1
0
mirror of https://git.yoctoproject.org/poky synced 2026-08-30 00:26:36 +00:00

openssh: Fix CVE-2026-60000

This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-60000. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60000

(From OE-Core rev: c3dad1896c5377635506c87a09234240c5bbca90)

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
Devansh Patel
2026-07-20 11:57:49 -07:00
committed by Paul Barker
parent cb5e6f65a5
commit 012eac4b8f
2 changed files with 141 additions and 0 deletions
@@ -0,0 +1,140 @@
From 055316632809a2e2e58eac2020699b52187d1b11 Mon Sep 17 00:00:00 2001
From: "djm@openbsd.org" <djm@openbsd.org>
Date: Mon, 6 Jul 2026 07:53:30 +0000
Subject: [PATCH] upstream: Fix multiple RFC 4462 (GSSAPIAuthentication)
compliance
problems
1) Remove an early failure return for GSSAPI authentication attempts
made for invalid accounts that yielded different behaviour for
valid vs invalid accounts.
2) Fix a situation where some GSSAPI requestes were not correctly
subjected to MaxAuthTries.
3) Fix a moderate pre-authentication resource DoS related to #2.
Add missing logging for error cases.
Report and fixes from Manfred Kaiser, milCERT AT
CVE: CVE-2026-60000
Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192]
Backport Changes:
- Kept Scarthgap's PRIVSEP(ssh_gssapi_server_ctx()) interface and its
authentication-context guard while applying the upstream RFC 4462 state,
failure, logging, and MaxAuthTries changes.
- Retained the Scarthgap auth2-gss.c OpenBSD revision identifier.
OpenBSD-Commit-ID: ca0acdd64eea435d6f89534538a9eb404a5629d3
(cherry picked from commit 5d04ca6af739b82fd30d84d2783ca802ebfa1192)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
auth2-gss.c | 53 ++++++++++++++++++++++++-----------------------------
1 file changed, 24 insertions(+), 29 deletions(-)
diff --git a/auth2-gss.c b/auth2-gss.c
index 195578bcf..6846eae5b 100644
--- a/auth2-gss.c
+++ b/auth2-gss.c
@@ -110,12 +110,6 @@ userauth_gssapi(struct ssh *ssh, const char *method)
return (0);
}
- if (!authctxt->valid || authctxt->user == NULL) {
- debug2_f("disabled because of invalid user");
- free(doid);
- return (0);
- }
-
if (GSS_ERROR(PRIVSEP(ssh_gssapi_server_ctx(&ctxt, &goid)))) {
if (ctxt != NULL)
ssh_gssapi_delete_ctx(&ctxt);
@@ -177,8 +171,14 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh)
(r = sshpkt_send(ssh)) != 0)
fatal_fr(r, "send ERRTOK packet");
}
+ logit("Failed gssapi-with-mic for %s%.100s "
+ "from %.200s port %d ssh2",
+ authctxt->valid ? "" : "invalid user ",
+ authctxt->user,
+ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
authctxt->postponed = 0;
ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
} else {
if (send_tok.length != 0) {
@@ -190,14 +190,18 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh)
fatal_fr(r, "send TOKEN packet");
}
if (maj_status == GSS_S_COMPLETE) {
- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
- if (flags & GSS_C_INTEG_FLAG)
- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC,
+ ssh_dispatch_set(ssh,
+ SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
+ /* note: keep ERRTOK handler as per RFC 4462 s3.4 */
+ if (flags & GSS_C_INTEG_FLAG) {
+ ssh_dispatch_set(ssh,
+ SSH2_MSG_USERAUTH_GSSAPI_MIC,
&input_gssapi_mic);
- else
+ } else {
ssh_dispatch_set(ssh,
SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE,
&input_gssapi_exchange_complete);
+ }
}
}
@@ -209,10 +213,6 @@ static int
input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh)
{
Authctxt *authctxt = ssh->authctxt;
- Gssctxt *gssctxt;
- gss_buffer_desc send_tok = GSS_C_EMPTY_BUFFER;
- gss_buffer_desc recv_tok;
- OM_uint32 maj_status;
int r;
u_char *p;
size_t len;
@@ -220,26 +220,21 @@ input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh)
if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
fatal("No authentication or GSSAPI context");
- gssctxt = authctxt->methoddata;
- if ((r = sshpkt_get_string(ssh, &p, &len)) != 0 ||
+ /* Minimal error handling - just cancel auth and return FAILURE */
+ if ((r = sshpkt_get_string_direct(ssh, NULL, NULL)) != 0 ||
(r = sshpkt_get_end(ssh)) != 0)
fatal_fr(r, "parse packet");
- recv_tok.value = p;
- recv_tok.length = len;
-
- /* Push the error token into GSSAPI to see what it says */
- maj_status = PRIVSEP(ssh_gssapi_accept_ctx(gssctxt, &recv_tok,
- &send_tok, NULL));
-
- free(recv_tok.value);
- /* We can't return anything to the client, even if we wanted to */
+ logit("Failed gssapi-with-mic for %s%.100s from %.200s port %d ssh2",
+ authctxt->valid ? "" : "invalid user ",
+ authctxt->user,
+ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
+ authctxt->postponed = 0;
ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
-
- /* The client will have already moved on to the next auth */
-
- gss_release_buffer(&maj_status, &send_tok);
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, NULL);
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, NULL);
+ userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
return 0;
}
@@ -43,6 +43,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
file://CVE-2026-59995.patch \
file://CVE-2026-60001.patch \
file://CVE-2026-60002.patch \
file://CVE-2026-60000.patch \
"
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"