[Git][security-tracker-team/security-tracker][master] Update status for two libssh2 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 10 19:40:48 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cc4c68b6 by Salvatore Bonaccorso at 2026-08-10T20:39:39+02:00
Update status for two libssh2 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -37403,13 +37403,15 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-th
NOTE: https://github.com/bikini/exploitarium/tree/main/7zip-rar5-motw-chain-poc
NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ...)
- - libssh2 <undetermined>
+ - libssh2 <unfixed>
NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
- TODO: check with upstream, only affecting libssh2 on Windows?
+ NOTE: https://github.com/libssh2/libssh2/pull/2127
+ NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...)
- - libssh2 <undetermined>
+ - libssh2 <unfixed>
NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
- TODO: check with upstream, only affecting libssh2 on Windows?
+ NOTE: https://github.com/libssh2/libssh2/pull/2128
+ NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12
CVE-2026-58049 (FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) perform ...)
- ffmpeg <unfixed>
[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cc4c68b68df3cf8c144773df484cb3e0dc022167
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cc4c68b68df3cf8c144773df484cb3e0dc022167
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/a1147430/attachment.htm>
More information about the debian-security-tracker-commits
mailing list