[Git][security-tracker-team/security-tracker][master] Mark libssh2 issues as no-dsa
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 10:15:28 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f038cb68 by Salvatore Bonaccorso at 2026-08-21T10:50:57+02:00
Mark libssh2 issues as no-dsa
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -31818,16 +31818,19 @@ CVE-2026-66142 (Apache Neethi is vulnerable to uncontrolled recursion when parsi
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authen ...)
- libssh2 1.11.1-5 (bug #1142856)
+ [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
[bookworm] - libssh2 <not-affected> (Vulnerable code not present)
[bullseye] - libssh2 <not-affected> (Vulnerable code not present)
NOTE: https://github.com/libssh2/libssh2/pull/2198
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bo ...)
- libssh2 1.11.1-5 (bug #1142856)
+ [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE: https://github.com/libssh2/libssh2/pull/2202
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9
CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authen ...)
- libssh2 1.11.1-5 (bug #1142856)
+ [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
[bookworm] - libssh2 <not-affected> (Vulnerable code not present)
[bullseye] - libssh2 <not-affected> (Vulnerable code not present)
NOTE: https://github.com/libssh2/libssh2/pull/2401
@@ -55419,11 +55422,13 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-th
NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ...)
- libssh2 1.11.1-6 (bug #1144415)
+ [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
NOTE: https://github.com/libssh2/libssh2/pull/2127
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...)
- libssh2 1.11.1-6 (bug #1144415)
+ [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
NOTE: https://github.com/libssh2/libssh2/pull/2128
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f038cb683a7068e1a3c959a2573a6ecc38ade689
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f038cb683a7068e1a3c959a2573a6ecc38ade689
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/444d4156/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list