[Git][security-tracker-team/security-tracker][master] Update status for two libssh2 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 10 19:40:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cc4c68b6 by Salvatore Bonaccorso at 2026-08-10T20:39:39+02:00
Update status for two libssh2 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37403,13 +37403,15 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-th
 	NOTE: https://github.com/bikini/exploitarium/tree/main/7zip-rar5-motw-chain-poc
 	NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
 CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but  ...)
-	- libssh2 <undetermined>
+	- libssh2 <unfixed>
 	NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
-	TODO: check with upstream, only affecting libssh2 on Windows?
+	NOTE: https://github.com/libssh2/libssh2/pull/2127
+	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
 CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...)
-	- libssh2 <undetermined>
+	- libssh2 <unfixed>
 	NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
-	TODO: check with upstream, only affecting libssh2 on Windows?
+	NOTE: https://github.com/libssh2/libssh2/pull/2128
+	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12
 CVE-2026-58049 (FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) perform ...)
 	- ffmpeg <unfixed>
 	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cc4c68b68df3cf8c144773df484cb3e0dc022167

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cc4c68b68df3cf8c144773df484cb3e0dc022167
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/a1147430/attachment.htm>


More information about the debian-security-tracker-commits mailing list