From 87b425ca6dab61fc8a202f8570c91a725d1cbebd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Stefan=20M=C3=BCller?= Date: Thu, 20 Aug 2026 07:32:05 +0000 Subject: [PATCH] package/libssh2: fix CVE-2026-66032 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Backport the fix for CVE-2026-66032. A SFTP error path can leave a dangling pointer after freeing the response buffer, which may result in a double free on subsequent error handling. Use Debian's libssh2 1.11.1 backport of the upstream fix. Signed-off-by: Stefan Müller [Julien: add links to Debian patches] Signed-off-by: Julien Olivain (cherry picked from commit 05c13e87e983705ef65c18979a5d1bb7b50438a2) Signed-off-by: Titouan Christophe --- ...-prevent-dangling-pointer-after-free.patch | 29 +++++++++++++++++++ package/libssh2/libssh2.mk | 3 ++ 2 files changed, 32 insertions(+) create mode 100644 package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch diff --git a/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch b/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch new file mode 100644 index 0000000000..3658c00e0d --- /dev/null +++ b/package/libssh2/0007-sftp-prevent-dangling-pointer-after-free.patch @@ -0,0 +1,29 @@ +From 5e4776146552d898b9c0e1b313cd093fa8dc92d0 Mon Sep 17 00:00:00 2001 +From: Will Cosgrove +Date: Thu, 2 Jul 2026 11:00:23 -0700 +Subject: [PATCH] Prevent dangling pointer by nullifying data (#2180) + +Set data to NULL after freeing it to avoid dangling pointer. fixes +GHSA-px3w-7g75-hg7w. + +Credit: VladimirEliTokarev +Forwarded: not-needed + +CVE: CVE-2026-66032 +Upstream: https://sources.debian.org/patches/libssh2/1.11.1-6/CVE-2026-66032.patch/ +Upstream: https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0 +Signed-off-by: Stefan Müller +--- + src/sftp.c | 1 + + 1 file changed, 1 insertion(+) + +--- a/src/sftp.c ++++ b/src/sftp.c +@@ -1279,6 +1279,7 @@ + "got HANDLE FXOK")); + + LIBSSH2_FREE(session, data); ++ data = NULL; + + /* silly situation, but check for a HANDLE */ + rc = sftp_packet_require(sftp, SSH_FXP_HANDLE, diff --git a/package/libssh2/libssh2.mk b/package/libssh2/libssh2.mk index 6b2d774b38..583ed56c1c 100644 --- a/package/libssh2/libssh2.mk +++ b/package/libssh2/libssh2.mk @@ -27,6 +27,9 @@ LIBSSH2_IGNORE_CVES += CVE-2026-55200 # 0006-sftp-symlink-fix-SSH_FXP_STATUS-response.patch LIBSSH2_IGNORE_CVES += CVE-2025-15661 +# 0007-sftp-prevent-dangling-pointer-after-free.patch +LIBSSH2_IGNORE_CVES += CVE-2026-66032 + ifeq ($(BR2_PACKAGE_LIBSSH2_MBEDTLS),y) LIBSSH2_DEPENDENCIES += mbedtls LIBSSH2_CONF_OPTS += --with-libmbedcrypto-prefix=$(STAGING_DIR)/usr \