stable

libssh2-1.11.1-1.el10_1

FEDORA-EPEL-2025-206aae91e0 created by pghmcfc 2 months ago for Fedora EPEL 10.1

This update, to the current upstream libssh2 release, addresses a couple of security issues:

  • CVE-2023-6918 (missing checks for return values for digests)
  • CVE-2023-48795 (prefix truncation attack on Binary Packet Protocol (BPP) - "Terrapin")

It also removes support for a number of legacy algorithms that were disabled by default or removed from OpenSSH in the 2015-2018 time period. See the RELEASE_NOTES file for full details.

In addition, there are a large number of bug fixes and enhancements, which again are described in the RELEASE_NOTES file.

This update has been submitted for testing by pghmcfc.

2 months ago

This update's test gating status has been changed to 'ignored'.

2 months ago

This update has been pushed to testing.

2 months ago

This update has been submitted for stable by bodhi.

a month ago

This update has been pushed to stable.

a month ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-1
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
2 months ago
in testing
2 months ago
in stable
a month ago
approved
a month ago
BZ#2254210 CVE-2023-48795 ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
0
0
BZ#2254997 CVE-2023-6918 libssh: Missing checks for return values for digests
0
0
BZ#2255046 CVE-2023-48795 libssh2: ssh: Prefix truncation attack on Binary Packet Protocol (BPP) [epel-all]
0
0
BZ#2255158 TRIAGE CVE-2023-6918 libssh2: libssh: Missing checks for return values for digests [epel-all]
0
0

Automated Test Results