new file mode 100644
@@ -0,0 +1,68 @@
+From 53b8152623290c69657a6774d96888b876e6061f Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Thu, 26 Mar 2026 16:32:24 +0100
+Subject: CVE-2026-59845 socket: Properly check fork() return code
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+During execution of proxy command, when fork() fails, its return value
+is stored in pid and when the parent process attempts to kill it,
+it sends the kill signal to all processes the calling application has
+access to (except for init).
+
+This caused nard to debug issues when the system under the load was hitting
+fork failures, which resulted in killing of all the system processes
+(of given user).
+
+Reported and first patch iteration provided by: Halil Oktay (oblivionsage).
+
+This code missing fork return value check is in libssh since 2010
+(f31a14b7932ef4cc165ddd8f1f1a5b23eb21beb3), but this issue is exploitable only
+since libssh 0.9.0 as previously there was no implementation of killing
+ProxyCommand children.
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+(cherry picked from commit 92b6fb9c5e2d1606e8f809fd884ab6dd4d3b7d45)
+CVE: CVE-2026-59845
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/socket.c | 13 ++++++++++++-
+ 1 file changed, 12 insertions(+), 1 deletion(-)
+
+diff --git a/src/socket.c b/src/socket.c
+index 99dcf8cc..ba9ba52d 100644
+--- a/src/socket.c
++++ b/src/socket.c
+@@ -964,6 +964,7 @@ ssh_execute_command(const char *command, socket_t in, socket_t out)
+ int
+ ssh_socket_connect_proxycommand(ssh_socket s, const char *command)
+ {
++ char err_msg[SSH_ERRNO_MSG_MAX] = {0};
+ socket_t pair[2];
+ ssh_poll_handle h = NULL;
+ int pid;
+@@ -982,7 +983,17 @@ ssh_socket_connect_proxycommand(ssh_socket s, const char *command)
+ pid = fork();
+ if (pid == 0) {
+ ssh_execute_command(command, pair[0], pair[0]);
+- /* Does not return */
++ /* child: Does not return */
++ }
++ /* parent */
++ if (pid == -1) {
++ close(pair[0]);
++ close(pair[1]);
++ ssh_set_error(s->session,
++ SSH_FATAL,
++ "fork failed: %s",
++ ssh_strerror(errno, err_msg, SSH_ERRNO_MSG_MAX));
++ return SSH_ERROR;
+ }
+ s->proxy_pid = pid;
+ close(pair[0]);
+--
+2.50.1
+
new file mode 100644
@@ -0,0 +1,39 @@
+From c483a187354dfd96b16d3309a74f6d1cf82c2074 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Fri, 15 May 2026 17:01:21 +0200
+Subject: CVE-2026-59847 libcrypto: Fix tag verification of AES-GCM ciphers
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+EVP_DecryptFinal() returns 0 errors, which was wrongly checked since
+its introduction.
+
+Reported by Ben Smyth discuss@bensmyth.com
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+
+CVE: CVE-2026-59847
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/libcrypto.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/libcrypto.c b/src/libcrypto.c
+index 69a850de..ff27770c 100644
+--- a/src/libcrypto.c
++++ b/src/libcrypto.c
+@@ -674,7 +674,7 @@ evp_cipher_aead_decrypt(struct ssh_cipher_struct *cipher,
+ rc = EVP_DecryptFinal(cipher->ctx,
+ NULL,
+ &outlen);
+- if (rc < 0) {
++ if (rc != 1 || outlen != 0) {
+ SSH_LOG(SSH_LOG_WARNING, "EVP_DecryptFinal failed: Failed authentication");
+ return SSH_ERROR;
+ }
+--
+2.50.1
+
new file mode 100644
@@ -0,0 +1,35 @@
+From d4847509b792d564d1935dbfea4ee1496ad3d3d9 Mon Sep 17 00:00:00 2001
+From: Jakub Jelen <jjelen@redhat.com>
+Date: Mon, 18 May 2026 08:56:31 +0200
+Subject: CVE-2026-59847 libcrypto: Fix symmetric issue during encryption
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Jakub Jelen <jjelen@redhat.com>
+Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
+(cherry picked from commit a5173c6ad249f7960bc7c1cc75a6a05ead8e3eba)
+
+CVE: CVE-2026-59847
+Upstream-Status: Backport [https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/libcrypto.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/libcrypto.c b/src/libcrypto.c
+index ff27770c..95187e1d 100644
+--- a/src/libcrypto.c
++++ b/src/libcrypto.c
+@@ -586,7 +586,7 @@ evp_cipher_aead_encrypt(struct ssh_cipher_struct *cipher,
+ rc = EVP_EncryptFinal(cipher->ctx,
+ NULL,
+ &tmplen);
+- if (rc < 0) {
++ if (rc != 1) {
+ SSH_LOG(SSH_LOG_WARNING, "EVP_EncryptFinal failed: Failed to create a tag");
+ return;
+ }
+--
+2.50.1
+
@@ -32,6 +32,9 @@ SRC_URI = "git://git.libssh.org/projects/libssh.git;protocol=https;branch=stable
file://CVE-2026-0968-2.patch \
file://CVE-2026-0967.patch \
file://CVE-2026-0965.patch \
+ file://CVE-2026-59845.patch \
+ file://CVE-2026-59847-01.patch \
+ file://CVE-2026-59847-02.patch \
"
SRCREV = "10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
Pick patch from [1], [2] & [3] also mentioned at Debian report in [4] & [5] [1] https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f [2] https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074 [3] https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9 [4] https://security-tracker.debian.org/tracker/CVE-2026-59845 [5] https://security-tracker.debian.org/tracker/CVE-2026-59847 Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> --- .../libssh/libssh/CVE-2026-59845.patch | 68 +++++++++++++++++++ .../libssh/libssh/CVE-2026-59847-01.patch | 39 +++++++++++ .../libssh/libssh/CVE-2026-59847-02.patch | 35 ++++++++++ .../recipes-support/libssh/libssh_0.10.6.bb | 3 + 4 files changed, 145 insertions(+) create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59845.patch create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59847-01.patch create mode 100644 meta-oe/recipes-support/libssh/libssh/CVE-2026-59847-02.patch