diff options
| author | Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com> | 2026-05-20 10:29:31 +0200 |
|---|---|---|
| committer | Paul Barker <paul@pbarker.dev> | 2026-06-10 14:35:20 +0100 |
| commit | 473edc73e6268935d4f6cec185553aa1980809ac (patch) | |
| tree | 8fa0bebc01fa1f84ef96337030915711de6b457a /meta | |
| parent | e0f9a13f5fc5e4422a6c9a98e788918d323d85a8 (diff) | |
| download | poky-473edc73e6268935d4f6cec185553aa1980809ac.tar.gz | |
openssh: patch CVE-2026-35387
Backport patch from [1] matching CVE description in [2] and change described
in release note [3].
[1] https://github.com/openssh/openssh-portable/commit/fd1c7e131f331942d20f42f31e79912d570081fa
[2] https://security-tracker.debian.org/tracker/CVE-2026-35387
[3] https://www.openssh.org/releasenotes.html#10.3p1
(From OE-Core rev: c8fb33de27b9e2be5aeaa4178ddc7b6e724f45ee)
Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Reviewed-by: Bruno Vernay <bruno.vernay@se.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta')
| -rw-r--r-- | meta/recipes-connectivity/openssh/openssh/CVE-2026-35387.patch | 205 | ||||
| -rw-r--r-- | meta/recipes-connectivity/openssh/openssh_9.6p1.bb | 1 |
2 files changed, 206 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-35387.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-35387.patch new file mode 100644 index 0000000000..c4806bd993 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-35387.patch | |||
| @@ -0,0 +1,205 @@ | |||
| 1 | From faaf123656513f16994853379c388ad8cc850f8c Mon Sep 17 00:00:00 2001 | ||
| 2 | From: "djm@openbsd.org" <djm@openbsd.org> | ||
| 3 | Date: Thu, 2 Apr 2026 07:48:13 +0000 | ||
| 4 | Subject: [PATCH] upstream: correctly match ECDSA signature algorithms against | ||
| 5 | |||
| 6 | algorithm allowlists: HostKeyAlgorithms, PubkeyAcceptedAlgorithms and | ||
| 7 | HostbasedAcceptedAlgorithms. | ||
| 8 | |||
| 9 | Previously, if any ECDSA type (say "ecdsa-sha2-nistp521") was | ||
| 10 | present in one of these lists, then all ECDSA algorithms would | ||
| 11 | be permitted. | ||
| 12 | |||
| 13 | Reported by Christos Papakonstantinou of Cantina and Spearbit. | ||
| 14 | |||
| 15 | OpenBSD-Commit-ID: c790e2687c35989ae34a00e709be935c55b16a86 | ||
| 16 | |||
| 17 | CVE: CVE-2026-35387 | ||
| 18 | Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/fd1c7e131f331942d20f42f31e79912d570081fa] | ||
| 19 | Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com> | ||
| 20 | --- | ||
| 21 | auth2-hostbased.c | 9 +++++---- | ||
| 22 | auth2-pubkey.c | 9 +++++---- | ||
| 23 | auth2-pubkeyfile.c | 26 +++++++++++++++----------- | ||
| 24 | sshconnect2.c | 28 ++++++++++++++++++---------- | ||
| 25 | 4 files changed, 43 insertions(+), 29 deletions(-) | ||
| 26 | |||
| 27 | diff --git a/auth2-hostbased.c b/auth2-hostbased.c | ||
| 28 | index 06bb464ff..02eeed3f0 100644 | ||
| 29 | --- a/auth2-hostbased.c | ||
| 30 | +++ b/auth2-hostbased.c | ||
| 31 | @@ -1,4 +1,4 @@ | ||
| 32 | -/* $OpenBSD: auth2-hostbased.c,v 1.52 2023/03/05 05:34:09 dtucker Exp $ */ | ||
| 33 | +/* $OpenBSD: auth2-hostbased.c,v 1.57 2026/04/02 07:48:13 djm Exp $ */ | ||
| 34 | /* | ||
| 35 | * Copyright (c) 2000 Markus Friedl. All rights reserved. | ||
| 36 | * | ||
| 37 | @@ -95,9 +95,10 @@ userauth_hostbased(struct ssh *ssh, const char *method) | ||
| 38 | error_f("cannot decode key: %s", pkalg); | ||
| 39 | goto done; | ||
| 40 | } | ||
| 41 | - if (key->type != pktype) { | ||
| 42 | - error_f("type mismatch for decoded key " | ||
| 43 | - "(received %d, expected %d)", key->type, pktype); | ||
| 44 | + if (key->type != pktype || (sshkey_type_plain(pktype) == KEY_ECDSA && | ||
| 45 | + sshkey_ecdsa_nid_from_name(pkalg) != key->ecdsa_nid)) { | ||
| 46 | + error_f("key type mismatch for decoded key " | ||
| 47 | + "(received %s, expected %s)", sshkey_ssh_name(key), pkalg); | ||
| 48 | goto done; | ||
| 49 | } | ||
| 50 | if (match_pattern_list(pkalg, options.hostbased_accepted_algos, 0) != 1) { | ||
| 51 | diff --git a/auth2-pubkey.c b/auth2-pubkey.c | ||
| 52 | index 3f49e1df3..1e07ff74e 100644 | ||
| 53 | --- a/auth2-pubkey.c | ||
| 54 | +++ b/auth2-pubkey.c | ||
| 55 | @@ -1,4 +1,4 @@ | ||
| 56 | -/* $OpenBSD: auth2-pubkey.c,v 1.119 2023/07/27 22:25:17 djm Exp $ */ | ||
| 57 | +/* $OpenBSD: auth2-pubkey.c,v 1.126 2026/04/02 07:48:13 djm Exp $ */ | ||
| 58 | /* | ||
| 59 | * Copyright (c) 2000 Markus Friedl. All rights reserved. | ||
| 60 | * Copyright (c) 2010 Damien Miller. All rights reserved. | ||
| 61 | @@ -148,9 +148,10 @@ userauth_pubkey(struct ssh *ssh, const char *method) | ||
| 62 | error_f("cannot decode key: %s", pkalg); | ||
| 63 | goto done; | ||
| 64 | } | ||
| 65 | - if (key->type != pktype) { | ||
| 66 | - error_f("type mismatch for decoded key " | ||
| 67 | - "(received %d, expected %d)", key->type, pktype); | ||
| 68 | + if (key->type != pktype || (sshkey_type_plain(pktype) == KEY_ECDSA && | ||
| 69 | + sshkey_ecdsa_nid_from_name(pkalg) != key->ecdsa_nid)) { | ||
| 70 | + error_f("key type mismatch for decoded key " | ||
| 71 | + "(received %s, expected %s)", sshkey_ssh_name(key), pkalg); | ||
| 72 | goto done; | ||
| 73 | } | ||
| 74 | if (auth2_key_already_used(authctxt, key)) { | ||
| 75 | diff --git a/auth2-pubkeyfile.c b/auth2-pubkeyfile.c | ||
| 76 | index 31e7481fb..869c8e055 100644 | ||
| 77 | --- a/auth2-pubkeyfile.c | ||
| 78 | +++ b/auth2-pubkeyfile.c | ||
| 79 | @@ -1,4 +1,4 @@ | ||
| 80 | -/* $OpenBSD: auth2-pubkeyfile.c,v 1.4 2023/03/05 05:34:09 dtucker Exp $ */ | ||
| 81 | +/* $OpenBSD: auth2-pubkeyfile.c,v 1.8 2026/04/02 07:48:13 djm Exp $ */ | ||
| 82 | /* | ||
| 83 | * Copyright (c) 2000 Markus Friedl. All rights reserved. | ||
| 84 | * Copyright (c) 2010 Damien Miller. All rights reserved. | ||
| 85 | @@ -50,6 +50,7 @@ | ||
| 86 | #include "authfile.h" | ||
| 87 | #include "match.h" | ||
| 88 | #include "ssherr.h" | ||
| 89 | +#include "xmalloc.h" | ||
| 90 | |||
| 91 | int | ||
| 92 | auth_authorise_keyopts(struct passwd *pw, struct sshauthopt *opts, | ||
| 93 | @@ -146,20 +147,23 @@ auth_authorise_keyopts(struct passwd *pw, struct sshauthopt *opts, | ||
| 94 | static int | ||
| 95 | match_principals_option(const char *principal_list, struct sshkey_cert *cert) | ||
| 96 | { | ||
| 97 | - char *result; | ||
| 98 | + char *list, *olist, *entry; | ||
| 99 | u_int i; | ||
| 100 | |||
| 101 | - /* XXX percent_expand() sequences for authorized_principals? */ | ||
| 102 | - | ||
| 103 | - for (i = 0; i < cert->nprincipals; i++) { | ||
| 104 | - if ((result = match_list(cert->principals[i], | ||
| 105 | - principal_list, NULL)) != NULL) { | ||
| 106 | - debug3("matched principal from key options \"%.100s\"", | ||
| 107 | - result); | ||
| 108 | - free(result); | ||
| 109 | - return 1; | ||
| 110 | + olist = list = xstrdup(principal_list); | ||
| 111 | + for (;;) { | ||
| 112 | + if ((entry = strsep(&list, ",")) == NULL || *entry == '\0') | ||
| 113 | + break; | ||
| 114 | + for (i = 0; i < cert->nprincipals; i++) { | ||
| 115 | + if (strcmp(entry, cert->principals[i]) == 0) { | ||
| 116 | + debug3("matched principal from key i" | ||
| 117 | + "options \"%.100s\"", entry); | ||
| 118 | + free(olist); | ||
| 119 | + return 1; | ||
| 120 | + } | ||
| 121 | } | ||
| 122 | } | ||
| 123 | + free(olist); | ||
| 124 | return 0; | ||
| 125 | } | ||
| 126 | |||
| 127 | diff --git a/sshconnect2.c b/sshconnect2.c | ||
| 128 | index a5f92f04c..a296c9b8c 100644 | ||
| 129 | --- a/sshconnect2.c | ||
| 130 | +++ b/sshconnect2.c | ||
| 131 | @@ -1,4 +1,4 @@ | ||
| 132 | -/* $OpenBSD: sshconnect2.c,v 1.371 2023/12/18 14:45:49 djm Exp $ */ | ||
| 133 | +/* $OpenBSD: sshconnect2.c,v 1.385 2026/04/02 07:48:13 djm Exp $ */ | ||
| 134 | /* | ||
| 135 | * Copyright (c) 2000 Markus Friedl. All rights reserved. | ||
| 136 | * Copyright (c) 2008 Damien Miller. All rights reserved. | ||
| 137 | @@ -91,6 +91,7 @@ extern Options options; | ||
| 138 | static char *xxx_host; | ||
| 139 | static struct sockaddr *xxx_hostaddr; | ||
| 140 | static const struct ssh_conn_info *xxx_conn_info; | ||
| 141 | +static int key_type_allowed(struct sshkey *, const char *); | ||
| 142 | |||
| 143 | static int | ||
| 144 | verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh) | ||
| 145 | @@ -100,6 +101,10 @@ verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh) | ||
| 146 | if ((r = sshkey_check_rsa_length(hostkey, | ||
| 147 | options.required_rsa_size)) != 0) | ||
| 148 | fatal_r(r, "Bad server host key"); | ||
| 149 | + if (!key_type_allowed(hostkey, options.hostkeyalgorithms)) { | ||
| 150 | + fatal("Server host key %s not in HostKeyAlgorithms", | ||
| 151 | + sshkey_ssh_name(hostkey)); | ||
| 152 | + } | ||
| 153 | if (verify_host_key(xxx_host, xxx_hostaddr, hostkey, | ||
| 154 | xxx_conn_info) != 0) | ||
| 155 | fatal("Host key verification failed."); | ||
| 156 | @@ -1608,34 +1613,37 @@ load_identity_file(Identity *id) | ||
| 157 | } | ||
| 158 | |||
| 159 | static int | ||
| 160 | -key_type_allowed_by_config(struct sshkey *key) | ||
| 161 | +key_type_allowed(struct sshkey *key, const char *allowlist) | ||
| 162 | { | ||
| 163 | - if (match_pattern_list(sshkey_ssh_name(key), | ||
| 164 | - options.pubkey_accepted_algos, 0) == 1) | ||
| 165 | + if (match_pattern_list(sshkey_ssh_name(key), allowlist, 0) == 1) | ||
| 166 | return 1; | ||
| 167 | |||
| 168 | /* RSA keys/certs might be allowed by alternate signature types */ | ||
| 169 | switch (key->type) { | ||
| 170 | case KEY_RSA: | ||
| 171 | - if (match_pattern_list("rsa-sha2-512", | ||
| 172 | - options.pubkey_accepted_algos, 0) == 1) | ||
| 173 | + if (match_pattern_list("rsa-sha2-512", allowlist, 0) == 1) | ||
| 174 | return 1; | ||
| 175 | - if (match_pattern_list("rsa-sha2-256", | ||
| 176 | - options.pubkey_accepted_algos, 0) == 1) | ||
| 177 | + if (match_pattern_list("rsa-sha2-256", allowlist, 0) == 1) | ||
| 178 | return 1; | ||
| 179 | break; | ||
| 180 | case KEY_RSA_CERT: | ||
| 181 | if (match_pattern_list("rsa-sha2-512-cert-v01@openssh.com", | ||
| 182 | - options.pubkey_accepted_algos, 0) == 1) | ||
| 183 | + allowlist, 0) == 1) | ||
| 184 | return 1; | ||
| 185 | if (match_pattern_list("rsa-sha2-256-cert-v01@openssh.com", | ||
| 186 | - options.pubkey_accepted_algos, 0) == 1) | ||
| 187 | + allowlist, 0) == 1) | ||
| 188 | return 1; | ||
| 189 | break; | ||
| 190 | } | ||
| 191 | return 0; | ||
| 192 | } | ||
| 193 | |||
| 194 | +static int | ||
| 195 | +key_type_allowed_by_config(struct sshkey *key) | ||
| 196 | +{ | ||
| 197 | + return key_type_allowed(key, options.pubkey_accepted_algos); | ||
| 198 | +} | ||
| 199 | + | ||
| 200 | /* obtain a list of keys from the agent */ | ||
| 201 | static int | ||
| 202 | get_agent_identities(struct ssh *ssh, int *agent_fdp, | ||
| 203 | -- | ||
| 204 | 2.43.0 | ||
| 205 | |||
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index 3a9010a7a4..9267bbd2c9 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb | |||
| @@ -35,6 +35,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar | |||
| 35 | file://CVE-2025-61985.patch \ | 35 | file://CVE-2025-61985.patch \ |
| 36 | file://CVE-2025-61984.patch \ | 36 | file://CVE-2025-61984.patch \ |
| 37 | file://CVE-2026-35385.patch \ | 37 | file://CVE-2026-35385.patch \ |
| 38 | file://CVE-2026-35387.patch \ | ||
| 38 | " | 39 | " |
| 39 | SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" | 40 | SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" |
| 40 | 41 | ||
