From 363cb74e6b68bdf507ba6070620df9d77208254a Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Thu, 26 Mar 2026 16:32:24 +0100 Subject: [PATCH] CVE-2026-59845 socket: Properly check fork() return code MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit During execution of proxy command, when fork() fails, its return value is stored in pid and when the parent process attempts to kill it, it sends the kill signal to all processes the calling application has access to (except for init). This caused nard to debug issues when the system under the load was hitting fork failures, which resulted in killing of all the system processes (of given user). Reported and first patch iteration provided by: Halil Oktay (oblivionsage). This code missing fork return value check is in libssh since 2010 (f31a14b7932ef4cc165ddd8f1f1a5b23eb21beb3), but this issue is exploitable only since libssh 0.9.0 as previously there was no implementation of killing ProxyCommand children. Signed-off-by: Jakub Jelen Reviewed-by: Pavol Žáčik --- src/socket.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/src/socket.c b/src/socket.c index f470bb28..84777058 100644 --- a/src/socket.c +++ b/src/socket.c @@ -918,7 +918,17 @@ ssh_socket_connect_proxycommand(ssh_socket s, const char *command) pid = fork(); if (pid == 0) { ssh_execute_command(command, pair[0], pair[0]); - /* Does not return */ + /* child: Does not return */ + } + /* parent */ + if (pid == -1) { + close(pair[0]); + close(pair[1]); + ssh_set_error(s->session, + SSH_FATAL, + "fork failed: %s", + strerror(errno)); + return SSH_ERROR; } s->proxy_pid = pid; close(pair[0]);