diff --git a/openssh-10.4p1-CVE-2026-59995.patch b/openssh-10.4p1-CVE-2026-59995.patch new file mode 100644 index 0000000..0ba8388 --- /dev/null +++ b/openssh-10.4p1-CVE-2026-59995.patch @@ -0,0 +1,20 @@ +diff --git a/sftp.c b/sftp.c +index 0ab9206c2..0b57e0833 100644 +--- a/sftp.c ++++ b/sftp.c +@@ -2289,13 +2289,8 @@ interactive_loop(struct sftp_conn *conn, char *file1, char *file2) + return (-1); + } + } else { +- /* XXX this is wrong wrt quoting */ +- snprintf(cmd, sizeof cmd, "get%s %s%s%s", +- global_aflag ? " -a" : "", dir, +- file2 == NULL ? "" : " ", +- file2 == NULL ? "" : file2); +- err = parse_dispatch_command(conn, cmd, +- &remote_path, startdir, 1, 0); ++ err = process_get(conn, dir, file2, remote_path, 0, 0, ++ global_aflag, 0); + free(dir); + free(startdir); + free(remote_path); diff --git a/openssh.spec b/openssh.spec index f5907f1..5ad348c 100644 --- a/openssh.spec +++ b/openssh.spec @@ -47,9 +47,9 @@ # Do not forget to bump pam_ssh_agent_auth release if you rewind the main package release to 1 %global openssh_ver 9.9p1 -%global openssh_rel 11 +%global openssh_rel 12 %global pam_ssh_agent_ver 0.10.4 -%global pam_ssh_agent_rel 9 +%global pam_ssh_agent_rel 10 Summary: An open source implementation of SSH protocol version 2 Name: openssh @@ -269,6 +269,8 @@ Patch1047: openssh-9.9p1-cve-2026-60002.patch # upstream eddd1d2daa64a6ab1a915ca88436fa41aede44d4 # upstream bc328144f149af07139a0f2c1329018cd85b86b7 Patch1048: openssh-9.9p1-maxstartups-mistracking.patch +# upstream 6a57081dc35acf3ee298108d4bc3580489608d5f +Patch1049: openssh-10.4p1-CVE-2026-59995.patch License: BSD @@ -492,6 +494,7 @@ popd %patch1046 -p1 -b .scp-remote-glob %patch1047 -p1 -b .cve-2026-60002 %patch1048 -p1 -b .maxstartups-mistracking +%patch1049 -p1 -b .CVE-2026-59995 %patch100 -p1 -b .coverity @@ -782,6 +785,11 @@ test -f %{sysconfig_anaconda} && \ %endif %changelog +* Wed Aug 12 2026 Dmitry Belyavskiy - 9.9p1-12 +- Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded + file location + Resolves: RHEL-236326 + * Thu Jul 30 2026 Zoltan Fridrich - 9.9p1-11 - Fix mistracking of MaxStartups process exits in some situations Resolves: RHEL-216650