-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 05 Sep 2026 09:40:39 -0300 Source: libssh2 Architecture: source Version: 1.10.0-3+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Nicolas Mora <babelouest@debian.org> Changed-By: Emmanuel Arias <eamanu@debian.org> Closes: 1140401 1142856 1144415 Changes: libssh2 (1.10.0-3+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2025-15661: a malicious server could send an oversized link_len in SSH_FXP_NAME responses (READLINK/REALPATH) and trigger an out-of-bounds memcpy, leaking heap memory or crashing the client (Closes: #1140401). * CVE-2026-7598: The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. * CVE-2026-58050: libsshw2 reads an attacker-controlled 32-bit attribute without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. count from a publickey-subsystem response and uses it without bounds checking, causing an overflows to an undersized buffer (Closes: #1144415). * CVE-2026-58051: libssh2 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. * CVE-2026-66032: fix double free in sftp_open() reachable from a malicious server during SFTP session setup (SSH_FXP_OPEN answered with SSH_FXP_STATUS/FX_OK followed by a failing sftp_packet_require()) (Closes: #1142856). * CVE-2026-66034: fix missing bounds check in libssh2_publickey_list_fetch() leading to a heap out-of-bounds read and a free of an uninitialized pointer, triggerable by a malicious server via the publickey subsystem. Checksums-Sha1: 331d38f5294022ca82a4b4eb640605b0da25848a 2096 libssh2_1.10.0-3+deb12u1.dsc 2ebb3bc5c944090ade840f3a0ada9874eced979b 965044 libssh2_1.10.0.orig.tar.gz b8b951a5c3ca74eb74a3a1359e865c114691c93d 12196 libssh2_1.10.0-3+deb12u1.debian.tar.xz 767451cf806d386ef6230a2fade0f459841c4b5c 7210 libssh2_1.10.0-3+deb12u1_source.buildinfo Checksums-Sha256: c83e73990cdc7f315c57cc558fcc677fbc6e9a102edde97b3ddb4ba9c9fc189a 2096 libssh2_1.10.0-3+deb12u1.dsc 2d64e90f3ded394b91d3a2e774ca203a4179f69aebee03003e5a6fa621e41d51 965044 libssh2_1.10.0.orig.tar.gz e4da32facae7fea48f1ba73ba1a17214ee88863143517bf7e4d58a6149deb792 12196 libssh2_1.10.0-3+deb12u1.debian.tar.xz a02c9f8d232e5fb5d69f3eacbf9cd43221fa381d67e4f067a9991742c3cd1c01 7210 libssh2_1.10.0-3+deb12u1_source.buildinfo Files: cfc6619aef29492aeeebdf1364739abe 2096 libs optional libssh2_1.10.0-3+deb12u1.dsc f604ba083fad23bf715a9ecccc9f57f4 965044 libs optional libssh2_1.10.0.orig.tar.gz aa8c8070ef6ce585c1579c6dded77f31 12196 libs optional libssh2_1.10.0-3+deb12u1.debian.tar.xz 5ece1f4c793fe6497feb18cd58e29f3a 7210 libs optional libssh2_1.10.0-3+deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJGBAEBCgAwFiEEE3lnVbvHK7ir4q61+p3sXeEcY/EFAmqcDnkSHGVhbWFudUBk ZWJpYW4ub3JnAAoJEPqd7F3hHGPxeGUP/A1DbOIwfzZe2JcrnxE8D9pfnOvEjm2K TeuCrMvzFu9ZGgGAqq/T1PFQwevGxJi51hl/Xw4t7Mpqo+Wth8DKVy6ERHhr6L/A nOP22F8WYH6ys6MXWUCCq5jUEjZdRXeSEDdvt1DaDm+jF98agHmL6aqNGG3F8uMY sNNNSv2rhEmQkhpWSQTgt/a0fU9qYS1YkvoM2YfuVs/Qi12nlgjMtPDi0f+7XVEX AfhfP65Sj4/f6K9zD0K4TZxQg8TcB/0bwfOMgHHN2MoLwMvDntos4GWK14fenjg2 AZPQ6CAdPIlJXpccDo9kXsgHgSdKsIBV/c1P3LEWNdKqzjLrAAO9iYoDp16cYbEo 2DZOZfXmwdcVwBlNRWeEerJbJUBvud3Yo8Ktxv7Q2SBZ16CkmJbwBxqFkClHlEPt cyIvz6UiXlDR2hLPshJef93UddoAKocFRbHT+4qLWbPkiXXtGtbdPj/2kIoT2uJI ivEnZNxiBUcL/nT+ZOwUqpWJVkWCqMjWnk42gVVikNNQegLfu9UCffr/veb8xiAr fQ5ge+GeDW14qdkPJatJNoWLo6Fx2EnJREOA9vRqMbOOn5LCpENOzMHmt3B/oVYy HE3jGBM6VAYQ6CmLHr28qkEOkKUQNU6aRHgyThEg5AiyGp4gNHajzJ1FeXbmyyOv upVuvB0DCpQc =2yoh -----END PGP SIGNATURE-----