libssh: Fix CVE-2026-59843

The stable-0.11 commit shown in [1] is the upstream fix selected for
this backport. The upstream advisory [2] documents CVE-2026-59843 and
identifies libssh 0.11.5 as the fixed release for the 0.11 series.

[1] https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919
[2] https://www.libssh.org/security/advisories/CVE-2026-59843.txt

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
Hetvi Thakar
2026-09-02 10:38:54 +05:30
committed by Anuj Mittal
parent edf29eeda9
commit f6b642b915
2 changed files with 85 additions and 0 deletions
@@ -0,0 +1,84 @@
From d965eb941a9a83a0643570a93d8997b91e248fc1 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Pavol=20=C5=BD=C3=A1=C4=8Dik?= <pzacik@redhat.com>
Date: Fri, 6 Mar 2026 13:58:30 +0100
Subject: [PATCH] CVE-2026-59843 channels: Fail when receiving max packet size
0
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Do this both for SSH2_MSG_CHANNEL_OPEN and for
SSH2_MSG_CHANNEL_OPEN_CONFIRMATION. Using the
max packet size 0 would lead to an infinite loop
in channel_write_common.
Originally reported by Rinku Das on on 23th February.
Independently reported by Yi Lin on 26th February and
Haruto Kimura on 22nd March.
We do not consider this as a security issue as connecting
to untrusted servers on the internet brings much worse
security consequences than hanging your clinet.
Signed-off-by: Pavol Žáčik <pzacik@redhat.com>
Reviewed-by: Jakub Jelen <jjelen@redhat.com>
CVE: CVE-2026-59843
Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=687ef1c44b646b9db0b1c6e8f987edb7c9e4d919]
(cherry picked from commit 44b186fa17aff497dae420c59c003222e438103c)
(cherry picked from commit 687ef1c44b646b9db0b1c6e8f987edb7c9e4d919)
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
src/channels.c | 7 +++++++
src/messages.c | 19 +++++++++++++++----
2 files changed, 22 insertions(+), 4 deletions(-)
diff --git a/src/channels.c b/src/channels.c
index 8290dbd1..3afdcf11 100644
--- a/src/channels.c
+++ b/src/channels.c
@@ -192,6 +192,13 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open_conf){
if (rc != SSH_OK)
goto error;
+ if (channel->remote_maxpacket == 0) {
+ SSH_LOG(SSH_LOG_RARE,
+ "Invalid maximum packet size 0 in "
+ "SSH2_MSG_CHANNEL_OPEN_CONFIRMATION");
+ goto error;
+ }
+
SSH_LOG(SSH_LOG_PROTOCOL,
"Received a CHANNEL_OPEN_CONFIRMATION for channel %d:%d",
channel->local_channel,
diff --git a/src/messages.c b/src/messages.c
index 6dadabf0..e79ecec2 100644
--- a/src/messages.c
+++ b/src/messages.c
@@ -1160,10 +1160,21 @@ SSH_PACKET_CALLBACK(ssh_packet_channel_open){
SSH_LOG(SSH_LOG_PACKET,
"Clients wants to open a %s channel", type_c);
- ssh_buffer_unpack(packet,"ddd",
- &msg->channel_request_open.sender,
- &msg->channel_request_open.window,
- &msg->channel_request_open.packet_size);
+ rc = ssh_buffer_unpack(packet,
+ "ddd",
+ &msg->channel_request_open.sender,
+ &msg->channel_request_open.window,
+ &msg->channel_request_open.packet_size);
+ if (rc != SSH_OK){
+ goto error;
+ }
+
+ if (msg->channel_request_open.packet_size == 0) {
+ ssh_set_error(session,
+ SSH_FATAL,
+ "Invalid maximum packet size 0 in SSH2_MSG_CHANNEL_OPEN");
+ goto error;
+ }
if (session->session_state != SSH_SESSION_STATE_AUTHENTICATED){
ssh_set_error(session,SSH_FATAL, "Invalid state when receiving channel open request (must be authenticated)");
@@ -35,6 +35,7 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-59845.patch \
file://CVE-2026-59847-01.patch \
file://CVE-2026-59847-02.patch \
file://CVE-2026-59843.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"