-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 01 Aug 2026 13:42:11 +0200 Source: libssh Binary: libssh-doc Architecture: all Version: 0.11.5-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Martin Pitt Description: libssh-doc - tiny C SSH library - Documentation files Closes: 1127693 1142537 Changes: libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium . * New upstream security/bug fix release 0.11.4: - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname() - CVE-2026-3731: Read buffer overrun when handling SFTP extensions - Note: CVE-2025-14821 is Windows specific, does not apply to Linux https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ (Closes: #1127693) * New upstream security/bug fix release 0.11.5: - CVE-2026-15370: Stack buffer overflow in SFTP server longname construction - CVE-2026-59843: Denial of service via zero advertised channel packet size - CVE-2026-59844: Denial of service via oversized SFTP read length - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure - CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification - CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs - CVE-2026-59849: Denial of service via automatic certificate authentication loop - CVE-2026-59850: Use-after-free via data callbacks on closed channels - Zero-initialize every ssh_string https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ (Closes: #1142537) Checksums-Sha1: 6343e8a67bcf248be863d937c6966e64eea27bb1 615120 libssh-doc_0.11.5-0+deb13u1_all.deb 245a488bec89936fe48a7aefed39fee283a5c96b 10432 libssh_0.11.5-0+deb13u1_all-buildd.buildinfo Checksums-Sha256: 445ca323060b5564507c1d63d8bf2b443cfb9291df4f604b67d23168e809e034 615120 libssh-doc_0.11.5-0+deb13u1_all.deb 237f7ebd4aaa8efdf4207005d49e9ef586524fcdcc37d557d93371a8612c825e 10432 libssh_0.11.5-0+deb13u1_all-buildd.buildinfo Files: cb8fd155eaf32ad85adb6f4c60ddd2cc 615120 doc optional libssh-doc_0.11.5-0+deb13u1_all.deb 3563df89a8d7672a2eadb8f3196828d1 10432 libs optional libssh_0.11.5-0+deb13u1_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmpuT/UACgkQmgPNRvTf /zf7zRAAwQIY/jkxIFD5SHtmWjfxANwsO0ZXm4UkuGI8nY+iBA0vu+ZAz+qMuE09 /fZeYfn9MSKY7c6MPFtKuzz52aNMFVYZ+NeusZFmkrkVmnj7Uiwa2psGq52VJ4+7 YVHavlWgSE7cSVaWgEOuGEoaRsQLeRBP7HYbEFgLFeUPxynO+DBA9IKSqdcxCf9t XQfAIy3gqFZja9Qf4M67kKI4RimmUGo1V9iktqUMFlgjB4KqtuEvztANxphrhjAF +2bBqAxCfnxKnNaub9eTn/Onrj5dY6MQl46/MXVRCd8f4/Q+U+hzpAm+VneLnN/P GhKbzb7NfZPyPmFWhyQYLSKSkX14ujInTvE8SVgSsaqbT+ACEyPVeighYSif3WRB 0Tn2LQCNa6xemb81fRAiGqXCP2mDU5blVG+hLWxGMbWwsZg5OkmyXwilkwJVa7KA 0zL0B1phb1TIXyw7lIY5cqD7NSd5d4cvigRmr8/km8CAajxcfMTxuMCn3NIHNQVe N4U7voxqKsa0G8pqHtomJ39+HduWlnnJ/IVi0Zini0yV+rjUWulJG6Bi/T28IOXT gb/JfV5RxgMpsszkR4Y9Xx9Tx7o9N/3MnsxGJIJgjbJJFlyRaE2BGxSo1gX4ltdS ij6zqnzccAjoNeI4PYJLUsR68Lvq9xPbBFJRFK4HtSHYYnmNVfE= =pltT -----END PGP SIGNATURE-----