[Git][security-tracker-team/security-tracker][master] Correct status for CVE-2026-59843/libssh in unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 28 14:34:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c1012415 by Salvatore Bonaccorso at 2026-07-28T15:34:08+02:00
Correct status for CVE-2026-59843/libssh in unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7818,10 +7818,11 @@ CVE-2026-59842 (A flaw was found in libssh. During server-side GSSAPI key exchan
 	NOTE: Introduced with: https://git.libssh.org/projects/libssh.git/commit/?id=88c2ea6752fab7b3da9cc4c51eaf632361a44080 (libssh-0.12.0)
 	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=5568ae6c5a1adcb008d044985fe5f1d1567bc610 (libssh-0.12.1)
 CVE-2026-59843 (A flaw was found in libssh. A remote authenticated peer can advertise  ...)
-	- libssh 0.12.1-1 (bug #1142537)
-	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
+	- libssh 0.12.2-1
+	NOTE: https://www.libssh.org/2026/07/28/libssh-0-12-2-security-release/
 	NOTE: https://www.libssh.org/security/advisories/CVE-2026-59843.txt
-	TODO: check fixing commit in libssh-0.12.1
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=3f785905760d2e2a87037285ab85b37b9924e409 (libssh-0.12.2)
+	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=006ddd503566ee13e00db42bc111e898388f8664 (libssh-0.12.2)
 CVE-2026-59844 (A flaw was found in libssh. A remote authenticated client can issue SS ...)
 	- libssh 0.12.1-1 (bug #1142537)
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c10124157879f7853c56488e3e6f604c3d81bbca

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c10124157879f7853c56488e3e6f604c3d81bbca
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/54210854/attachment.htm>


More information about the debian-security-tracker-commits mailing list