From ab99bff6e8e9e47f39904a19dd55ebf89b5604c9 Mon Sep 17 00:00:00 2001 From: Dmitry Belyavskiy Date: Wed, 12 Aug 2026 13:26:08 +0200 Subject: [PATCH] Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded ...file location Resolves: RHEL-236323 --- openssh-10.4p1-CVE-2026-59995.patch | 20 ++++++++++++++++++++ openssh.spec | 10 +++++++++- 2 files changed, 29 insertions(+), 1 deletion(-) create mode 100644 openssh-10.4p1-CVE-2026-59995.patch diff --git a/openssh-10.4p1-CVE-2026-59995.patch b/openssh-10.4p1-CVE-2026-59995.patch new file mode 100644 index 0000000..0ba8388 --- /dev/null +++ b/openssh-10.4p1-CVE-2026-59995.patch @@ -0,0 +1,20 @@ +diff --git a/sftp.c b/sftp.c +index 0ab9206c2..0b57e0833 100644 +--- a/sftp.c ++++ b/sftp.c +@@ -2289,13 +2289,8 @@ interactive_loop(struct sftp_conn *conn, char *file1, char *file2) + return (-1); + } + } else { +- /* XXX this is wrong wrt quoting */ +- snprintf(cmd, sizeof cmd, "get%s %s%s%s", +- global_aflag ? " -a" : "", dir, +- file2 == NULL ? "" : " ", +- file2 == NULL ? "" : file2); +- err = parse_dispatch_command(conn, cmd, +- &remote_path, startdir, 1, 0); ++ err = process_get(conn, dir, file2, remote_path, 0, 0, ++ global_aflag, 0); + free(dir); + free(startdir); + free(remote_path); diff --git a/openssh.spec b/openssh.spec index 1c8f56b..adc8b18 100644 --- a/openssh.spec +++ b/openssh.spec @@ -43,7 +43,7 @@ Summary: An open source implementation of SSH protocol version 2 Name: openssh Version: %{openssh_ver} -Release: 28%{?dist} +Release: 29%{?dist} URL: http://www.openssh.com/portable.html Source0: ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-%{version}.tar.gz Source1: ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-%{version}.tar.gz.asc @@ -259,6 +259,8 @@ Patch1046: openssh-9.9p1-cve-2026-60002.patch # upstream 8b05bbeb293c5f777915e37e9ed43a06fb8e7614 # upstream 5a5e47740b6466d58242aca28b9e584bab4ccf1d Patch1047: openssh-9.9p1-copy-data-ext-self-copy.patch +# upstream 6a57081dc35acf3ee298108d4bc3580489608d5f +Patch1048: openssh-10.4p1-CVE-2026-59995.patch License: BSD-3-Clause AND BSD-2-Clause AND ISC AND SSH-OpenSSH AND ssh-keyscan AND snprintf AND LicenseRef-Fedora-Public-Domain AND X11-distribute-modifications-variant Requires: /sbin/nologin @@ -470,6 +472,7 @@ gpgv2 --quiet --keyring %{SOURCE3} %{SOURCE1} %{SOURCE0} %patch -P 1045 -p1 -b .scp-remote-glob %patch -P 1046 -p1 -b .cve-2026-60002 %patch -P 1047 -p1 -b .copy-data-ext-self-copy +%patch -P 1048 -p1 -b .CVE-2026-59995 %patch -P 100 -p1 -b .coverity @@ -750,6 +753,11 @@ test -f %{sysconfig_anaconda} && \ %attr(0755,root,root) %{_libdir}/sshtest/sk-dummy.so %changelog +* Wed Aug 12 2026 Dmitry Belyavskiy - 9.9p1-29 +- Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded + file location + Resolves: RHEL-236323 + * Thu Jul 16 2026 Zoltan Fridrich - 9.9p1-28 - Fix GSSAPI indicators check ignoring subsequent deny rules if allow rule matched first