new file mode 100644
@@ -0,0 +1,80 @@
+From 9910d5ef53124ce1157d57bc11e222658aa41299 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Fri, 7 Aug 2026 05:03:56 +0000
+Subject: [PATCH] upstream: avoid potential realloc use-after-free in the
+ client if a
+
+remote forwarding is added via the local session multiplexing socket while a
+remote forwarding open request is pending with the server.
+
+Report and fix from Brian Mingus of Cognatory
+
+OpenBSD-Commit-ID: c7888d566576386d0e96859f9ec7310a1e2d3609
+
+CVE: CVE-2026-73282
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299]
+
+Backport Changes:
+- Omitted the upstream OpenBSD revision-only hunk and retained the Wrynose
+ OpenSSH 10.3p1 revision.
+
+(cherry picked from commit 9910d5ef53124ce1157d57bc11e222658aa41299)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ ssh.c | 19 +++++++++++++++++--
+ 1 file changed, 16 insertions(+), 3 deletions(-)
+
+diff --git a/ssh.c b/ssh.c
+index d030b548..e9f99c43 100644
+--- a/ssh.c
++++ b/ssh.c
+@@ -1899,14 +1899,24 @@
+ }
+ }
+
++struct rfwd_confirm_ctx {
++ int fid;
++};
++
+ /* Callback for remote forward global requests */
+ static void
+ ssh_confirm_remote_forward(struct ssh *ssh, int type, uint32_t seq, void *ctxt)
+ {
+- struct Forward *rfwd = (struct Forward *)ctxt;
++ struct rfwd_confirm_ctx *rctx = (struct rfwd_confirm_ctx *)ctxt;
++ struct Forward *rfwd;
+ u_int port;
+ int r;
+
++ if (rctx->fid < 0 || rctx->fid >= options.num_remote_forwards)
++ fatal_f("invalid forwarding ID %d", rctx->fid);
++ rfwd = &options.remote_forwards[rctx->fid];
++ freezero(rctx, sizeof(*rctx));
++
+ /* XXX verbose() on failure? */
+ debug("remote forward %s for: listen %s%s%d, connect %s:%d",
+ type == SSH2_MSG_REQUEST_SUCCESS ? "success" : "failure",
+@@ -2084,6 +2094,8 @@
+
+ /* Initiate remote TCP/IP port forwardings. */
+ for (i = 0; i < options.num_remote_forwards; i++) {
++ struct rfwd_confirm_ctx *rctx;
++
+ debug("Remote connections from %.200s:%d forwarded to "
+ "local address %.200s:%d",
+ (options.remote_forwards[i].listen_path != NULL) ?
+@@ -2098,9 +2110,10 @@
+ if ((options.remote_forwards[i].handle =
+ channel_request_remote_forwarding(ssh,
+ &options.remote_forwards[i])) >= 0) {
++ rctx = xcalloc(1, sizeof(*rctx));
++ rctx->fid = i;
+ client_register_global_confirm(
+- ssh_confirm_remote_forward,
+- &options.remote_forwards[i]);
++ ssh_confirm_remote_forward, rctx);
+ forward_confirms_pending++;
+ } else if (options.exit_on_forward_failure)
+ fatal("Could not request remote forwarding.");
+--
+2.43.0
@@ -32,6 +32,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta
file://CVE-2026-60002.patch \
file://CVE-2026-60000.patch \
file://CVE-2026-73283.patch \
+ file://CVE-2026-73282.patch \
"
SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4"