diff mbox series

[wrynose,2/3] openssh: fix CVE-2026-73282

Message ID 20260929035745.321529-2-hthakar@cisco.com
State New
Headers show
Series [wrynose,1/3] openssh: fix CVE-2026-73283 | expand

Commit Message

From: Hetvi Thakar <hthakar@cisco.com>

This patch applies the upstream fix that tracks pending remote-forward
requests by index instead of retaining a pointer that realloc may
invalidate. The upstream fix commit is referenced in [1], and the
public CVE advisory is referenced in [2].

[1] https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299
[2] https://www.cve.org/CVERecord?id=CVE-2026-73282

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
 .../openssh/openssh/CVE-2026-73282.patch      | 80 +++++++++++++++++++
 .../openssh/openssh_10.3p1.bb                 |  1 +
 2 files changed, 81 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch
diff mbox series

Patch

diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch
new file mode 100644
index 00000000000..f5b4762e511
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch
@@ -0,0 +1,80 @@ 
+From 9910d5ef53124ce1157d57bc11e222658aa41299 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Fri, 7 Aug 2026 05:03:56 +0000
+Subject: [PATCH] upstream: avoid potential realloc use-after-free in the
+ client if a
+
+remote forwarding is added via the local session multiplexing socket while a
+remote forwarding open request is pending with the server.
+
+Report and fix from Brian Mingus of Cognatory
+
+OpenBSD-Commit-ID: c7888d566576386d0e96859f9ec7310a1e2d3609
+
+CVE: CVE-2026-73282
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299]
+
+Backport Changes:
+- Omitted the upstream OpenBSD revision-only hunk and retained the Wrynose
+  OpenSSH 10.3p1 revision.
+
+(cherry picked from commit 9910d5ef53124ce1157d57bc11e222658aa41299)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ ssh.c | 19 +++++++++++++++++--
+ 1 file changed, 16 insertions(+), 3 deletions(-)
+
+diff --git a/ssh.c b/ssh.c
+index d030b548..e9f99c43 100644
+--- a/ssh.c
++++ b/ssh.c
+@@ -1899,14 +1899,24 @@
+ 	}
+ }
+ 
++struct rfwd_confirm_ctx {
++	int fid;
++};
++
+ /* Callback for remote forward global requests */
+ static void
+ ssh_confirm_remote_forward(struct ssh *ssh, int type, uint32_t seq, void *ctxt)
+ {
+-	struct Forward *rfwd = (struct Forward *)ctxt;
++	struct rfwd_confirm_ctx *rctx = (struct rfwd_confirm_ctx *)ctxt;
++	struct Forward *rfwd;
+ 	u_int port;
+ 	int r;
+ 
++	if (rctx->fid < 0 || rctx->fid >= options.num_remote_forwards)
++		fatal_f("invalid forwarding ID %d", rctx->fid);
++	rfwd = &options.remote_forwards[rctx->fid];
++	freezero(rctx, sizeof(*rctx));
++
+ 	/* XXX verbose() on failure? */
+ 	debug("remote forward %s for: listen %s%s%d, connect %s:%d",
+ 	    type == SSH2_MSG_REQUEST_SUCCESS ? "success" : "failure",
+@@ -2084,6 +2094,8 @@
+ 
+ 	/* Initiate remote TCP/IP port forwardings. */
+ 	for (i = 0; i < options.num_remote_forwards; i++) {
++		struct rfwd_confirm_ctx *rctx;
++
+ 		debug("Remote connections from %.200s:%d forwarded to "
+ 		    "local address %.200s:%d",
+ 		    (options.remote_forwards[i].listen_path != NULL) ?
+@@ -2098,9 +2110,10 @@
+ 		if ((options.remote_forwards[i].handle =
+ 		    channel_request_remote_forwarding(ssh,
+ 		    &options.remote_forwards[i])) >= 0) {
++			rctx = xcalloc(1, sizeof(*rctx));
++			rctx->fid = i;
+ 			client_register_global_confirm(
+-			    ssh_confirm_remote_forward,
+-			    &options.remote_forwards[i]);
++			    ssh_confirm_remote_forward, rctx);
+ 			forward_confirms_pending++;
+ 		} else if (options.exit_on_forward_failure)
+ 			fatal("Could not request remote forwarding.");
+-- 
+2.43.0
diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
index 3085f71bc6e..00e2cd8726e 100644
--- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb
@@ -32,6 +32,7 @@  SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta
            file://CVE-2026-60002.patch \
            file://CVE-2026-60000.patch \
            file://CVE-2026-73283.patch \
+           file://CVE-2026-73282.patch \
            "
 SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4"