]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
openssh: Fix CVE-2025-26466
authorVijay Anusuri <vanusuri@mvista.com>
Tue, 4 Mar 2025 04:06:58 +0000 (09:36 +0530)
committerSteve Sakoman <steve@sakoman.com>
Tue, 4 Mar 2025 14:13:52 +0000 (06:13 -0800)
commit7360f3998939e202f9611644a8bed0c3fe0c782a
tree6e8000309948fc358d16acb054aa421ccece92d0
parentc74a6d6afc52606825e583cae1162e13a5369498
openssh: Fix CVE-2025-26466

sshd(8) in OpenSSH versions 9.5p1 to 9.9p1
  (inclusive) is vulnerable to a memory/CPU denial-of-service related
  to the handling of SSH2_MSG_PING packets. This condition may be
  mitigated using the existing PerSourcePenalties feature.

Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/6ce00f0c2ecbb9f75023dbe627ee6460bcec78c2]

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-connectivity/openssh/openssh/CVE-2025-26466.patch [new file with mode: 0644]
meta/recipes-connectivity/openssh/openssh_9.6p1.bb