[Git][security-tracker-team/security-tracker][master] Track fixes for two libssh2 issues via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 16 19:38:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bcb80d5f by Salvatore Bonaccorso at 2026-08-16T20:36:46+02:00
Track fixes for two libssh2 issues via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -48425,12 +48425,12 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-th
NOTE: https://github.com/bikini/exploitarium/tree/main/7zip-rar5-motw-chain-poc
NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ...)
- - libssh2 <unfixed> (bug #1144415)
+ - libssh2 1.11.1-6 (bug #1144415)
NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
NOTE: https://github.com/libssh2/libssh2/pull/2127
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...)
- - libssh2 <unfixed> (bug #1144415)
+ - libssh2 1.11.1-6 (bug #1144415)
NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
NOTE: https://github.com/libssh2/libssh2/pull/2128
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bcb80d5f9bbfbd0cb0b91154f33b019c8e2e1c3a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bcb80d5f9bbfbd0cb0b91154f33b019c8e2e1c3a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/5f410ee4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list