-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 01 Aug 2026 13:42:11 +0200 Source: libssh Binary: libssh-4 libssh-4-dbgsym libssh-dev Architecture: s390x Version: 0.11.5-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: s390x Build Daemon (zani) Changed-By: Martin Pitt Description: libssh-4 - tiny C SSH library (OpenSSL flavor) libssh-dev - tiny C SSH library - Development files (OpenSSL flavor) Closes: 1127693 1142537 Changes: libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium . * New upstream security/bug fix release 0.11.4: - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname() - CVE-2026-3731: Read buffer overrun when handling SFTP extensions - Note: CVE-2025-14821 is Windows specific, does not apply to Linux https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ (Closes: #1127693) * New upstream security/bug fix release 0.11.5: - CVE-2026-15370: Stack buffer overflow in SFTP server longname construction - CVE-2026-59843: Denial of service via zero advertised channel packet size - CVE-2026-59844: Denial of service via oversized SFTP read length - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure - CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification - CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs - CVE-2026-59849: Denial of service via automatic certificate authentication loop - CVE-2026-59850: Use-after-free via data callbacks on closed channels - Zero-initialize every ssh_string https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ (Closes: #1142537) Checksums-Sha1: a26ad09b012070e6fdb066a1405061e761a7c70a 562928 libssh-4-dbgsym_0.11.5-0+deb13u1_s390x.deb 322b7ed462c1d4771c11eb841557e00757e36229 195776 libssh-4_0.11.5-0+deb13u1_s390x.deb 26aed956a9d61e8c2fca425a09765d1d6c91a836 256292 libssh-dev_0.11.5-0+deb13u1_s390x.deb b90c8a642e1255405560362c08d855d83ff4c9d7 8729 libssh_0.11.5-0+deb13u1_s390x-buildd.buildinfo Checksums-Sha256: e585136e727ccdf9c1ff5d3d747362c07511e5adfa2147870b59a4df7bc8e224 562928 libssh-4-dbgsym_0.11.5-0+deb13u1_s390x.deb 6e2d90b1dc22c8e3de8d947b9003c8e5d5d4e9c0a1473404bbddaf5f6f9eab22 195776 libssh-4_0.11.5-0+deb13u1_s390x.deb 1c78b0bb5994091cdeb68dcb41a71325e7836229ffcebf0ca58a2b0cd2c447fd 256292 libssh-dev_0.11.5-0+deb13u1_s390x.deb 09023dcc5d6be6721784b5d3631dfc3696ffee8102d73fb71f76a9621237cd75 8729 libssh_0.11.5-0+deb13u1_s390x-buildd.buildinfo Files: bcce576cba95f23976478ccbbaf22421 562928 debug optional libssh-4-dbgsym_0.11.5-0+deb13u1_s390x.deb 50cee8a96d2c2dacd812b6acd3c00feb 195776 libs optional libssh-4_0.11.5-0+deb13u1_s390x.deb 5fe8ab1f83f3633b561c001e578d6bf3 256292 libdevel optional libssh-dev_0.11.5-0+deb13u1_s390x.deb d17192e165e0a6da71a7ed79068ba99f 8729 libs optional libssh_0.11.5-0+deb13u1_s390x-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfUKc1SwkyxlVJBiWHOd5r2LlPicFAmpuT9AACgkQHOd5r2Ll PicgxRAAwdl0Ug3HJg6nyk1GbM/ApjLSxzwC2F/XIxX/sqS6I+oLr6DEf0F5zeNe Znu82WNq9phTKorNZKo6Qk7cjRjMFIye1xn8WSctNEc/C5BjIlEg408JLPOXlONa Hh+yPlGpnXVt98293ttqWVpxJplhptvLe5jkNP0shsUTRFiKdn90Ep/NaDHx3WJ+ /fLYQdlKsHv8pgPmPgd2xzL5CW2wiSD8tCN7vmPLbgEngZBktmbjIyOuX+8Z+gsi kI/HcvWDfEtSGV/h/i8JnHbgA6AjNQMzku38e3M2VYRxIJhXKPirS/G6W7i3vJZm nmQmBwwyhLTp5EmDeSsgwv70UbqnCchMhqFdW6RpsvdmV8ZOfIoTenrUIM3HZUPp xZVJytO7y83iNI4MSUNH5YfLh7dSqLS6f/cZMYV+sFEJ1AD0cFJTAHjgSpJeMYHv dU0+PGg/pgKVBifZzswfKrECWyyNrfCqjRLTLM3qB9AWUv6JtslorHf5aT8QE+Zt PZ3byN8KIFKbyGjKOskuRVsSXmjdlUHXmEjWSDGBZdnEBTA+r1P1w581+kEcuvZ9 ctgM1KVLKZV06jjNtnEGjhZ95yLa4dtIpx0o6odWCjiId59vBDq9crD+sZSrJJ5l 2+NzvIUewpWw7Xd3g9FMMe91durBIAKCn0chQRd8Zo3nO0d1EGI= =lSpV -----END PGP SIGNATURE-----