mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-25 12:00:22 +00:00
libssh: fix for CVE-2026-59845, CVE-2026-59847
Pick patch from [1], [2] & [3] also mentioned at Debian report in [4] & [5] [1] https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f [2] https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074 [3] https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9 [4] https://security-tracker.debian.org/tracker/CVE-2026-59845 [5] https://security-tracker.debian.org/tracker/CVE-2026-59847 Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
@@ -0,0 +1,68 @@
|
||||
From 53b8152623290c69657a6774d96888b876e6061f Mon Sep 17 00:00:00 2001
|
||||
From: Jakub Jelen <jjelen@redhat.com>
|
||||
Date: Thu, 26 Mar 2026 16:32:24 +0100
|
||||
Subject: CVE-2026-59845 socket: Properly check fork() return code
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
During execution of proxy command, when fork() fails, its return value
|
||||
is stored in pid and when the parent process attempts to kill it,
|
||||
it sends the kill signal to all processes the calling application has
|
||||
access to (except for init).
|
||||
|
||||
This caused nard to debug issues when the system under the load was hitting
|
||||
fork failures, which resulted in killing of all the system processes
|
||||
(of given user).
|
||||
|
||||
Reported and first patch iteration provided by: Halil Oktay (oblivionsage).
|
||||
|
||||
This code missing fork return value check is in libssh since 2010
|
||||
(f31a14b7932ef4cc165ddd8f1f1a5b23eb21beb3), but this issue is exploitable only
|
||||
since libssh 0.9.0 as previously there was no implementation of killing
|
||||
ProxyCommand children.
|
||||
|
||||
Signed-off-by: Jakub Jelen <jjelen@redhat.com>
|
||||
Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
|
||||
(cherry picked from commit 92b6fb9c5e2d1606e8f809fd884ab6dd4d3b7d45)
|
||||
CVE: CVE-2026-59845
|
||||
Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f]
|
||||
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
|
||||
---
|
||||
src/socket.c | 13 ++++++++++++-
|
||||
1 file changed, 12 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/socket.c b/src/socket.c
|
||||
index 99dcf8cc..ba9ba52d 100644
|
||||
--- a/src/socket.c
|
||||
+++ b/src/socket.c
|
||||
@@ -964,6 +964,7 @@ ssh_execute_command(const char *command, socket_t in, socket_t out)
|
||||
int
|
||||
ssh_socket_connect_proxycommand(ssh_socket s, const char *command)
|
||||
{
|
||||
+ char err_msg[SSH_ERRNO_MSG_MAX] = {0};
|
||||
socket_t pair[2];
|
||||
ssh_poll_handle h = NULL;
|
||||
int pid;
|
||||
@@ -982,7 +983,17 @@ ssh_socket_connect_proxycommand(ssh_socket s, const char *command)
|
||||
pid = fork();
|
||||
if (pid == 0) {
|
||||
ssh_execute_command(command, pair[0], pair[0]);
|
||||
- /* Does not return */
|
||||
+ /* child: Does not return */
|
||||
+ }
|
||||
+ /* parent */
|
||||
+ if (pid == -1) {
|
||||
+ close(pair[0]);
|
||||
+ close(pair[1]);
|
||||
+ ssh_set_error(s->session,
|
||||
+ SSH_FATAL,
|
||||
+ "fork failed: %s",
|
||||
+ ssh_strerror(errno, err_msg, SSH_ERRNO_MSG_MAX));
|
||||
+ return SSH_ERROR;
|
||||
}
|
||||
s->proxy_pid = pid;
|
||||
close(pair[0]);
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
From c483a187354dfd96b16d3309a74f6d1cf82c2074 Mon Sep 17 00:00:00 2001
|
||||
From: Jakub Jelen <jjelen@redhat.com>
|
||||
Date: Fri, 15 May 2026 17:01:21 +0200
|
||||
Subject: CVE-2026-59847 libcrypto: Fix tag verification of AES-GCM ciphers
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
EVP_DecryptFinal() returns 0 errors, which was wrongly checked since
|
||||
its introduction.
|
||||
|
||||
Reported by Ben Smyth discuss@bensmyth.com
|
||||
|
||||
Signed-off-by: Jakub Jelen <jjelen@redhat.com>
|
||||
Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
|
||||
|
||||
CVE: CVE-2026-59847
|
||||
Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074]
|
||||
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
|
||||
---
|
||||
src/libcrypto.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/libcrypto.c b/src/libcrypto.c
|
||||
index 69a850de..ff27770c 100644
|
||||
--- a/src/libcrypto.c
|
||||
+++ b/src/libcrypto.c
|
||||
@@ -674,7 +674,7 @@ evp_cipher_aead_decrypt(struct ssh_cipher_struct *cipher,
|
||||
rc = EVP_DecryptFinal(cipher->ctx,
|
||||
NULL,
|
||||
&outlen);
|
||||
- if (rc < 0) {
|
||||
+ if (rc != 1 || outlen != 0) {
|
||||
SSH_LOG(SSH_LOG_WARNING, "EVP_DecryptFinal failed: Failed authentication");
|
||||
return SSH_ERROR;
|
||||
}
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
From d4847509b792d564d1935dbfea4ee1496ad3d3d9 Mon Sep 17 00:00:00 2001
|
||||
From: Jakub Jelen <jjelen@redhat.com>
|
||||
Date: Mon, 18 May 2026 08:56:31 +0200
|
||||
Subject: CVE-2026-59847 libcrypto: Fix symmetric issue during encryption
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jakub Jelen <jjelen@redhat.com>
|
||||
Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
|
||||
(cherry picked from commit a5173c6ad249f7960bc7c1cc75a6a05ead8e3eba)
|
||||
|
||||
CVE: CVE-2026-59847
|
||||
Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9]
|
||||
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
|
||||
---
|
||||
src/libcrypto.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/libcrypto.c b/src/libcrypto.c
|
||||
index ff27770c..95187e1d 100644
|
||||
--- a/src/libcrypto.c
|
||||
+++ b/src/libcrypto.c
|
||||
@@ -586,7 +586,7 @@ evp_cipher_aead_encrypt(struct ssh_cipher_struct *cipher,
|
||||
rc = EVP_EncryptFinal(cipher->ctx,
|
||||
NULL,
|
||||
&tmplen);
|
||||
- if (rc < 0) {
|
||||
+ if (rc != 1) {
|
||||
SSH_LOG(SSH_LOG_WARNING, "EVP_EncryptFinal failed: Failed to create a tag");
|
||||
return;
|
||||
}
|
||||
--
|
||||
2.50.1
|
||||
|
||||
@@ -32,6 +32,9 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
|
||||
file://CVE-2026-0968-2.patch \
|
||||
file://CVE-2026-0967.patch \
|
||||
file://CVE-2026-0965.patch \
|
||||
file://CVE-2026-59845.patch \
|
||||
file://CVE-2026-59847-01.patch \
|
||||
file://CVE-2026-59847-02.patch \
|
||||
"
|
||||
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user