[Git][security-tracker-team/security-tracker][master] Mark libssh2 issues as no-dsa

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 10:15:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f038cb68 by Salvatore Bonaccorso at 2026-08-21T10:50:57+02:00
Mark libssh2 issues as no-dsa

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31818,16 +31818,19 @@ CVE-2026-66142 (Apache Neethi is vulnerable to uncontrolled recursion when parsi
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authen ...)
 	- libssh2 1.11.1-5 (bug #1142856)
+	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	[bookworm] - libssh2 <not-affected> (Vulnerable code not present)
 	[bullseye] - libssh2 <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/libssh2/libssh2/pull/2198
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
 CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bo ...)
 	- libssh2 1.11.1-5 (bug #1142856)
+	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/libssh2/libssh2/pull/2202
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9
 CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authen ...)
 	- libssh2 1.11.1-5 (bug #1142856)
+	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	[bookworm] - libssh2 <not-affected> (Vulnerable code not present)
 	[bullseye] - libssh2 <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/libssh2/libssh2/pull/2401
@@ -55419,11 +55422,13 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-th
 	NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
 CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but  ...)
 	- libssh2 1.11.1-6 (bug #1144415)
+	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
 	NOTE: https://github.com/libssh2/libssh2/pull/2127
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
 CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...)
 	- libssh2 1.11.1-6 (bug #1144415)
+	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
 	NOTE: https://github.com/libssh2/libssh2/pull/2128
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f038cb683a7068e1a3c959a2573a6ecc38ade689

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f038cb683a7068e1a3c959a2573a6ecc38ade689
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/444d4156/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list