-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 01 Aug 2026 13:42:11 +0200 Source: libssh Binary: libssh-4 libssh-4-dbgsym libssh-dev Architecture: i386 Version: 0.11.5-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Martin Pitt Description: libssh-4 - tiny C SSH library (OpenSSL flavor) libssh-dev - tiny C SSH library - Development files (OpenSSL flavor) Closes: 1127693 1142537 Changes: libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium . * New upstream security/bug fix release 0.11.4: - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname() - CVE-2026-3731: Read buffer overrun when handling SFTP extensions - Note: CVE-2025-14821 is Windows specific, does not apply to Linux https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ (Closes: #1127693) * New upstream security/bug fix release 0.11.5: - CVE-2026-15370: Stack buffer overflow in SFTP server longname construction - CVE-2026-59843: Denial of service via zero advertised channel packet size - CVE-2026-59844: Denial of service via oversized SFTP read length - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure - CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification - CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs - CVE-2026-59849: Denial of service via automatic certificate authentication loop - CVE-2026-59850: Use-after-free via data callbacks on closed channels - Zero-initialize every ssh_string https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ (Closes: #1142537) Checksums-Sha1: fa05ed28a9fd0c7a8d6628ec51764aa03f193dbd 476760 libssh-4-dbgsym_0.11.5-0+deb13u1_i386.deb c98dd555cd84401577930706cf9536538fc93ce6 232288 libssh-4_0.11.5-0+deb13u1_i386.deb 9b4a37ebf252bd7b7c7d9871565c7497bc837885 294840 libssh-dev_0.11.5-0+deb13u1_i386.deb cd9b2ea655b3be265ea11ef74e43d164f9adc170 8765 libssh_0.11.5-0+deb13u1_i386-buildd.buildinfo Checksums-Sha256: 1b2f16d504cdba16b4d67975ab83534ebecfc4c4a066bf587935724a38db5186 476760 libssh-4-dbgsym_0.11.5-0+deb13u1_i386.deb 98b1d23b99852ddb6119e81f8f71184e44ef36a02c84a26b0e28eb10be06311f 232288 libssh-4_0.11.5-0+deb13u1_i386.deb b6c9a3a5a4b9611cb4c2972d17784c898624bdbd2cba51274e54a81c03a833eb 294840 libssh-dev_0.11.5-0+deb13u1_i386.deb a729d556f67cb8a46044746ccc9924502cdebfa1f3749d7e06dec2047ed0503f 8765 libssh_0.11.5-0+deb13u1_i386-buildd.buildinfo Files: 1d46a34040d23524dec456f5f071016e 476760 debug optional libssh-4-dbgsym_0.11.5-0+deb13u1_i386.deb 0025ad3b1347c7556e731cb71a843ed7 232288 libs optional libssh-4_0.11.5-0+deb13u1_i386.deb 32499e6c8eb2256199b7ddd175f30a22 294840 libdevel optional libssh-dev_0.11.5-0+deb13u1_i386.deb 467302313f388edf295832eea4654ca6 8765 libs optional libssh_0.11.5-0+deb13u1_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmpuUDUACgkQTwt/65ON 6zfv9Q//TisQMfITCP95OzZEw14QpbJZJY49LkAH85PyJsLvgz3NSl5omGDYNnJN W4uQta5TiBd/kuQeCuM2GgcxxpeNIxNjb/5WBkZURonYNAH+hF5L8HzQn/I/CFjl 0ZDg/etQO0PVXa5toHOCXegFTL1TsfaFo9BJzwfkyV0j/YnrmfqhxJtuy3YvG9O0 v+aIorAHyeLVGO45hFFNrwA6T32vqF07R9RXTf8Hoa8GTP+QoFcy2Ui9PNZ5b4t7 ipgBTJEj2ZilFbzYHeCDY05vrvzZ79q3OBfSY10mZwiypV0apVnposRcXZ1jSBo5 9r7+TDkJs9vu7Eytidtco+xW2E6DTeelFjS2KxyeQfMXLAwk1mGVcdHbaQpCW/mq XpXiaq63rpyPC8xku5eiA1p+uL/7i03lis36Cc3Hjc4qezX9cd6BIXT/xsPke7b9 gCTSWtmyRyTOs6qCYhY0t33tutWejfnae1NDd6uc7G+4UoI4LwjVCWrsoOMD5z63 wxF8Nz4nscvdRH+C09MWNpNqKQi7ouVe99jmV3Vbrc46kNLxr1ggVewVD36Mdy0y SrUCwnM1uLx+iC1ak8VJe9x9Jhr+rRBcRPMga4XCvhWOx4/vJjc+uwlKeBnj6e3q eugIteYXF1DvsZa34jEDZ2TPp/TD6yRSaUgQyy2c31EnSaJmUUc= =VUHB -----END PGP SIGNATURE-----