Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1108407: libssh: CVE-2025-4877 CVE-2025-4878 CVE-2025-5318 CVE-2025

    From Martin Pitt@21:1/5 to All on Sun Jul 6 16:50:01 2025
    Hello Salvatore and Debian Security Team,

    Salvatore Bonaccorso [2025-06-27 21:48 +0200]:
    The following vulnerabilities were published for libssh.

    [0] https://security-tracker.debian.org/tracker/CVE-2025-4877
    https://www.cve.org/CVERecord?id=CVE-2025-4877
    [1] https://security-tracker.debian.org/tracker/CVE-2025-4878
    https://www.cve.org/CVERecord?id=CVE-2025-4878
    [2] https://security-tracker.debian.org/tracker/CVE-2025-5318
    https://www.cve.org/CVERecord?id=CVE-2025-5318
    [3] https://security-tracker.debian.org/tracker/CVE-2025-5351
    https://www.cve.org/CVERecord?id=CVE-2025-5351
    [4] https://security-tracker.debian.org/tracker/CVE-2025-5372
    https://www.cve.org/CVERecord?id=CVE-2025-5372
    [5] https://security-tracker.debian.org/tracker/CVE-2025-5449
    https://www.cve.org/CVERecord?id=CVE-2025-5449
    [6] https://security-tracker.debian.org/tracker/CVE-2025-5987
    https://www.cve.org/CVERecord?id=CVE-2025-5987

    The unstable → testing fix for these just landed [1], thanks for nudging that!

    I backported the fixes to the 0.10.6 package in bookworm. Note that CVE-2025-5449 dos not apply to the 0.10.x and older series, none of the affected code exits. The other patches were relatively straightforward to backport.

    I pushed the backport to salsa [2] already and locally prepared the update, debdiff at [3]. I didn't push the release tag/changelog commit to salsa yet, I'll do that once I get your ok to upload this.

    Thanks,

    Martin

    [1] https://tracker.debian.org/news/1650288/libssh-0112-1-migrated-to-testing/ [2] https://salsa.debian.org/debian/libssh/-/commit/ae681fa733b65a2792d04660232e8e1407d92e75
    [3] https://people.debian.org/~mpitt/tmp/libssh_0.10.6-0+deb12u2.debdiff

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Salvatore Bonaccorso@21:1/5 to Martin Pitt on Sun Jul 6 21:00:01 2025
    Hi Martin,

    On Sun, Jul 06, 2025 at 04:35:09PM +0200, Martin Pitt wrote:
    Hello Salvatore and Debian Security Team,

    Salvatore Bonaccorso [2025-06-27 21:48 +0200]:
    The following vulnerabilities were published for libssh.

    [0] https://security-tracker.debian.org/tracker/CVE-2025-4877
    https://www.cve.org/CVERecord?id=CVE-2025-4877
    [1] https://security-tracker.debian.org/tracker/CVE-2025-4878
    https://www.cve.org/CVERecord?id=CVE-2025-4878
    [2] https://security-tracker.debian.org/tracker/CVE-2025-5318
    https://www.cve.org/CVERecord?id=CVE-2025-5318
    [3] https://security-tracker.debian.org/tracker/CVE-2025-5351
    https://www.cve.org/CVERecord?id=CVE-2025-5351
    [4] https://security-tracker.debian.org/tracker/CVE-2025-5372
    https://www.cve.org/CVERecord?id=CVE-2025-5372
    [5] https://security-tracker.debian.org/tracker/CVE-2025-5449
    https://www.cve.org/CVERecord?id=CVE-2025-5449
    [6] https://security-tracker.debian.org/tracker/CVE-2025-5987
    https://www.cve.org/CVERecord?id=CVE-2025-5987

    The unstable → testing fix for these just landed [1], thanks for nudging that!

    Wecome!

    I backported the fixes to the 0.10.6 package in bookworm. Note that CVE-2025-5449 dos not apply to the 0.10.x and older series, none of the affected code exits. The other patches were relatively straightforward to backport.

    Thanks will have a look and update the security-tracker metadata.

    I pushed the backport to salsa [2] already and locally prepared the update, debdiff at [3]. I didn't push the release tag/changelog commit to salsa yet, I'll do that once I get your ok to upload this.

    We did mark those actually all no-dsa, thinking they do not warrant a
    DSA. But can you please fix those via the next bookworm-pu now that
    the upper suite is fixed as well?

    Thanks for your work!

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 41:57:17
    Calls: 12,109
    Files: 15,006
    Messages: 6,518,416

© >>> Magnum BBS <<<, 2026