2538,7 +2656,11 @@ int sftp_rename(sftp_session sftp, const char *original, const char *newname) {
+     return -1;
+   }
+ 
+-  id = sftp_get_new_id(sftp);
++  rc = sftp_get_new_id(sftp, &id);
++  if (rc != SSH_OK) {
++    SSH_BUFFER_FREE(buffer);
++    return -1;
++  }
+ 
+   rc = ssh_buffer_pack(buffer,
+                        "dss",
+@@ -2622,7 +2744,11 @@ int sftp_setstat(sftp_session sftp, const char *file, sftp_attributes attr)
+         return -1;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return -1;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "ds",
+@@ -2752,7 +2878,11 @@ int sftp_symlink(sftp_session sftp, const char *target, const char *dest) {
+     return -1;
+   }
+ 
+-  id = sftp_get_new_id(sftp);
++  rc = sftp_get_new_id(sftp, &id);
++  if (rc != SSH_OK) {
++    SSH_BUFFER_FREE(buffer);
++    return -1;
++  }
+ 
+   /* TODO check for version number if they ever fix it. */
+   if (ssh_get_openssh_version(sftp->session)) {
+@@ -2850,7 +2980,11 @@ char *sftp_readlink(sftp_session sftp, const char *path)
+         return NULL;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return NULL;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "ds",
+@@ -2976,7 +3110,11 @@ sftp_statvfs_t sftp_statvfs(sftp_session sftp, const char *path)
+         return NULL;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return NULL;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "dss",
+@@ -3051,7 +3189,11 @@ int sftp_fsync(sftp_file file)
+         return -1;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return -1;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "dsS",
+@@ -3151,7 +3293,11 @@ sftp_statvfs_t sftp_fstatvfs(sftp_file file)
+         return NULL;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return NULL;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "dsS",
+@@ -3238,7 +3384,11 @@ char *sftp_canonicalize_path(sftp_session sftp, const char *path)
+         return NULL;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return NULL;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "ds",
+@@ -3329,7 +3479,11 @@ static sftp_attributes sftp_xstat(sftp_session sftp,
+         return NULL;
+     }
+ 
+-    id = sftp_get_new_id(sftp);
++    rc = sftp_get_new_id(sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return NULL;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "ds",
+@@ -3407,7 +3561,11 @@ sftp_attributes sftp_fstat(sftp_file file)
+         return NULL;
+     }
+ 
+-    id = sftp_get_new_id(file->sftp);
++    rc = sftp_get_new_id(file->sftp, &id);
++    if (rc != SSH_OK) {
++        SSH_BUFFER_FREE(buffer);
++        return NULL;
++    }
+ 
+     rc = ssh_buffer_pack(buffer,
+                          "dS",
+diff --git a/tests/client/CMakeLists.txt b/tests/client/CMakeLists.txt
+index 71e5182e..864478a7 100644
+--- a/tests/client/CMakeLists.txt
++++ b/tests/client/CMakeLists.txt
+@@ -49,6 +49,7 @@ if (WITH_SFTP)
+         torture_sftp_dir
+         torture_sftp_read
+         torture_sftp_fsync
++        torture_sftp_request_id
+         ${SFTP_BENCHMARK_TESTS})
+ endif (WITH_SFTP)
+ 
+diff --git a/tests/client/torture_sftp_request_id.c b/tests/client/torture_sftp_request_id.c
+new file mode 100644
+index 00000000..fe6d3f91
+--- /dev/null
++++ b/tests/client/torture_sftp_request_id.c
+@@ -0,0 +1,183 @@
++#include "config.h"
++
++#define LIBSSH_STATIC
++
++#include "sftp.c"
++#include "torture.h"
++
++#include <pwd.h>
++#include <sys/types.h>
++
++static int sshd_setup(void **state)
++{
++    torture_setup_sshd_server(state, false);
++
++    return 0;
++}
++
++static int sshd_teardown(void **state)
++{
++    torture_teardown_sshd_server(state);
++
++    return 0;
++}
++
++static int session_setup(void **state)
++{
++    struct torture_state *s = *state;
++    struct passwd *pwd = NULL;
++    int rc;
++
++    pwd = getpwnam("bob");
++    assert_non_null(pwd);
++
++    rc = setuid(pwd->pw_uid);
++    assert_return_code(rc, errno);
++
++    s->ssh.session = torture_ssh_session(s,
++                                         TORTURE_SSH_SERVER,
++                                         NULL,
++                                         TORTURE_SSH_USER_ALICE,
++                                         NULL);
++    assert_non_null(s->ssh.session);
++
++    s->ssh.tsftp = torture_sftp_session(s->ssh.session);
++    assert_non_null(s->ssh.tsftp);
++
++    return 0;
++}
++
++static int session_teardown(void **state)
++{
++    struct torture_state *s = *state;
++
++    torture_rmdirs(s->ssh.tsftp->testdir);
++    torture_sftp_close(s->ssh.tsftp);
++    ssh_disconnect(s->ssh.session);
++    ssh_free(s->ssh.session);
++
++    return 0;
++}
++
++static void torture_sftp_request_id_null(void **state)
++{
++    struct torture_state *s = *state;
++    struct torture_sftp *t = s->ssh.tsftp;
++    sftp_session sftp = t->sftp;
++    int rc;
++
++    rc = sftp_get_new_id(sftp, NULL);
++    assert_int_equal(rc, SSH_ERROR);
++}
++
++static void torture_sftp_request_id_add(void **state)
++{
++    struct torture_state *s = *state;
++    struct torture_sftp *t = s->ssh.tsftp;
++    sftp_session sftp = t->sftp;
++    uint32_t id1, id2;
++    int rc;
++    size_t count;
++
++    /* The list of IDs should be empty at first */
++    count = ssh_list_count(sftp->outstanding_ids);
++    assert_int_equal(count, 0);
++
++    /* Request a new ID */
++    rc = sftp_get_new_id(sftp, &id1);
++    assert_int_equal(rc, SSH_OK);
++
++    /* Check that the list has one ID now */
++    count = ssh_list_count(sftp->outstanding_ids);
++    assert_int_equal(count, 1);
++
++    /* Request another ID */
++    rc = sftp_get_new_id(sftp, &id2);
++    assert_int_equal(rc, SSH_OK);
++
++    /* Check that the IDs differ */
++    assert_int_not_equal(id1, id2);
++
++    /* Check that the list has two IDs now */
++    count = ssh_list_count(sftp->outstanding_ids);
++    assert_int_equal(count, 2);
++}
++
++static void torture_sftp_request_id_remove(void **state)
++{
++    struct torture_state *s = *state;
++    struct torture_sftp *t = s->ssh.tsftp;
++    sftp_session sftp = t->sftp;
++    sftp_attributes attr = NULL;
++    size_t count;
++
++    count = ssh_list_count(sftp->outstanding_ids);
++    assert_int_equal(count, 0);
++
++    /* We send a request and receive a response */
++    attr = sftp_stat(sftp, SSH_EXECUTABLE);
++    assert_non_null(attr);
++
++    /* The number of outstanding requests should be back to 0 */
++    count = ssh_list_count(sftp->outstanding_ids);
++    assert_int_equal(count, 0);
++
++    sftp_attributes_free(attr);
++}
++
++static void torture_sftp_request_id_unknown(void **state)
++{
++    struct torture_state *s = *state;
++    struct torture_sftp *t = s->ssh.tsftp;
++    sftp_session sftp = t->sftp;
++    ssh_buffer buffer = NULL;
++    uint32_t id = 0;
++    int rc;
++    size_t count;
++
++    count = ssh_list_count(sftp->outstanding_ids);
++    assert_int_equal(count, 0);
++
++    buffer = ssh_buffer_new();
++    assert_non_null(buffer);
++
++    rc = ssh_buffer_pack(buffer, "ds", id, "/tmp");
++    assert_int_equal(rc, SSH_OK);
++
++    /* Send a request without saving the request ID */
++    rc = sftp_packet_write(sftp, SSH_FXP_OPENDIR, buffer);
++    assert_int_not_equal(rc, -1);
++    SSH_BUFFER_FREE(buffer);
++
++    /* An attempt to receive the response should fail without queuing it */
++    rc = sftp_read_and_dispatch(sftp);
++    assert_int_equal(rc, -1);
++    assert_null(sftp->queue);
++}
++
++int torture_run_tests(void)
++{
++    int rc;
++    struct CMUnitTest tests[] = {
++        cmocka_unit_test_setup_teardown(torture_sftp_request_id_null,
++                                        session_setup,
++                                        session_teardown),
++        cmocka_unit_test_setup_teardown(torture_sftp_request_id_add,
++                                        session_setup,
++                                        session_teardown),
++        cmocka_unit_test_setup_teardown(torture_sftp_request_id_remove,
++                                        session_setup,
++                                        session_teardown),
++        cmocka_unit_test_setup_teardown(torture_sftp_request_id_unknown,
++                                        session_setup,
++                                        session_teardown),
++    };
++
++    ssh_init();
++
++    torture_filter_tests(tests);
++    rc = cmocka_run_group_tests(tests, sshd_setup, sshd_teardown);
++    ssh_finalize();
++
++    return rc;
++}
+-- 
+2.35.6
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 8e86073fd3..1a5f521f6a 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -34,11 +34,9 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
            file://CVE-2026-0965.patch \
            file://CVE-2026-59843.patch \
            file://CVE-2026-59844.patch \
-<<<<<<< HEAD
-=======
-           file://CVE-2026-59845.patch \
            file://CVE-2026-59846.patch \
->>>>>>> b782f294a0 (libssh: Fix CVE-2026-59846)
+           file://CVE-2026-59848.patch \
+           file://CVE-2026-59848-regression.patch \
           "
 SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
 
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850
  2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
                   ` (3 preceding siblings ...)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-09-01  1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
  5 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
  To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar

From: Hetvi Thakar <hthakar@cisco.com>

The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59850 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.

[1] https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2
[2] https://www.libssh.org/security/advisories/CVE-2026-59850.txt

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
 .../libssh/libssh/CVE-2026-59850.patch        | 40 +++++++++++++++++++
 .../recipes-support/libssh/libssh_0.10.6.bb   |  1 +
 2 files changed, 41 insertions(+)
 create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch

diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
new file mode 100644
index 0000000000..61e502c796
--- /dev/null
+++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
@@ -0,0 +1,40 @@
+From a207ee3b4244c0e5da902245f8b81f3617b416f3 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Wed, 1 Jul 2026 16:43:08 +0200
+Subject: [PATCH] CVE-2026-59850 channels: Avoid processing DATA packets on
+ closed channels
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+
+CVE: CVE-2026-59850
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2]
+
+(cherry picked from commit a8a3fa352bb5213e08a35e4494c6e44360e2e38a)
+(cherry picked from commit 6edfb52b3b364577d2db0334c0514a977efceed2)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/channels.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/src/channels.c b/src/channels.c
+index 3afdcf11..1543c792 100644
+--- a/src/channels.c
++++ b/src/channels.c
+@@ -575,6 +575,13 @@ SSH_PACKET_CALLBACK(channel_rcv_data){
+       channel->local_window,
+       channel->remote_window);
+ 
++    if (channel->flags & SSH_CHANNEL_FLAG_CLOSED_REMOTE) {
++        SSH_LOG(SSH_LOG_WARNING, "Received data on (remotely) closed channel");
++        ssh_set_error(session, SSH_FATAL, "Received data on (remotely) closed channel");
++        SSH_STRING_FREE(str);
++        return SSH_PACKET_USED;
++    }
++
+   /* What shall we do in this case? Let's accept it anyway */
+   if (len > channel->local_window) {
+     SSH_LOG(SSH_LOG_RARE,
diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
index 1a5f521f6a..cc957d62ca 100644
--- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
+++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb
@@ -37,6 +37,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
            file://CVE-2026-59846.patch \
            file://CVE-2026-59848.patch \
            file://CVE-2026-59848-regression.patch \
+           file://CVE-2026-59850.patch \
           "
 SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
 
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 8+ messages in thread

* Re: [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
  2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
                   ` (4 preceding siblings ...)
  2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-01  1:37 ` Anuj Mittal
  2026-09-01  8:23   ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  5 siblings, 1 reply; 8+ messages in thread
From: Anuj Mittal @ 2026-09-01  1:37 UTC (permalink / raw)
  To: hthakar; +Cc: openembedded-devel, xe-linux-external

On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
PRIVATE LIMITED at Cisco) via lists.openembedded.org
<hthakar=cisco.com@lists.openembedded.org> wrote:
>
> From: Hetvi Thakar <hthakar@cisco.com>
>
> Backport five upstream libssh security fixes to the 0.10.6 recipe on
>  scarthgap:
>
>  - CVE-2026-59843
>  - CVE-2026-59844
>  - CVE-2026-59846
>  - CVE-2026-59848
>  - CVE-2026-59850
>
> Carry these as focused backports instead of upgrading libssh because
> newer releases include API and functional changes outside the security
> scope.
>
> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
> code or features absent from 0.10.6. NVD correction requests have been
> submitted for these inaccurate affected-version entries; therefore, no
> CVE_STATUS entries are added.
>
> The individual commits retain the upstream fix provenance and advisory
> references for each CVE.
>
> Testing:
> - Applied all five patches to libssh 0.10.6 in series order without
>   conflicts or fuzz.
> - Package build completed successfully.
>
> Hetvi Thakar (5):
>   libssh: Fix CVE-2026-59843
>   libssh: Fix CVE-2026-59844
>   libssh: Fix CVE-2026-59846
>   libssh: Fix CVE-2026-59848
>   libssh: Fix CVE-2026-59850

3/5 is adding unresolved merge markers to recipe that 4/5 is then
removing. Please fix the patches, rebase them on current scarthgap and
resend.

Thanks,

Anuj


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
  2026-09-01  1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
@ 2026-09-01  8:23   ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 0 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-01  8:23 UTC (permalink / raw)
  To: openembedded-devel

[-- Attachment #1: Type: text/plain, Size: 1811 bytes --]

On Tue, Sep 1, 2026 at 07:07 AM, Anuj Mittal wrote:

> 
> On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS
> PRIVATE LIMITED at Cisco) via lists.openembedded.org
> <hthakar=cisco.com@lists.openembedded.org> wrote:
> 
>> From: Hetvi Thakar <hthakar@cisco.com>
>> 
>> Backport five upstream libssh security fixes to the 0.10.6 recipe on
>> scarthgap:
>> 
>> - CVE-2026-59843
>> - CVE-2026-59844
>> - CVE-2026-59846
>> - CVE-2026-59848
>> - CVE-2026-59850
>> 
>> Carry these as focused backports instead of upgrading libssh because
>> newer releases include API and functional changes outside the security
>> scope.
>> 
>> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
>> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
>> code or features absent from 0.10.6. NVD correction requests have been
>> submitted for these inaccurate affected-version entries; therefore, no
>> CVE_STATUS entries are added.
>> 
>> The individual commits retain the upstream fix provenance and advisory
>> references for each CVE.
>> 
>> Testing:
>> - Applied all five patches to libssh 0.10.6 in series order without
>> conflicts or fuzz.
>> - Package build completed successfully.
>> 
>> Hetvi Thakar (5):
>> libssh: Fix CVE-2026-59843
>> libssh: Fix CVE-2026-59844
>> libssh: Fix CVE-2026-59846
>> libssh: Fix CVE-2026-59848
>> libssh: Fix CVE-2026-59850
> 
> 3/5 is adding unresolved merge markers to recipe that 4/5 is then
> removing. Please fix the patches, rebase them on current scarthgap and
> resend.
> 
> Thanks,
> 
> Anuj

Hi,

Thanks for pointing this out.

I will fix the unresolved merge markers, rebase the patch series on
the current scarthgap branch, and resend the updated series.

Regards,
Hetvi

[-- Attachment #2: Type: text/html, Size: 2109 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-09-01  8:24 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01  1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal
2026-09-01  8:23   ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox