* [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs
@ 2026-08-19 11:10 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (5 more replies)
0 siblings, 6 replies; 8+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
Backport five upstream libssh security fixes to the 0.10.6 recipe on
scarthgap:
- CVE-2026-59843
- CVE-2026-59844
- CVE-2026-59846
- CVE-2026-59848
- CVE-2026-59850
Carry these as focused backports instead of upgrading libssh because
newer releases include API and functional changes outside the security
scope.
CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0.
CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on
code or features absent from 0.10.6. NVD correction requests have been
submitted for these inaccurate affected-version entries; therefore, no
CVE_STATUS entries are added.
The individual commits retain the upstream fix provenance and advisory
references for each CVE.
Testing:
- Applied all five patches to libssh 0.10.6 in series order without
conflicts or fuzz.
- Package build completed successfully.
Hetvi Thakar (5):
libssh: Fix CVE-2026-59843
libssh: Fix CVE-2026-59844
libssh: Fix CVE-2026-59846
libssh: Fix CVE-2026-59848
libssh: Fix CVE-2026-59850
.../libssh/libssh/CVE-2026-59843.patch | 84 +++
.../libssh/libssh/CVE-2026-59844.patch | 52 ++
.../libssh/libssh/CVE-2026-59846.patch | 87 +++
.../libssh/CVE-2026-59848-regression.patch | 45 ++
.../libssh/libssh/CVE-2026-59848.patch | 684 ++++++++++++++++++
.../libssh/libssh/CVE-2026-59850.patch | 40 +
.../recipes-support/libssh/libssh_0.10.6.bb | 6 +
7 files changed, 998 insertions(+)
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch
create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch
--
2.35.6
^ permalink raw reply [flat|nested] 8+ messages in thread* [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) ` (4 subsequent siblings) 5 siblings, 0 replies; 8+ messages in thread From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw) To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar From: Hetvi Thakar <hthakar@cisco.com> The stable-0.11 commit shown in [1] is the upstream fix selected for this backport. The upstream advisory [2] documents CVE-2026-59843 and identifies libssh 0.11.5 as the fixed release for the 0.11 series. [1] https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919 [2] https://www.libssh.org/security/advisories/CVE-2026-59843.txt Signed-off-by: Hetvi Thakar <hthakar@cisco.com> --- .../libssh/libssh/CVE-2026-59843.patch | 84 +++++++++++++++++++ .../recipes-support/libssh/libssh_0.10.6.bb | 1 + 2 files changed, 85 insertions(+) create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch new file mode 100644 index 0000000000..03d3ce6ea2 --- /dev/null +++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59843.patch @@ -0,0 +1,84 @@ +From d965eb941a9a83a0643570a93d8997b91e248fc1 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com> +Date: Fri, 6 Mar 2026 13:58:30 +0100 +Subject: [PATCH] CVE-2026-59843 channels: Fail when receiving max packet size + 0 +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Do this both for SSH2_MSG_CHANNEL_OPEN and for +SSH2_MSG_CHANNEL_OPEN_CONFIRMATION. Using the +max packet size 0 would lead to an infinite loop +in channel_write_common. + +Originally reported by Rinku Das on on 23th February. +Independently reported by Yi Lin on 26th February and +Haruto Kimura on 22nd March. + +We do not consider this as a security issue as connecting +to untrusted servers on the internet brings much worse +security consequences than hanging your clinet. + +Signed-off-by: Pavol Žáčik <pzacik@redhat.com> +Reviewed-by: Jakub Jelen <jjelen@redhat.com> + +CVE: CVE-2026-59843 +Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919] + +(cherry picked from commit 44b186fa17aff497dae420c59c003222e438103c) +(cherry picked from commit 687ef1c44b646b9db0b1c6e8f987edb7c9e4d919) +Signed-off-by: Hetvi Thakar <hthakar@cisco.com> +--- + src/channels.c | 7 +++++++ + src/messages.c | 19 +++++++++++++++---- + 2 files changed, 22 insertions(+), 4 deletions(-) + +diff --git a/src/channels.c b/src/channels.c +index 8290dbd1..3afdcf11 100644 +--- a/src/channels.c ++++ b/src/channels.c +@@ -192,6 +192,13 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open_conf){ + if (rc != SSH_OK) + goto error; + ++ if (channel->remote_maxpacket == 0) { ++ SSH_LOG(SSH_LOG_RARE, ++ "Invalid maximum packet size 0 in " ++ "SSH2_MSG_CHANNEL_OPEN_CONFIRMATION"); ++ goto error; ++ } ++ + SSH_LOG(SSH_LOG_PROTOCOL, + "Received a CHANNEL_OPEN_CONFIRMATION for channel %d:%d", + channel->local_channel, +diff --git a/src/messages.c b/src/messages.c +index 6dadabf0..e79ecec2 100644 +--- a/src/messages.c ++++ b/src/messages.c +@@ -1160,10 +1160,21 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open){ + SSH_LOG(SSH_LOG_PACKET, + "Clients wants to open a %s channel", type_c); + +- ssh_buffer_unpack(packet,"ddd", +- &msg->channel_request_open.sender, +- &msg->channel_request_open.window, +- &msg->channel_request_open.packet_size); ++ rc = ssh_buffer_unpack(packet, ++ "ddd", ++ &msg->channel_request_open.sender, ++ &msg->channel_request_open.window, ++ &msg->channel_request_open.packet_size); ++ if (rc != SSH_OK){ ++ goto error; ++ } ++ ++ if (msg->channel_request_open.packet_size == 0) { ++ ssh_set_error(session, ++ SSH_FATAL, ++ "Invalid maximum packet size 0 in SSH2_MSG_CHANNEL_OPEN"); ++ goto error; ++ } + + if (session->session_state != SSH_SESSION_STATE_AUTHENTICATED){ + ssh_set_error(session,SSH_FATAL, "Invalid state when receiving channel open request (must be authenticated)"); diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb index 1f64920a50..381b3efc7d 100644 --- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb +++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb @@ -32,6 +32,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable file://CVE-2026-0968-2.patch \ file://CVE-2026-0967.patch \ file://CVE-2026-0965.patch \ + file://CVE-2026-59843.patch \ " SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6" -- 2.35.6 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) ` (3 subsequent siblings) 5 siblings, 0 replies; 8+ messages in thread From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw) To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar From: Hetvi Thakar <hthakar@cisco.com> The stable-0.11 commit shown in [1] is the upstream fix selected for this backport. The upstream advisory [2] documents CVE-2026-59844 and identifies libssh 0.11.5 as the fixed release for the 0.11 series. [1] https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9 [2] https://www.libssh.org/security/advisories/CVE-2026-59844.txt Signed-off-by: Hetvi Thakar <hthakar@cisco.com> --- .../libssh/libssh/CVE-2026-59844.patch | 52 +++++++++++++++++++ .../recipes-support/libssh/libssh_0.10.6.bb | 1 + 2 files changed, 53 insertions(+) create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch new file mode 100644 index 0000000000..ac380622d9 --- /dev/null +++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59844.patch @@ -0,0 +1,52 @@ +From ef7cd6d4aef6d18ca8bf15cb0398b630284f46f4 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com> +Date: Fri, 6 Mar 2026 18:05:29 +0100 +Subject: [PATCH] CVE-2026-59844 sftpserver: cap accepted values of len in + SSH_FXP_READ +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +The client-provided length is directly used in +a malloc in process_read(), so not restricting it +leads to allocations bounded only by UINT32_MAX. + +The new cap is the same as the one currently used +by OpenSSH. + +Signed-off-by: Pavol Žáčik <pzacik@redhat.com> +Reviewed-by: Jakub Jelen <jjelen@redhat.com> + +CVE: CVE-2026-59844 +Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=e31f06e5380be4e714d5ad6965981fbf30738da9] + +Backport Changes: +- Replace the upstream goto error path with equivalent direct message cleanup + and return because libssh 0.10.6 does not have the refactored + sftp_make_client_message() error label. + +(cherry picked from commit 6dba2e06f0713c04ad5eca7d4315d0104be7e627) +(cherry picked from commit e31f06e5380be4e714d5ad6965981fbf30738da9) +Signed-off-by: Hetvi Thakar <hthakar@cisco.com> +--- + src/sftpserver.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/src/sftpserver.c b/src/sftpserver.c +index 528ef6f9..77290068 100644 +--- a/src/sftpserver.c ++++ b/src/sftpserver.c +@@ -105,6 +105,13 @@ sftp_client_message sftp_get_client_message(sftp_session sftp) { + sftp_client_message_free(msg); + return NULL; + } ++ if (msg->len > MAX_PACKET_LEN - 1024) { ++ ssh_set_error(sftp->session, SSH_FATAL, ++ "Too large SSH_FXP_READ length: %" PRIu32, ++ msg->len); ++ sftp_client_message_free(msg); ++ return NULL; ++ } + break; + case SSH_FXP_WRITE: + rc = ssh_buffer_unpack(payload, diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb index 381b3efc7d..a9d7729f2c 100644 --- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb +++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb @@ -33,6 +33,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable file://CVE-2026-0967.patch \ file://CVE-2026-0965.patch \ file://CVE-2026-59843.patch \ + file://CVE-2026-59844.patch \ " SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6" -- 2.35.6 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) ` (2 subsequent siblings) 5 siblings, 0 replies; 8+ messages in thread From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw) To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar From: Hetvi Thakar <hthakar@cisco.com> libssh 0.10.6 predates the username-validation helper used by the stable-0.11 fix, so the upstream commit in [1] cannot be applied as-is. Adapt the same dangerous-character check directly at the ProxyCommand %r expansion sink and add focused regression coverage. The upstream advisory [2] identifies libssh 0.11.5 and 0.12.1 as the fixed releases. [1] https://gitlab.com/libssh/libssh-mirror/-/commit/56ce3c193eb06af5bf3b07ec0b4c7308b5c72130 [2] https://www.libssh.org/security/advisories/CVE-2026-59846.txt Signed-off-by: Hetvi Thakar <hthakar@cisco.com> --- .../libssh/libssh/CVE-2026-59846.patch | 87 +++++++++++++++++++ .../recipes-support/libssh/libssh_0.10.6.bb | 5 ++ 2 files changed, 92 insertions(+) create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch new file mode 100644 index 0000000000..9c626d113d --- /dev/null +++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59846.patch @@ -0,0 +1,87 @@ +From 19fe4c9fc7b3bd3553250bf9ddea03ed1dcf044f Mon Sep 17 00:00:00 2001 +From: Jakub Jelen <jjelen@redhat.com> +Date: Thu, 2 Apr 2026 15:39:25 +0200 +Subject: [PATCH] CVE-2026-59846 Block shell metacharacters from usernames +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +When an attacker could sneak the dollar sign or backslash into the username +expanded for example in proxy command, it can result in printing environment +variables that might contain secrets. + +This is a fixup of CVE-2023-6004 which fixed this for hostnames, but these +two metacharacters were left out from the username filter. + +This keeps the list in one place to simplify maintenance. + +Signed-off-by: Jakub Jelen <jjelen@redhat.com> +Reviewed-by: Pavol Žáčik <pzacik@redhat.com> +(cherry picked from commit 6309df220e3431deb41946f892f4bb5af8b59dba) + +CVE: CVE-2026-59846 +Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=56ce3c193eb06af5bf3b07ec0b4c7308b5c72130] + +Backport Changes: +- libssh 0.10.6 predates ssh_check_username_syntax() and the centralized + SSH_DANGEROUS_SHELL_CHARS definition, so enforce the same character list + directly at the %r expansion sink in ssh_path_expand_escape(). +- Add focused regression coverage to the existing path-expansion unit test + for dollar-sign, backslash, and command-separator usernames. + +(cherry picked from commit 56ce3c193eb06af5bf3b07ec0b4c7308b5c72130) +Signed-off-by: Hetvi Thakar <hthakar@cisco.com> +--- + src/misc.c | 9 +++++++++ + tests/unittests/torture_misc.c | 18 ++++++++++++++++++ + 2 files changed, 27 insertions(+) + +diff --git a/src/misc.c b/src/misc.c +index e78c92ba..15b427d7 100644 +--- a/src/misc.c ++++ b/src/misc.c +@@ -1262,6 +1262,15 @@ char *ssh_path_expand_escape(ssh_session session, const char *s) + break; + case 'r': + if (session->opts.username) { ++ if (strpbrk(session->opts.username, ++ "'`\";&<>|(){}$\\,") != NULL) { ++ ssh_set_error(session, ++ SSH_FATAL, ++ "Invalid shell metacharacter in username"); ++ free(buf); ++ free(r); ++ return NULL; ++ } + x = strdup(session->opts.username); + } else { + ssh_set_error(session, SSH_FATAL, +diff --git a/tests/unittests/torture_misc.c b/tests/unittests/torture_misc.c +index 82d6cf16..66d392ed 100644 +--- a/tests/unittests/torture_misc.c ++++ b/tests/unittests/torture_misc.c +@@ -194,6 +194,24 @@ static void torture_path_expand_escape(void **state) { + assert_non_null(e); + assert_string_equal(e, "guru/meditation/222/by/root"); + ssh_string_free_char(e); ++ ++ free(session->opts.username); ++ session->opts.username = strdup("root$HOME"); ++ assert_non_null(session->opts.username); ++ e = ssh_path_expand_escape(session, s); ++ assert_null(e); ++ ++ free(session->opts.username); ++ session->opts.username = strdup("root\\user"); ++ assert_non_null(session->opts.username); ++ e = ssh_path_expand_escape(session, s); ++ assert_null(e); ++ ++ free(session->opts.username); ++ session->opts.username = strdup("root;id"); ++ assert_non_null(session->opts.username); ++ e = ssh_path_expand_escape(session, s); ++ assert_null(e); + } + + static void torture_path_expand_known_hosts(void **state) { diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb index a9d7729f2c..8e86073fd3 100644 --- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb +++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb @@ -34,6 +34,11 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable file://CVE-2026-0965.patch \ file://CVE-2026-59843.patch \ file://CVE-2026-59844.patch \ +<<<<<<< HEAD +======= + file://CVE-2026-59845.patch \ + file://CVE-2026-59846.patch \ +>>>>>>> b782f294a0 (libssh: Fix CVE-2026-59846) " SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6" -- 2.35.6 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) ` (2 preceding siblings ...) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal 5 siblings, 0 replies; 8+ messages in thread From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw) To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar From: Hetvi Thakar <hthakar@cisco.com> The stable-0.11 commit shown in [1] is the primary upstream fix selected for this backport. Commit [2] corrects the request-queue pointer state introduced by [1], so it is carried immediately afterward as a regression fix. The upstream advisory [3] documents CVE-2026-59848 and identifies libssh 0.11.5 as the fixed release for the 0.11 series. [1] https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497 [2] https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be [3] https://www.libssh.org/security/advisories/CVE-2026-59848.txt Signed-off-by: Hetvi Thakar <hthakar@cisco.com> --- .../libssh/CVE-2026-59848-regression.patch | 45 ++ .../libssh/libssh/CVE-2026-59848.patch | 684 ++++++++++++++++++ .../recipes-support/libssh/libssh_0.10.6.bb | 6 +- 3 files changed, 731 insertions(+), 4 deletions(-) create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch new file mode 100644 index 0000000000..161271264f --- /dev/null +++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848-regression.patch @@ -0,0 +1,45 @@ +From dddd93ac995ac382e4ec9496509f24003bd72c30 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com> +Date: Wed, 3 Jun 2026 12:56:09 +0200 +Subject: [PATCH] CVE-2026-59848 sftp: Initialize sftp_request_queue ptr in + sftp_free +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Signed-off-by: Pavol Žáčik <pzacik@redhat.com> +Reviewed-by: Jakub Jelen <jjelen@redhat.com> + +CVE: CVE-2026-59848 +Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=5309aefd99e1775db40bf20869f1fb1cc6c787be] + +Backport Changes: +- Adjusted hunk context for the consolidated libssh 0.10.6 SFTP + implementation; the pointer initialization is unchanged from upstream. +- Omitted the upstream tests/client/torture_sftp_request_id.c follow-up hunk + because CVE-2026-59848.patch introduces the backported regression test + directly with sftp_read_and_dispatch(); there is no intermediate + sftp_recv_response_msg() version to update. + +(cherry picked from commit 00876f7658fd265682708572122502188fa22076) +(cherry picked from commit 5309aefd99e1775db40bf20869f1fb1cc6c787be) +Signed-off-by: Hetvi Thakar <hthakar@cisco.com> +--- + src/sftp.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/sftp.c b/src/sftp.c +index e6755e2b..ff6e5200 100644 +--- a/src/sftp.c ++++ b/src/sftp.c +@@ -371,7 +371,7 @@ void sftp_server_free(sftp_session sftp) + + void sftp_free(sftp_session sftp) + { +- sftp_request_queue ptr; ++ sftp_request_queue ptr = NULL; + struct ssh_iterator *id_it = NULL; + + if (sftp == NULL) { +-- +2.35.6 diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch new file mode 100644 index 0000000000..2f4efb22f1 --- /dev/null +++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59848.patch @@ -0,0 +1,684 @@ +From ef75e652dd2808c27251da4d03feef84d158c1de Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com> +Date: Mon, 1 Jun 2026 16:33:03 +0200 +Subject: [PATCH] CVE-2026-59848 sftp: handle responses with unknown request + IDs +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +This adds a new field to sftp_session_struct, +containing a list of outstanding request IDs. +An ID is added to the list when a request +is constructed and removed when the corresponding +request is received. If a client receives a response +with an unknown request ID, it reports an error. + +Storing responses with unknown request IDs in +the response queue could be abused by a malicious +SFTP server which could deplete client memory +this way. + +Signed-off-by: Pavol Žáčik <pzacik@redhat.com> +Reviewed-by: Jakub Jelen <jjelen@redhat.com> + +CVE: CVE-2026-59848 +Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=a30a51003205744c10ba4439306f555206ae8497] + +Backport Changes: +- Consolidated the upstream src/sftp_common.c and src/sftp_aio.c changes + into src/sftp.c, where libssh 0.10.6 implements response dispatch, + request-ID allocation, and asynchronous SFTP reads. +- Kept sftp_get_new_id() static instead of exporting it through + sftp_priv.h because all 20 request-producing call sites in 0.10.6 are + in src/sftp.c; newer-only SFTP API call sites are absent. +- Retained the 0.10.6 request construction order and free the existing + request buffer when request-ID tracking fails. +- Adapted the unknown-ID regression test to call + sftp_read_and_dispatch() and verify the response queue remains empty; + 0.10.6 does not provide sftp_recv_response_msg(). + +(cherry picked from commit 26147eb4767937c797f97ff3b1b1663384232417) +(cherry picked from commit a30a51003205744c10ba4439306f555206ae8497) +Signed-off-by: Hetvi Thakar <hthakar@cisco.com> +--- + include/libssh/sftp.h | 1 + + src/sftp.c | 210 ++++++++++++++++++++++--- + tests/client/CMakeLists.txt | 1 + + tests/client/torture_sftp_request_id.c | 183 +++++++++++++++++++++ + 4 files changed, 369 insertions(+), 26 deletions(-) + create mode 100644 tests/client/torture_sftp_request_id.c + +diff --git a/include/libssh/sftp.h b/include/libssh/sftp.h +index c713466e..984c4eb7 100644 +--- a/include/libssh/sftp.h ++++ b/include/libssh/sftp.h +@@ -90,6 +90,7 @@ struct sftp_session_struct { + void **handles; + sftp_ext ext; + sftp_packet read_packet; ++ struct ssh_list *outstanding_ids; + }; + + struct sftp_packet_struct { +diff --git a/src/sftp.c b/src/sftp.c +index 2194a9ef..e6755e2b 100644 +--- a/src/sftp.c ++++ b/src/sftp.c +@@ -149,6 +149,12 @@ sftp_session sftp_new(ssh_session session) + goto error; + } + ++ sftp->outstanding_ids = ssh_list_new(); ++ if (sftp->outstanding_ids == NULL) { ++ ssh_set_error_oom(session); ++ goto error; ++ } ++ + if (ssh_channel_open_session(sftp->channel)) { + goto error; + } +@@ -165,6 +171,7 @@ error: + if (sftp->channel != NULL) { + ssh_channel_free(sftp->channel); + } ++ ssh_list_free(sftp->outstanding_ids); + if (sftp->read_packet != NULL) { + if (sftp->read_packet->payload != NULL) { + SSH_BUFFER_FREE(sftp->read_packet->payload); +@@ -196,6 +203,12 @@ sftp_new_channel(ssh_session session, ssh_channel channel) + goto error; + } + ++ sftp->outstanding_ids = ssh_list_new(); ++ if (sftp->outstanding_ids == NULL) { ++ ssh_set_error_oom(session); ++ goto error; ++ } ++ + sftp->read_packet = calloc(1, sizeof(struct sftp_packet_struct)); + if (sftp->read_packet == NULL) { + ssh_set_error_oom(session); +@@ -217,6 +230,7 @@ error: + if (sftp->ext != NULL) { + sftp_ext_free(sftp->ext); + } ++ ssh_list_free(sftp->outstanding_ids); + if (sftp->read_packet != NULL) { + if (sftp->read_packet->payload != NULL) { + SSH_BUFFER_FREE(sftp->read_packet->payload); +@@ -358,6 +372,7 @@ void sftp_server_free(sftp_session sftp) + void sftp_free(sftp_session sftp) + { + sftp_request_queue ptr; ++ struct ssh_iterator *id_it = NULL; + + if (sftp == NULL) { + return; +@@ -384,6 +399,12 @@ void sftp_free(sftp_session sftp) + + sftp_ext_free(sftp->ext); + ++ id_it = ssh_list_get_iterator(sftp->outstanding_ids); ++ for (; id_it != NULL; id_it = id_it->next) { ++ free((uint32_t *)id_it->data); ++ } ++ ssh_list_free(sftp->outstanding_ids); ++ + SAFE_FREE(sftp); + } + +@@ -571,6 +592,8 @@ static sftp_message sftp_get_message(sftp_packet packet) + { + sftp_session sftp = packet->sftp; + sftp_message msg = NULL; ++ struct ssh_iterator *id_it = NULL; ++ bool id_found = false; + int rc; + + switch(packet->type) { +@@ -618,6 +641,28 @@ static sftp_message sftp_get_message(sftp_packet packet) + msg->id, + msg->packet_type); + ++ /* Validate that this ID is in our outstanding requests list */ ++ id_it = ssh_list_get_iterator(sftp->outstanding_ids); ++ for (; id_it != NULL; id_it = id_it->next) { ++ uint32_t *stored_id = (uint32_t *)id_it->data; ++ if (*stored_id == msg->id) { ++ id_found = true; ++ ssh_list_remove(sftp->outstanding_ids, id_it); ++ free(stored_id); ++ break; ++ } ++ } ++ ++ if (!id_found) { ++ ssh_set_error(packet->sftp->session, ++ SSH_FATAL, ++ "Unknown request ID %" PRIu32, ++ msg->id); ++ sftp_message_free(msg); ++ sftp_set_error(packet->sftp, SSH_FX_FAILURE); ++ return NULL; ++ } ++ + return msg; + } + +@@ -902,13 +947,46 @@ static sftp_message sftp_dequeue(sftp_session sftp, uint32_t id){ + return NULL; + } + +-/* +- * Assigns a new SFTP ID for new requests and assures there is no collision +- * between them. +- * Returns a new ID ready to use in a request ++/** ++ * @brief Assigns a new SFTP ID for new requests and assures there is no ++ * collision between them. ++ * ++ * @param sftp The sftp session handle. ++ * @param id_out Pointer to store the new ID. ++ * ++ * @returns SSH_OK on success with the new ID stored in *id ++ * @returns SSH_ERROR on failure with the sftp and ssh errors set + */ +-static inline uint32_t sftp_get_new_id(sftp_session session) { +- return ++session->id_counter; ++static int sftp_get_new_id(sftp_session sftp, uint32_t *id_out) ++{ ++ uint32_t *id = NULL; ++ int rc; ++ ++ if (id_out == NULL) { ++ ssh_set_error_invalid(sftp->session); ++ sftp_set_error(sftp, SSH_FX_FAILURE); ++ return SSH_ERROR; ++ } ++ ++ id = malloc(sizeof(uint32_t)); ++ if (id == NULL) { ++ ssh_set_error_oom(sftp->session); ++ sftp_set_error(sftp, SSH_FX_FAILURE); ++ return SSH_ERROR; ++ } ++ ++ *id = ++sftp->id_counter; ++ rc = ssh_list_append(sftp->outstanding_ids, id); ++ if (rc != SSH_OK) { ++ free(id); ++ ssh_set_error_oom(sftp->session); ++ sftp_set_error(sftp, SSH_FX_FAILURE); ++ return SSH_ERROR; ++ } ++ ++ *id_out = *id; ++ ++ return SSH_OK; + } + + static sftp_status_message parse_status_msg(sftp_message msg){ +@@ -1029,7 +1107,11 @@ sftp_dir sftp_opendir(sftp_session sftp, const char *path) + return NULL; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(payload); ++ return NULL; ++ } + + rc = ssh_buffer_pack(payload, + "ds", +@@ -1571,7 +1653,11 @@ sftp_attributes sftp_readdir(sftp_session sftp, sftp_dir dir) + return NULL; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(payload); ++ return NULL; ++ } + + rc = ssh_buffer_pack(payload, + "dS", +@@ -1704,7 +1790,11 @@ static int sftp_handle_close(sftp_session sftp, ssh_string handle) + return -1; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "dS", +@@ -1835,7 +1925,11 @@ sftp_file sftp_open(sftp_session sftp, + sftp_flags |= SSH_FXF_APPEND; + } + SSH_LOG(SSH_LOG_PACKET,"Opening file %s with sftp flags %x",file,sftp_flags); +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return NULL; ++ } + + rc = ssh_buffer_pack(buffer, + "dsd", +@@ -1946,7 +2040,11 @@ ssize_t sftp_read(sftp_file handle, void *buf, size_t count) { + return -1; + } + +- id = sftp_get_new_id(handle->sftp); ++ rc = sftp_get_new_id(handle->sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "dSqd", +@@ -2047,7 +2145,11 @@ int sftp_async_read_begin(sftp_file file, uint32_t len){ + return -1; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "dSqd", +@@ -2173,7 +2275,11 @@ ssize_t sftp_write(sftp_file file, const void *buf, size_t count) { + return -1; + } + +- id = sftp_get_new_id(file->sftp); ++ rc = sftp_get_new_id(file->sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "dSqdP", +@@ -2291,7 +2397,11 @@ int sftp_unlink(sftp_session sftp, const char *file) { + return -1; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "ds", +@@ -2366,7 +2476,11 @@ int sftp_rmdir(sftp_session sftp, const char *directory) { + return -1; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "ds", +@@ -2443,7 +2557,11 @@ int sftp_mkdir(sftp_session sftp, const char *directory, mode_t mode) + attr.permissions = mode; + attr.flags = SSH_FILEXFER_ATTR_PERMISSIONS; + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "ds", +@@ -2538,7 +2656,11 @@ int sftp_rename(sftp_session sftp, const char *original, const char *newname) { + return -1; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "dss", +@@ -2622,7 +2744,11 @@ int sftp_setstat(sftp_session sftp, const char *file, sftp_attributes attr) + return -1; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "ds", +@@ -2752,7 +2878,11 @@ int sftp_symlink(sftp_session sftp, const char *target, const char *dest) { + return -1; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + /* TODO check for version number if they ever fix it. */ + if (ssh_get_openssh_version(sftp->session)) { +@@ -2850,7 +2980,11 @@ char *sftp_readlink(sftp_session sftp, const char *path) + return NULL; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return NULL; ++ } + + rc = ssh_buffer_pack(buffer, + "ds", +@@ -2976,7 +3110,11 @@ sftp_statvfs_t sftp_statvfs(sftp_session sftp, const char *path) + return NULL; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return NULL; ++ } + + rc = ssh_buffer_pack(buffer, + "dss", +@@ -3051,7 +3189,11 @@ int sftp_fsync(sftp_file file) + return -1; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return -1; ++ } + + rc = ssh_buffer_pack(buffer, + "dsS", +@@ -3151,7 +3293,11 @@ sftp_statvfs_t sftp_fstatvfs(sftp_file file) + return NULL; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return NULL; ++ } + + rc = ssh_buffer_pack(buffer, + "dsS", +@@ -3238,7 +3384,11 @@ char *sftp_canonicalize_path(sftp_session sftp, const char *path) + return NULL; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return NULL; ++ } + + rc = ssh_buffer_pack(buffer, + "ds", +@@ -3329,7 +3479,11 @@ static sftp_attributes sftp_xstat(sftp_session sftp, + return NULL; + } + +- id = sftp_get_new_id(sftp); ++ rc = sftp_get_new_id(sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return NULL; ++ } + + rc = ssh_buffer_pack(buffer, + "ds", +@@ -3407,7 +3561,11 @@ sftp_attributes sftp_fstat(sftp_file file) + return NULL; + } + +- id = sftp_get_new_id(file->sftp); ++ rc = sftp_get_new_id(file->sftp, &id); ++ if (rc != SSH_OK) { ++ SSH_BUFFER_FREE(buffer); ++ return NULL; ++ } + + rc = ssh_buffer_pack(buffer, + "dS", +diff --git a/tests/client/CMakeLists.txt b/tests/client/CMakeLists.txt +index 71e5182e..864478a7 100644 +--- a/tests/client/CMakeLists.txt ++++ b/tests/client/CMakeLists.txt +@@ -49,6 +49,7 @@ if (WITH_SFTP) + torture_sftp_dir + torture_sftp_read + torture_sftp_fsync ++ torture_sftp_request_id + ${SFTP_BENCHMARK_TESTS}) + endif (WITH_SFTP) + +diff --git a/tests/client/torture_sftp_request_id.c b/tests/client/torture_sftp_request_id.c +new file mode 100644 +index 00000000..fe6d3f91 +--- /dev/null ++++ b/tests/client/torture_sftp_request_id.c +@@ -0,0 +1,183 @@ ++#include "config.h" ++ ++#define LIBSSH_STATIC ++ ++#include "sftp.c" ++#include "torture.h" ++ ++#include <pwd.h> ++#include <sys/types.h> ++ ++static int sshd_setup(void **state) ++{ ++ torture_setup_sshd_server(state, false); ++ ++ return 0; ++} ++ ++static int sshd_teardown(void **state) ++{ ++ torture_teardown_sshd_server(state); ++ ++ return 0; ++} ++ ++static int session_setup(void **state) ++{ ++ struct torture_state *s = *state; ++ struct passwd *pwd = NULL; ++ int rc; ++ ++ pwd = getpwnam("bob"); ++ assert_non_null(pwd); ++ ++ rc = setuid(pwd->pw_uid); ++ assert_return_code(rc, errno); ++ ++ s->ssh.session = torture_ssh_session(s, ++ TORTURE_SSH_SERVER, ++ NULL, ++ TORTURE_SSH_USER_ALICE, ++ NULL); ++ assert_non_null(s->ssh.session); ++ ++ s->ssh.tsftp = torture_sftp_session(s->ssh.session); ++ assert_non_null(s->ssh.tsftp); ++ ++ return 0; ++} ++ ++static int session_teardown(void **state) ++{ ++ struct torture_state *s = *state; ++ ++ torture_rmdirs(s->ssh.tsftp->testdir); ++ torture_sftp_close(s->ssh.tsftp); ++ ssh_disconnect(s->ssh.session); ++ ssh_free(s->ssh.session); ++ ++ return 0; ++} ++ ++static void torture_sftp_request_id_null(void **state) ++{ ++ struct torture_state *s = *state; ++ struct torture_sftp *t = s->ssh.tsftp; ++ sftp_session sftp = t->sftp; ++ int rc; ++ ++ rc = sftp_get_new_id(sftp, NULL); ++ assert_int_equal(rc, SSH_ERROR); ++} ++ ++static void torture_sftp_request_id_add(void **state) ++{ ++ struct torture_state *s = *state; ++ struct torture_sftp *t = s->ssh.tsftp; ++ sftp_session sftp = t->sftp; ++ uint32_t id1, id2; ++ int rc; ++ size_t count; ++ ++ /* The list of IDs should be empty at first */ ++ count = ssh_list_count(sftp->outstanding_ids); ++ assert_int_equal(count, 0); ++ ++ /* Request a new ID */ ++ rc = sftp_get_new_id(sftp, &id1); ++ assert_int_equal(rc, SSH_OK); ++ ++ /* Check that the list has one ID now */ ++ count = ssh_list_count(sftp->outstanding_ids); ++ assert_int_equal(count, 1); ++ ++ /* Request another ID */ ++ rc = sftp_get_new_id(sftp, &id2); ++ assert_int_equal(rc, SSH_OK); ++ ++ /* Check that the IDs differ */ ++ assert_int_not_equal(id1, id2); ++ ++ /* Check that the list has two IDs now */ ++ count = ssh_list_count(sftp->outstanding_ids); ++ assert_int_equal(count, 2); ++} ++ ++static void torture_sftp_request_id_remove(void **state) ++{ ++ struct torture_state *s = *state; ++ struct torture_sftp *t = s->ssh.tsftp; ++ sftp_session sftp = t->sftp; ++ sftp_attributes attr = NULL; ++ size_t count; ++ ++ count = ssh_list_count(sftp->outstanding_ids); ++ assert_int_equal(count, 0); ++ ++ /* We send a request and receive a response */ ++ attr = sftp_stat(sftp, SSH_EXECUTABLE); ++ assert_non_null(attr); ++ ++ /* The number of outstanding requests should be back to 0 */ ++ count = ssh_list_count(sftp->outstanding_ids); ++ assert_int_equal(count, 0); ++ ++ sftp_attributes_free(attr); ++} ++ ++static void torture_sftp_request_id_unknown(void **state) ++{ ++ struct torture_state *s = *state; ++ struct torture_sftp *t = s->ssh.tsftp; ++ sftp_session sftp = t->sftp; ++ ssh_buffer buffer = NULL; ++ uint32_t id = 0; ++ int rc; ++ size_t count; ++ ++ count = ssh_list_count(sftp->outstanding_ids); ++ assert_int_equal(count, 0); ++ ++ buffer = ssh_buffer_new(); ++ assert_non_null(buffer); ++ ++ rc = ssh_buffer_pack(buffer, "ds", id, "/tmp"); ++ assert_int_equal(rc, SSH_OK); ++ ++ /* Send a request without saving the request ID */ ++ rc = sftp_packet_write(sftp, SSH_FXP_OPENDIR, buffer); ++ assert_int_not_equal(rc, -1); ++ SSH_BUFFER_FREE(buffer); ++ ++ /* An attempt to receive the response should fail without queuing it */ ++ rc = sftp_read_and_dispatch(sftp); ++ assert_int_equal(rc, -1); ++ assert_null(sftp->queue); ++} ++ ++int torture_run_tests(void) ++{ ++ int rc; ++ struct CMUnitTest tests[] = { ++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_null, ++ session_setup, ++ session_teardown), ++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_add, ++ session_setup, ++ session_teardown), ++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_remove, ++ session_setup, ++ session_teardown), ++ cmocka_unit_test_setup_teardown(torture_sftp_request_id_unknown, ++ session_setup, ++ session_teardown), ++ }; ++ ++ ssh_init(); ++ ++ torture_filter_tests(tests); ++ rc = cmocka_run_group_tests(tests, sshd_setup, sshd_teardown); ++ ssh_finalize(); ++ ++ return rc; ++} +-- +2.35.6 diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb index 8e86073fd3..1a5f521f6a 100644 --- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb +++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb @@ -34,11 +34,9 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable file://CVE-2026-0965.patch \ file://CVE-2026-59843.patch \ file://CVE-2026-59844.patch \ -<<<<<<< HEAD -======= - file://CVE-2026-59845.patch \ file://CVE-2026-59846.patch \ ->>>>>>> b782f294a0 (libssh: Fix CVE-2026-59846) + file://CVE-2026-59848.patch \ + file://CVE-2026-59848-regression.patch \ " SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6" -- 2.35.6 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) ` (3 preceding siblings ...) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal 5 siblings, 0 replies; 8+ messages in thread From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-19 11:10 UTC (permalink / raw) To: openembedded-devel; +Cc: xe-linux-external, Hetvi Thakar From: Hetvi Thakar <hthakar@cisco.com> The stable-0.11 commit shown in [1] is the upstream fix selected for this backport. The upstream advisory [2] documents CVE-2026-59850 and identifies libssh 0.11.5 as the fixed release for the 0.11 series. [1] https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2 [2] https://www.libssh.org/security/advisories/CVE-2026-59850.txt Signed-off-by: Hetvi Thakar <hthakar@cisco.com> --- .../libssh/libssh/CVE-2026-59850.patch | 40 +++++++++++++++++++ .../recipes-support/libssh/libssh_0.10.6.bb | 1 + 2 files changed, 41 insertions(+) create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch diff --git a/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch new file mode 100644 index 0000000000..61e502c796 --- /dev/null +++ b/meta-oe/recipes-support/libssh/libssh/CVE-2026-59850.patch @@ -0,0 +1,40 @@ +From a207ee3b4244c0e5da902245f8b81f3617b416f3 Mon Sep 17 00:00:00 2001 +From: Jakub Jelen <jjelen@redhat.com> +Date: Wed, 1 Jul 2026 16:43:08 +0200 +Subject: [PATCH] CVE-2026-59850 channels: Avoid processing DATA packets on + closed channels +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Signed-off-by: Jakub Jelen <jjelen@redhat.com> +Reviewed-by: Pavol Žáčik <pzacik@redhat.com> + +CVE: CVE-2026-59850 +Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=6edfb52b3b364577d2db0334c0514a977efceed2] + +(cherry picked from commit a8a3fa352bb5213e08a35e4494c6e44360e2e38a) +(cherry picked from commit 6edfb52b3b364577d2db0334c0514a977efceed2) +Signed-off-by: Hetvi Thakar <hthakar@cisco.com> +--- + src/channels.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/src/channels.c b/src/channels.c +index 3afdcf11..1543c792 100644 +--- a/src/channels.c ++++ b/src/channels.c +@@ -575,6 +575,13 @@ SSH_PACKET_CALLBACK(channel_rcv_data){ + channel->local_window, + channel->remote_window); + ++ if (channel->flags & SSH_CHANNEL_FLAG_CLOSED_REMOTE) { ++ SSH_LOG(SSH_LOG_WARNING, "Received data on (remotely) closed channel"); ++ ssh_set_error(session, SSH_FATAL, "Received data on (remotely) closed channel"); ++ SSH_STRING_FREE(str); ++ return SSH_PACKET_USED; ++ } ++ + /* What shall we do in this case? Let's accept it anyway */ + if (len > channel->local_window) { + SSH_LOG(SSH_LOG_RARE, diff --git a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb index 1a5f521f6a..cc957d62ca 100644 --- a/meta-oe/recipes-support/libssh/libssh_0.10.6.bb +++ b/meta-oe/recipes-support/libssh/libssh_0.10.6.bb @@ -37,6 +37,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable file://CVE-2026-59846.patch \ file://CVE-2026-59848.patch \ file://CVE-2026-59848-regression.patch \ + file://CVE-2026-59850.patch \ " SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6" -- 2.35.6 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs 2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) ` (4 preceding siblings ...) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-01 1:37 ` Anuj Mittal 2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 5 siblings, 1 reply; 8+ messages in thread From: Anuj Mittal @ 2026-09-01 1:37 UTC (permalink / raw) To: hthakar; +Cc: openembedded-devel, xe-linux-external On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org <hthakar=cisco.com@lists.openembedded.org> wrote: > > From: Hetvi Thakar <hthakar@cisco.com> > > Backport five upstream libssh security fixes to the 0.10.6 recipe on > scarthgap: > > - CVE-2026-59843 > - CVE-2026-59844 > - CVE-2026-59846 > - CVE-2026-59848 > - CVE-2026-59850 > > Carry these as focused backports instead of upgrading libssh because > newer releases include API and functional changes outside the security > scope. > > CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0. > CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on > code or features absent from 0.10.6. NVD correction requests have been > submitted for these inaccurate affected-version entries; therefore, no > CVE_STATUS entries are added. > > The individual commits retain the upstream fix provenance and advisory > references for each CVE. > > Testing: > - Applied all five patches to libssh 0.10.6 in series order without > conflicts or fuzz. > - Package build completed successfully. > > Hetvi Thakar (5): > libssh: Fix CVE-2026-59843 > libssh: Fix CVE-2026-59844 > libssh: Fix CVE-2026-59846 > libssh: Fix CVE-2026-59848 > libssh: Fix CVE-2026-59850 3/5 is adding unresolved merge markers to recipe that 4/5 is then removing. Please fix the patches, rebase them on current scarthgap and resend. Thanks, Anuj ^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs 2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal @ 2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 0 siblings, 0 replies; 8+ messages in thread From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-01 8:23 UTC (permalink / raw) To: openembedded-devel [-- Attachment #1: Type: text/plain, Size: 1811 bytes --] On Tue, Sep 1, 2026 at 07:07 AM, Anuj Mittal wrote: > > On Wed, Aug 19, 2026 at 7:10 PM Hetvi Thakar -X (hthakar - E INFOCHIPS > PRIVATE LIMITED at Cisco) via lists.openembedded.org > <hthakar=cisco.com@lists.openembedded.org> wrote: > >> From: Hetvi Thakar <hthakar@cisco.com> >> >> Backport five upstream libssh security fixes to the 0.10.6 recipe on >> scarthgap: >> >> - CVE-2026-59843 >> - CVE-2026-59844 >> - CVE-2026-59846 >> - CVE-2026-59848 >> - CVE-2026-59850 >> >> Carry these as focused backports instead of upgrading libssh because >> newer releases include API and functional changes outside the security >> scope. >> >> CVE-2026-15370 and CVE-2026-59849 affect libssh >= 0.11.0. >> CVE-2026-59842 and CVE-2026-59851 affect only libssh 0.12.0 and rely on >> code or features absent from 0.10.6. NVD correction requests have been >> submitted for these inaccurate affected-version entries; therefore, no >> CVE_STATUS entries are added. >> >> The individual commits retain the upstream fix provenance and advisory >> references for each CVE. >> >> Testing: >> - Applied all five patches to libssh 0.10.6 in series order without >> conflicts or fuzz. >> - Package build completed successfully. >> >> Hetvi Thakar (5): >> libssh: Fix CVE-2026-59843 >> libssh: Fix CVE-2026-59844 >> libssh: Fix CVE-2026-59846 >> libssh: Fix CVE-2026-59848 >> libssh: Fix CVE-2026-59850 > > 3/5 is adding unresolved merge markers to recipe that 4/5 is then > removing. Please fix the patches, rebase them on current scarthgap and > resend. > > Thanks, > > Anuj Hi, Thanks for pointing this out. I will fix the unresolved merge markers, rebase the patch series on the current scarthgap branch, and resend the updated series. Regards, Hetvi [-- Attachment #2: Type: text/html, Size: 2109 bytes --] ^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-01 8:24 UTC | newest] Thread overview: 8+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-08-19 11:10 [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 1/5] libssh: Fix CVE-2026-59843 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 2/5] libssh: Fix CVE-2026-59844 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 3/5] libssh: Fix CVE-2026-59846 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 4/5] libssh: Fix CVE-2026-59848 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-08-19 11:10 ` [meta-oe][scarthgap][PATCH 5/5] libssh: Fix CVE-2026-59850 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) 2026-09-01 1:37 ` [oe] [meta-oe][scarthgap][PATCH 0/5] libssh: Fix multiple CVEs Anuj Mittal 2026-09-01 8:23 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox