-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 01 Aug 2026 13:42:11 +0200 Source: libssh Binary: libssh-4 libssh-4-dbgsym libssh-dev Architecture: armhf Version: 0.11.5-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-06) Changed-By: Martin Pitt Description: libssh-4 - tiny C SSH library (OpenSSL flavor) libssh-dev - tiny C SSH library - Development files (OpenSSL flavor) Closes: 1127693 1142537 Changes: libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium . * New upstream security/bug fix release 0.11.4: - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname() - CVE-2026-3731: Read buffer overrun when handling SFTP extensions - Note: CVE-2025-14821 is Windows specific, does not apply to Linux https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ (Closes: #1127693) * New upstream security/bug fix release 0.11.5: - CVE-2026-15370: Stack buffer overflow in SFTP server longname construction - CVE-2026-59843: Denial of service via zero advertised channel packet size - CVE-2026-59844: Denial of service via oversized SFTP read length - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure - CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification - CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs - CVE-2026-59849: Denial of service via automatic certificate authentication loop - CVE-2026-59850: Use-after-free via data callbacks on closed channels - Zero-initialize every ssh_string https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ (Closes: #1142537) Checksums-Sha1: 274e2e83a271c87e848e6880c66007a13e62104f 571716 libssh-4-dbgsym_0.11.5-0+deb13u1_armhf.deb 3b982a055be79b20cc2e3c46000819716cf5594a 184040 libssh-4_0.11.5-0+deb13u1_armhf.deb d953d666fea6e06d3c38677eb121e38c817c23e9 245980 libssh-dev_0.11.5-0+deb13u1_armhf.deb b0e05defa7053ab9073a56fe35e2d06db0cfc63a 8733 libssh_0.11.5-0+deb13u1_armhf-buildd.buildinfo Checksums-Sha256: be46f7f9ac7585902c70f45c95247813a0673177971517a7327ac391c6c77779 571716 libssh-4-dbgsym_0.11.5-0+deb13u1_armhf.deb befc9f208a8bbfed470316031f3025924ae8213a3c630ced47788b96481959cc 184040 libssh-4_0.11.5-0+deb13u1_armhf.deb 8fcdc17a2775c4b6792c267cfb221af5c060fca3cb3b0ec8bce2c4bb388e78fc 245980 libssh-dev_0.11.5-0+deb13u1_armhf.deb b7929023ceed7117e9a4d8caafe73d1118180e099b1452561c8a59643024d2bf 8733 libssh_0.11.5-0+deb13u1_armhf-buildd.buildinfo Files: caf39e2bde7cddd512046f5bf87f9952 571716 debug optional libssh-4-dbgsym_0.11.5-0+deb13u1_armhf.deb 342dda2f2803859f9f9098677fbf2951 184040 libs optional libssh-4_0.11.5-0+deb13u1_armhf.deb 00a423a58974daecfbc94d3c32ebae1b 245980 libdevel optional libssh-dev_0.11.5-0+deb13u1_armhf.deb 314a1e690726a9f5b4e3dc721cde3a6f 8733 libs optional libssh_0.11.5-0+deb13u1_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBOUsBrtd5lcy6oRfutMAkCxKbL0FAmpuT/4ACgkQutMAkCxK bL2KdA/5AZLMqv+XzVNGTMcmbF+HjOd4TeP+V02L0iKv9lw/+gpI79q8kyl95CXw UqZcQLCnTT/POugmtMFiIcLA18UCD+pHMF5X6Pu1/DzWydTg6HIEzeJw1YAFdM2o MlPAv8fi14gwEBY64IvWlp3ovZhvalBaiyEFSmh9EqumZ8qwU5394LGjbPxjo26Q /Yl1oOfCjjITViewYyTf7VQHNJp/Q6sVtSpJxEJA3eOgUH9oQiNVdXFV8FDPiRTO nG1QzO5EcAl2nOGxitRzqUyNpwJOV11wd0rbRou/NqQc5DWWcoTiCqbp1Q+03meb giIYVsUV/RZQ4Vg9H3WaVEiVjjok3qI3m0HAop94tx+Mw9cYPj5iq+NTSryulI54 bjc+Z8/TKxbXifnC3NtCEFO6GyivwuNDsblcTBLa2yeNsFllbEStxQJUzZqFiP9X 45VIse8YUUSuqMjiwb/boXfc3zQPTJ+C6EpLWVI/jkBYx51t3KhxYC398uGZlFeU hGavKkgqmTL45IvwMM7AID/pOE7zvTv+MOskOUxhwQqF/WwuABaoPpkUlhgJ0Rp4 Vuho5RLQgqmo+Kvzp4FuuSvAqq6uWPBc4I8kKoZtmKocCaig565/jzYmPmGk7QL7 thK81PhvwYts11EUXwjvxl3EhmZigbWAR3Jd27Ilw+b8V9+Zkr8= =GwB0 -----END PGP SIGNATURE-----