package/libssh2: backport upstream patch for CVE-2026-55200

- CVE-2026-55200:
    libssh2 through 1.11.1, fixed in commit 97acf3df contains an out-of-
    bounds write vulnerability in ssh2_transport_read() that fails to
    enforce upper bounds on packet_length field. Remote attackers can send
    crafted SSH packets with excessively large packet_length values to
    corrupt heap memory and achieve remote code execution.

For more information, see:
  - https://www.cve.org/CVERecord?id=CVE-2026-55200
  - 97acf3dfda

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
This commit is contained in:
Thomas Perale
2026-06-30 21:42:00 +02:00
committed by Fiona Klute
parent 3c8cfad804
commit c5aa932745
2 changed files with 39 additions and 0 deletions

View File

@@ -0,0 +1,36 @@
From 97acf3dfda80c91c3a8c9f2372546301d4a1a7a8 Mon Sep 17 00:00:00 2001
From: Will Cosgrove <will@panic.com>
Date: Fri, 12 Jun 2026 15:57:44 -0700
Subject: [PATCH] transport.c: Additional boundary checks for packet length
(#2052)
Add additional bounds checking on packet length to prevent OOB write.
Credit: [TristanInSec](https://github.com/TristanInSec)
CVE: CVE-2026-55200
Upstream: https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8
[thomas: backport to 1.11.1, change ntohu32 call]
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
---
src/transport.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/src/transport.c b/src/transport.c
index 869fc5a4fa..7925ad33d1 100644
--- a/src/transport.c
+++ b/src/transport.c
@@ -645,8 +645,12 @@ int ssh2_transport_read(LIBSSH2_SESSION *session)
total_num = 4;
p->packet_length = _libssh2_ntohu32(block);
- if(p->packet_length < 1)
+ if(p->packet_length < 1) {
return LIBSSH2_ERROR_DECRYPT;
+ }
+ else if(p->packet_length > LIBSSH2_PACKET_MAXPAYLOAD) {
+ return LIBSSH2_ERROR_OUT_OF_BOUNDARY;
+ }
/* total_num may include size field, however due to existing
* logic it needs to be removed after the entire packet is read

View File

@@ -19,6 +19,9 @@ LIBSSH2_IGNORE_CVES += CVE-2026-7598
# 0002-packet-check-libssh2-get-string-return-in-EXT-INFO-handler.patch # 0002-packet-check-libssh2-get-string-return-in-EXT-INFO-handler.patch
LIBSSH2_IGNORE_CVES += CVE-2026-55199 LIBSSH2_IGNORE_CVES += CVE-2026-55199
# 0003-transport-c-Additional-boundary-checks-for-packet-length.patch
LIBSSH2_IGNORE_CVES += CVE-2026-55200
ifeq ($(BR2_PACKAGE_LIBSSH2_MBEDTLS),y) ifeq ($(BR2_PACKAGE_LIBSSH2_MBEDTLS),y)
LIBSSH2_DEPENDENCIES += mbedtls LIBSSH2_DEPENDENCIES += mbedtls
LIBSSH2_CONF_OPTS += --with-libmbedcrypto-prefix=$(STAGING_DIR)/usr \ LIBSSH2_CONF_OPTS += --with-libmbedcrypto-prefix=$(STAGING_DIR)/usr \