Files
poky/meta/recipes-connectivity
Devansh Patel 077627338a openssh: set status for CVE-2026-59998
Analysis:
- CVE-2026-59998 concerns an undocumented limitation of
  GSSAPIStrictAcceptorCheck in Windows Active Directory
  environments [1].
- Upstream OpenSSH 10.4 only documents the existing behavior and
  provides no code remediation [2].
- The recipe disables Kerberos/GSSAPI by default. Mark the CVE
  not-applicable-config when PACKAGECONFIG lacks kerberos, and
  unpatched when kerberos is enabled.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59998
[2] 8058c5bdb5

(From OE-Core rev: 543550522f831479f07d332a40ba343c53ae1065)

Signed-off-by: Devansh Patel <devanshp@cisco.com>
[YC: See previous version of this patch for context about ignoring vs
this CVE vs patching:
https://patchwork.yoctoproject.org/project/oe-core/patch/20260720175518.3546447-3-devanshp@cisco.com/#40497 ]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-31 16:41:23 +01:00
..
2026-07-22 21:08:54 +01:00
2025-05-27 09:38:57 -07:00
2026-07-20 09:04:32 +01:00
2024-06-20 06:29:44 -07:00
2024-09-19 05:11:35 -07:00
2026-01-26 09:45:39 +00:00
2024-02-19 11:34:33 +00:00
2023-09-02 18:23:05 +01:00
2026-07-02 13:42:26 +01:00
2025-04-16 06:41:24 -07:00
2026-06-26 16:55:54 +01:00
2025-05-02 08:20:11 -07:00
2026-07-22 21:08:54 +01:00