-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 01 Aug 2026 13:42:11 +0200 Source: libssh Architecture: source Version: 0.11.5-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Laurent Bigonville Changed-By: Martin Pitt Closes: 1127693 1142537 Changes: libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium . * New upstream security/bug fix release 0.11.4: - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname() - CVE-2026-3731: Read buffer overrun when handling SFTP extensions - Note: CVE-2025-14821 is Windows specific, does not apply to Linux https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ (Closes: #1127693) * New upstream security/bug fix release 0.11.5: - CVE-2026-15370: Stack buffer overflow in SFTP server longname construction - CVE-2026-59843: Denial of service via zero advertised channel packet size - CVE-2026-59844: Denial of service via oversized SFTP read length - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure - CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification - CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs - CVE-2026-59849: Denial of service via automatic certificate authentication loop - CVE-2026-59850: Use-after-free via data callbacks on closed channels - Zero-initialize every ssh_string https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ (Closes: #1142537) Checksums-Sha1: 2087dc4964630a8390271bf4168f8091174e0573 2371 libssh_0.11.5-0+deb13u1.dsc 004929095e3d23cfb3d999bec7779362afea9e73 629716 libssh_0.11.5.orig.tar.xz 30146aedb82f2b3790a117c21bebdea05b063e04 31932 libssh_0.11.5-0+deb13u1.debian.tar.xz 7533bd519a94a351f5601b9babbf9d82f5acf448 8085 libssh_0.11.5-0+deb13u1_source.buildinfo Checksums-Sha256: 8aeaec786998691f4a2a320ae66943d3fa324882465d2a91f62658a13cd7bcff 2371 libssh_0.11.5-0+deb13u1.dsc 6898ba9dd836d618b71dc7a4bb786a502c173cef5cafbf20fe5e0567ba4ea30c 629716 libssh_0.11.5.orig.tar.xz 00576a30d068e87813f96b1b8405d249d7fdaf75b9e61c5af775910dc15022fd 31932 libssh_0.11.5-0+deb13u1.debian.tar.xz 5bc098fe907fae7fd6a6cf9d1dc7d94a5ef4c348cbb73e5c1fc489da4dfac847 8085 libssh_0.11.5-0+deb13u1_source.buildinfo Files: 6d954a139c57a013b8c955c7f576cb58 2371 libs optional libssh_0.11.5-0+deb13u1.dsc 73aaa09a07041c6ec85b154cbcf604c3 629716 libs optional libssh_0.11.5.orig.tar.xz 7388f83349450388d6cae899b1059c92 31932 libs optional libssh_0.11.5-0+deb13u1.debian.tar.xz 270d452d8e4fe75f9f3a7b74904394ab 8085 libs optional libssh_0.11.5-0+deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmpuSoYACgkQ7nvd5Lhr VxM1TA//ZzzSSGg3N+ZXXGyE6NXDuo8QYJu6FtQz+wg5EGIOGojrpZzPorlzQns9 xmj7xidBx8T1M2fnJf+PA4i8iT/P1ZzfXqOOZJYBHeUR4euW1TaxOcrgPjeaTEeo jByYWX86FIIfGStutlAUIJUz77Lvf03rup2hY0ew3Cxj7z8/wFEnQ7zBxp6HbRlE 4v6ZFld8r/Bj7a/9O+YuCL0cA1E2QcUIoMqtibEatLKbmHD/guhNs1V9cfvcSEBh +mkU1cTyKNFB8wlG+HC4VGrFpow01stdu/1Vl6fYd6nXhcmjd//gosvK0PNa/e0+ gAY12pdlxioSaOoJe3lpnIl0AjC7X8cCXOv+9eZIkJ1fRpikV4eX068Y+Y92TdWC hGbgUxTSFSx0plvGhkkjLMq6p+f4ArQBqLc7TKSZpP3lfeCr4YmMSKkxs+hKzQCb Wm5Or26CCqW/uAyDL2c/duWaLpLtb0R9LL5E08gNLqYrgN3HfSFkcN4w3eVPfjq4 JdKdVR22QaWlJAaKcAMyzLfsSi/kC2QR3Td3XbCZTW6mqZ3kZ21FJ3B6GLwy6ku5 tpynFbuupiRGCZMNRfRaH+6otfOftec0So9DAmaann8Yln8DzxDRL5xAvcGPkza3 8ppL0RzYX/j5onShhwpFonPlPWwFvnBt6vdLQg2BgFyz7A0R/E4= =CuaC -----END PGP SIGNATURE-----