mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-01 06:21:56 -09:00
Backport the fix for CVE-2026-66034. The publickey subsystem does not sufficiently validate the length of a server-controlled comment field. A malformed response can therefore cause an out-of-bounds read. Use Debian's libssh2 1.11.1 backport of the upstream fix. Signed-off-by: Stefan Müller <stefan.mueller@rey-technology.com> [Julien: add links to Debian patches] Signed-off-by: Julien Olivain <ju.o@free.fr>
1.2 KiB
1.2 KiB