Hitendra Prajapati
2026-09-01 06:57:05 +05:30
committed by Anuj Mittal
parent 085604ac0b
commit 9e103dc4d0
4 changed files with 145 additions and 0 deletions
@@ -0,0 +1,68 @@
From 53b8152623290c69657a6774d96888b876e6061f Mon Sep 17 00:00:00 2001
From: Jakub Jelen <jjelen@redhat.com>
Date: Thu, 26 Mar 2026 16:32:24 +0100
Subject: CVE-2026-59845 socket: Properly check fork() return code
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
During execution of proxy command, when fork() fails, its return value
is stored in pid and when the parent process attempts to kill it,
it sends the kill signal to all processes the calling application has
access to (except for init).
This caused nard to debug issues when the system under the load was hitting
fork failures, which resulted in killing of all the system processes
(of given user).
Reported and first patch iteration provided by: Halil Oktay (oblivionsage).
This code missing fork return value check is in libssh since 2010
(f31a14b7932ef4cc165ddd8f1f1a5b23eb21beb3), but this issue is exploitable only
since libssh 0.9.0 as previously there was no implementation of killing
ProxyCommand children.
Signed-off-by: Jakub Jelen <jjelen@redhat.com>
Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
(cherry picked from commit 92b6fb9c5e2d1606e8f809fd884ab6dd4d3b7d45)
CVE: CVE-2026-59845
Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f]
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
---
src/socket.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/src/socket.c b/src/socket.c
index 99dcf8cc..ba9ba52d 100644
--- a/src/socket.c
+++ b/src/socket.c
@@ -964,6 +964,7 @@ ssh_execute_command(const char *command, socket_t in, socket_t out)
int
ssh_socket_connect_proxycommand(ssh_socket s, const char *command)
{
+ char err_msg[SSH_ERRNO_MSG_MAX] = {0};
socket_t pair[2];
ssh_poll_handle h = NULL;
int pid;
@@ -982,7 +983,17 @@ ssh_socket_connect_proxycommand(ssh_socket s, const char *command)
pid = fork();
if (pid == 0) {
ssh_execute_command(command, pair[0], pair[0]);
- /* Does not return */
+ /* child: Does not return */
+ }
+ /* parent */
+ if (pid == -1) {
+ close(pair[0]);
+ close(pair[1]);
+ ssh_set_error(s->session,
+ SSH_FATAL,
+ "fork failed: %s",
+ ssh_strerror(errno, err_msg, SSH_ERRNO_MSG_MAX));
+ return SSH_ERROR;
}
s->proxy_pid = pid;
close(pair[0]);
--
2.50.1
@@ -0,0 +1,39 @@
From c483a187354dfd96b16d3309a74f6d1cf82c2074 Mon Sep 17 00:00:00 2001
From: Jakub Jelen <jjelen@redhat.com>
Date: Fri, 15 May 2026 17:01:21 +0200
Subject: CVE-2026-59847 libcrypto: Fix tag verification of AES-GCM ciphers
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
EVP_DecryptFinal() returns 0 errors, which was wrongly checked since
its introduction.
Reported by Ben Smyth discuss@bensmyth.com
Signed-off-by: Jakub Jelen <jjelen@redhat.com>
Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
CVE: CVE-2026-59847
Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074]
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
---
src/libcrypto.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/libcrypto.c b/src/libcrypto.c
index 69a850de..ff27770c 100644
--- a/src/libcrypto.c
+++ b/src/libcrypto.c
@@ -674,7 +674,7 @@ evp_cipher_aead_decrypt(struct ssh_cipher_struct *cipher,
rc = EVP_DecryptFinal(cipher->ctx,
NULL,
&outlen);
- if (rc < 0) {
+ if (rc != 1 || outlen != 0) {
SSH_LOG(SSH_LOG_WARNING, "EVP_DecryptFinal failed: Failed authentication");
return SSH_ERROR;
}
--
2.50.1
@@ -0,0 +1,35 @@
From d4847509b792d564d1935dbfea4ee1496ad3d3d9 Mon Sep 17 00:00:00 2001
From: Jakub Jelen <jjelen@redhat.com>
Date: Mon, 18 May 2026 08:56:31 +0200
Subject: CVE-2026-59847 libcrypto: Fix symmetric issue during encryption
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Signed-off-by: Jakub Jelen <jjelen@redhat.com>
Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
(cherry picked from commit a5173c6ad249f7960bc7c1cc75a6a05ead8e3eba)
CVE: CVE-2026-59847
Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9]
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
---
src/libcrypto.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/libcrypto.c b/src/libcrypto.c
index ff27770c..95187e1d 100644
--- a/src/libcrypto.c
+++ b/src/libcrypto.c
@@ -586,7 +586,7 @@ evp_cipher_aead_encrypt(struct ssh_cipher_struct *cipher,
rc = EVP_EncryptFinal(cipher->ctx,
NULL,
&tmplen);
- if (rc < 0) {
+ if (rc != 1) {
SSH_LOG(SSH_LOG_WARNING, "EVP_EncryptFinal failed: Failed to create a tag");
return;
}
--
2.50.1
@@ -32,6 +32,9 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0968-2.patch \
file://CVE-2026-0967.patch \
file://CVE-2026-0965.patch \
file://CVE-2026-59845.patch \
file://CVE-2026-59847-01.patch \
file://CVE-2026-59847-02.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"