[ubuntu/noble-security] libssh2 1.11.0-4.1ubuntu0.24.04.3 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Mon Jul 13 12:19:55 UTC 2026
libssh2 (1.11.0-4.1ubuntu0.24.04.3) noble-security; urgency=medium
* SECURITY UPDATE: Multiple security issues in publickey
- debian/patches/CVE-2026-5805x-pre1.patch: fix potential arbitrary free
in libssh2_publickey_list_fetch().
- debian/patches/CVE-2026-5805x-pre2.patch: fix potential multiplication
overflow in 32-bit libssh2_publickey_list_fetch().
- debian/patches/CVE-2026-5805x-pre3.patch: cap packet size in
publickey_packet_receive().
- debian/patches/CVE-2026-5805x-pre4.patch: fix leaks when
publickey_response_success() received <8 bytes.
- debian/patches/CVE-2026-5805x-pre5.patch: fix potential OOB read in
publickey_response_success().
- debian/patches/CVE-2026-58051.patch: fix potential OOB read in
libssh2_publickey_list_fetch().
- debian/patches/CVE-2026-5805x-pre6.patch: fix potential OOB read.
- debian/patches/CVE-2026-5805x-pre7.patch: flatten bounds check if blocks
(tidy-up).
- debian/patches/CVE-2026-5805x-pre8.patch: rework bounds checks to avoid
pointer comparisons.
- debian/patches/CVE-2026-58050.patch: cap variable-length packet element
sizes.
- CVE-2026-58050
- CVE-2026-58051
Date: 2026-07-10 20:36:31.217369+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libssh2/1.11.0-4.1ubuntu0.24.04.3
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list