libssh: set status for CVE-2026-59842

Analysis:
  - CVE-2026-59842 affects information disclosure via short GSSAPI Curve25519 public key.
  - This vulnerable code is not present in the current libssh 0.10.6.
  - Hence ignoring the CVE for this version.

Reference:
1. https://www.cve.org/CVERecord?id=CVE-2026-59842
2. https://www.libssh.org/security/advisories/CVE-2026-59842.txt
3. https://security-tracker.debian.org/tracker/CVE-2026-59842

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
Hitendra Prajapati
2026-09-01 06:57:04 +05:30
committed by Anuj Mittal
parent b8bc579daa
commit 085604ac0b
@@ -72,3 +72,4 @@ BBCLASSEXTEND = "native nativesdk"
CVE_STATUS[CVE-2025-14821] = "not-applicable-platform: only affects Windows due to loading configuration from C:\etc"
#Reference: https://www.libssh.org/security/advisories/CVE-2026-15370.txt
CVE_STATUS[CVE-2026-15370] = "fixed-version: vulnerable SFTP server longname construction handling was introduced in 0.11.0 and is not present in 0.10.6"
CVE_STATUS[CVE-2026-59842] = "fixed-version: vulnerable information disclosure via short GSSAPI Curve25519 public key in 0.12.0 and is not present in 0.10.6"