mirror of
https://git.yoctoproject.org/poky
synced 2026-09-12 06:49:32 +02:00
libssh2: Fix CVE-2026-58051
Backport the upstream fix for CVE-2026-58051 using the
commit in [1].
The CVE advisory [2] describes an uninitialized
publickey-list entry cleanup issue affecting libssh2
through 1.11.1.
[1] a9758da45a
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58051
(From OE-Core rev: 19c481ffd3824512eb85845f04ae7b08b947b4f6)
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
1cd648c9ed
commit
ba7e6744c6
34
meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch
Normal file
34
meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch
Normal file
@@ -0,0 +1,34 @@
|
||||
From 39ea6e1783afcbd72838eaf649999baa2c41ab12 Mon Sep 17 00:00:00 2001
|
||||
From: Viktor Szakats <vszakats@users.noreply.github.com>
|
||||
Date: Mon, 29 Jun 2026 19:12:21 +0200
|
||||
Subject: [PATCH] publickey: fix potential arbitrary free in
|
||||
`libssh2_publickey_list_fetch()` (#2127)
|
||||
|
||||
Due to uninitialized list entry.
|
||||
|
||||
Reported-and-patch-by: Behzod Abdullayev
|
||||
Reported-by: Sharique Raza
|
||||
|
||||
Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9
|
||||
|
||||
CVE: CVE-2026-58051
|
||||
Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a]
|
||||
|
||||
(cherry picked from commit a9758da45a52bc8c630ec9493804d0c6ea30b24a)
|
||||
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
|
||||
---
|
||||
src/publickey.c | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
|
||||
diff --git a/src/publickey.c b/src/publickey.c
|
||||
index 9ff2e5cf..5af3b50a 100644
|
||||
--- a/src/publickey.c
|
||||
+++ b/src/publickey.c
|
||||
@@ -972,6 +972,7 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys,
|
||||
goto err_exit;
|
||||
}
|
||||
list = newlist;
|
||||
+ memset(&list[keys], 0, sizeof(list[keys]));
|
||||
}
|
||||
if(pkey->version == 1) {
|
||||
unsigned long comment_len;
|
||||
@@ -21,6 +21,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
|
||||
file://CVE-2026-66034.patch \
|
||||
file://CVE-2026-66035.patch \
|
||||
file://CVE-2026-58050.patch \
|
||||
file://CVE-2026-58051.patch \
|
||||
"
|
||||
|
||||
SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"
|
||||
|
||||
Reference in New Issue
Block a user