[Git][security-tracker-team/security-tracker][master] Triage libssh issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 21 12:59:54 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
68a86f3a by Salvatore Bonaccorso at 2026-07-21T13:56:32+02:00
Triage libssh issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,36 +1,74 @@
 CVE-2026-15370 [Stack buffer overflow in SFTP server longname construction]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-15370.txt
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=4f0c400929d3aa1f505c5545703107e1c26ba24c (libssh-0.12.1)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=770eafb74b23814815d1246249f5ce42fb92c7ba (libssh-0.12.1)
 CVE-2026-59842 [Information disclosure via short GSSAPI Curve25519 public key]
 	- libssh <unfixed>
+	[trixie] - libssh <not-affected> (Vulnerable code introduced later)
+	[bookworm] - libssh <not-affected> (Vulnerable code introduced later)
+	[bullseye] - libssh <not-affected> (Vulnerable code introduced later)
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59842.txt
+	NOTE: Introduced with: https://git.libssh.org/projects/libssh.git/commit/?id=88c2ea6752fab7b3da9cc4c51eaf632361a44080 (libssh-0.12.0)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=5568ae6c5a1adcb008d044985fe5f1d1567bc610 (libssh-0.12.1)
 CVE-2026-59843 [Denial of service via zero advertised channel packet size]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59843.txt
+	TODO: check fixing commit in libssh-0.12.1
 CVE-2026-59844 [Denial of service via oversized SFTP read length]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59844.txt
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2544f22733ffcd59a2e51e2950f80901d063b946 (libssh-0.12.1)
 CVE-2026-59845 [Denial of service via unchecked ProxyCommand fork() failure]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59845.txt
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f (libssh-0.12.1)
 CVE-2026-59846 [Information disclosure via ProxyCommand %r username expansion]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59846.txt
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2e74267b034f00e8e36c86440364f885cead5f45 (libssh-0.12.1)
 CVE-2026-59847 [Integrity downgrade via OpenSSL AES-GCM tag verification]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59847.txt
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074 (libssh-0.12.1)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9 (libssh-0.12.1)
 CVE-2026-59848 [Denial of service via SFTP responses with unknown request IDs]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59848.txt
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=9563afc950f473daa355ca594e2e5f4d520460ac (libssh-0.12.1)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=e3dc89de9754790e49b26f03b70e8e4acc88bde8 (libssh-0.12.1)
 CVE-2026-59849 [Denial of service via automatic certificate authentication loop]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59849.txt
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=d9fef838e27fc740f70d9b825c98b912f3e84b14 (libssh-0.12.1)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2a40a20b4963e033c7c5a21e3dc5ea6572178a20 (libssh-0.12.1)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=a540e27659b08828ef61f2910a790f7cf2af9f8d (libssh-0.12.1)
 CVE-2026-59850 [Use-after-free via data callbacks on closed channels]
 	- libssh <unfixed>
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59850.txt
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=7dfabb1fd213196c4912c314b418ff36c882ea54 (libssh-0.12.1)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=7edddfc580970c821b1bd866c5f88854a8bfd70d (libssh-0.12.1)
 CVE-2026-59851 [Authentication bypass via missing GSSAPI principal check]
 	- libssh <unfixed>
+	[trixie] - libssh <not-affected> (Vulnerable code introduced later)
+	[bookworm] - libssh <not-affected> (Vulnerable code introduced later)
+	[bullseye] - libssh <not-affected> (Vulnerable code introduced later)
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59851.txt
+	NOTE: Introduced with: https://git.libssh.org/projects/libssh.git/commit/?id=9044fcdb52c870f0036319945ac860054384b2c1 (libssh-0.12.0)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=73225a1774b32774ccc77f6fbd0a48e11505a6db (libssh-0.12.1)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=05d0fe43b599a867906e8fe96ad78e0cda204128 (libssh-0.12.1)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=f2f1078d6d7383eaa24570094d3a27c90e6e5f21 (libssh-0.12.1)
 CVE-2026-8082 (The bpost-shipping-platform WordPress plugin before 3.2.3 does not pro ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-6952 (A post-authentication command injection vulnerability in the "LogServe ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/68a86f3a8edc252aeba86ceecf7dfc77d4b02528

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/68a86f3a8edc252aeba86ceecf7dfc77d4b02528
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/e5a598b4/attachment.htm>


More information about the debian-security-tracker-commits mailing list