mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
- CVE-2026-55200:
libssh2 through 1.11.1, fixed in commit 97acf3df contains an out-of-
bounds write vulnerability in ssh2_transport_read() that fails to
enforce upper bounds on packet_length field. Remote attackers can send
crafted SSH packets with excessively large packet_length values to
corrupt heap memory and achieve remote code execution.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-55200
- 97acf3dfda
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
37 lines
1.4 KiB
Diff
37 lines
1.4 KiB
Diff
From 97acf3dfda80c91c3a8c9f2372546301d4a1a7a8 Mon Sep 17 00:00:00 2001
|
|
From: Will Cosgrove <will@panic.com>
|
|
Date: Fri, 12 Jun 2026 15:57:44 -0700
|
|
Subject: [PATCH] transport.c: Additional boundary checks for packet length
|
|
(#2052)
|
|
|
|
Add additional bounds checking on packet length to prevent OOB write.
|
|
|
|
Credit: [TristanInSec](https://github.com/TristanInSec)
|
|
|
|
CVE: CVE-2026-55200
|
|
Upstream: https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8
|
|
[thomas: backport to 1.11.1, change ntohu32 call]
|
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
|
---
|
|
src/transport.c | 6 +++++-
|
|
1 file changed, 5 insertions(+), 1 deletion(-)
|
|
|
|
diff --git a/src/transport.c b/src/transport.c
|
|
index 869fc5a4fa..7925ad33d1 100644
|
|
--- a/src/transport.c
|
|
+++ b/src/transport.c
|
|
@@ -645,8 +645,12 @@ int ssh2_transport_read(LIBSSH2_SESSION *session)
|
|
total_num = 4;
|
|
|
|
p->packet_length = _libssh2_ntohu32(block);
|
|
- if(p->packet_length < 1)
|
|
+ if(p->packet_length < 1) {
|
|
return LIBSSH2_ERROR_DECRYPT;
|
|
+ }
|
|
+ else if(p->packet_length > LIBSSH2_PACKET_MAXPAYLOAD) {
|
|
+ return LIBSSH2_ERROR_OUT_OF_BOUNDARY;
|
|
+ }
|
|
|
|
/* total_num may include size field, however due to existing
|
|
* logic it needs to be removed after the entire packet is read
|