summaryrefslogtreecommitdiffstats
path: root/meta
diff options
context:
space:
mode:
authorTheo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>2026-05-20 10:29:31 +0200
committerPaul Barker <paul@pbarker.dev>2026-06-10 14:35:20 +0100
commit473edc73e6268935d4f6cec185553aa1980809ac (patch)
tree8fa0bebc01fa1f84ef96337030915711de6b457a /meta
parente0f9a13f5fc5e4422a6c9a98e788918d323d85a8 (diff)
downloadpoky-473edc73e6268935d4f6cec185553aa1980809ac.tar.gz
openssh: patch CVE-2026-35387
Backport patch from [1] matching CVE description in [2] and change described in release note [3]. [1] https://github.com/openssh/openssh-portable/commit/fd1c7e131f331942d20f42f31e79912d570081fa [2] https://security-tracker.debian.org/tracker/CVE-2026-35387 [3] https://www.openssh.org/releasenotes.html#10.3p1 (From OE-Core rev: c8fb33de27b9e2be5aeaa4178ddc7b6e724f45ee) Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com> Reviewed-by: Bruno Vernay <bruno.vernay@se.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta')
-rw-r--r--meta/recipes-connectivity/openssh/openssh/CVE-2026-35387.patch205
-rw-r--r--meta/recipes-connectivity/openssh/openssh_9.6p1.bb1
2 files changed, 206 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-35387.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-35387.patch
new file mode 100644
index 0000000000..c4806bd993
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-35387.patch
@@ -0,0 +1,205 @@
1From faaf123656513f16994853379c388ad8cc850f8c Mon Sep 17 00:00:00 2001
2From: "djm@openbsd.org" <djm@openbsd.org>
3Date: Thu, 2 Apr 2026 07:48:13 +0000
4Subject: [PATCH] upstream: correctly match ECDSA signature algorithms against
5
6algorithm allowlists: HostKeyAlgorithms, PubkeyAcceptedAlgorithms and
7HostbasedAcceptedAlgorithms.
8
9Previously, if any ECDSA type (say "ecdsa-sha2-nistp521") was
10present in one of these lists, then all ECDSA algorithms would
11be permitted.
12
13Reported by Christos Papakonstantinou of Cantina and Spearbit.
14
15OpenBSD-Commit-ID: c790e2687c35989ae34a00e709be935c55b16a86
16
17CVE: CVE-2026-35387
18Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/fd1c7e131f331942d20f42f31e79912d570081fa]
19Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
20---
21 auth2-hostbased.c | 9 +++++----
22 auth2-pubkey.c | 9 +++++----
23 auth2-pubkeyfile.c | 26 +++++++++++++++-----------
24 sshconnect2.c | 28 ++++++++++++++++++----------
25 4 files changed, 43 insertions(+), 29 deletions(-)
26
27diff --git a/auth2-hostbased.c b/auth2-hostbased.c
28index 06bb464ff..02eeed3f0 100644
29--- a/auth2-hostbased.c
30+++ b/auth2-hostbased.c
31@@ -1,4 +1,4 @@
32-/* $OpenBSD: auth2-hostbased.c,v 1.52 2023/03/05 05:34:09 dtucker Exp $ */
33+/* $OpenBSD: auth2-hostbased.c,v 1.57 2026/04/02 07:48:13 djm Exp $ */
34 /*
35 * Copyright (c) 2000 Markus Friedl. All rights reserved.
36 *
37@@ -95,9 +95,10 @@ userauth_hostbased(struct ssh *ssh, const char *method)
38 error_f("cannot decode key: %s", pkalg);
39 goto done;
40 }
41- if (key->type != pktype) {
42- error_f("type mismatch for decoded key "
43- "(received %d, expected %d)", key->type, pktype);
44+ if (key->type != pktype || (sshkey_type_plain(pktype) == KEY_ECDSA &&
45+ sshkey_ecdsa_nid_from_name(pkalg) != key->ecdsa_nid)) {
46+ error_f("key type mismatch for decoded key "
47+ "(received %s, expected %s)", sshkey_ssh_name(key), pkalg);
48 goto done;
49 }
50 if (match_pattern_list(pkalg, options.hostbased_accepted_algos, 0) != 1) {
51diff --git a/auth2-pubkey.c b/auth2-pubkey.c
52index 3f49e1df3..1e07ff74e 100644
53--- a/auth2-pubkey.c
54+++ b/auth2-pubkey.c
55@@ -1,4 +1,4 @@
56-/* $OpenBSD: auth2-pubkey.c,v 1.119 2023/07/27 22:25:17 djm Exp $ */
57+/* $OpenBSD: auth2-pubkey.c,v 1.126 2026/04/02 07:48:13 djm Exp $ */
58 /*
59 * Copyright (c) 2000 Markus Friedl. All rights reserved.
60 * Copyright (c) 2010 Damien Miller. All rights reserved.
61@@ -148,9 +148,10 @@ userauth_pubkey(struct ssh *ssh, const char *method)
62 error_f("cannot decode key: %s", pkalg);
63 goto done;
64 }
65- if (key->type != pktype) {
66- error_f("type mismatch for decoded key "
67- "(received %d, expected %d)", key->type, pktype);
68+ if (key->type != pktype || (sshkey_type_plain(pktype) == KEY_ECDSA &&
69+ sshkey_ecdsa_nid_from_name(pkalg) != key->ecdsa_nid)) {
70+ error_f("key type mismatch for decoded key "
71+ "(received %s, expected %s)", sshkey_ssh_name(key), pkalg);
72 goto done;
73 }
74 if (auth2_key_already_used(authctxt, key)) {
75diff --git a/auth2-pubkeyfile.c b/auth2-pubkeyfile.c
76index 31e7481fb..869c8e055 100644
77--- a/auth2-pubkeyfile.c
78+++ b/auth2-pubkeyfile.c
79@@ -1,4 +1,4 @@
80-/* $OpenBSD: auth2-pubkeyfile.c,v 1.4 2023/03/05 05:34:09 dtucker Exp $ */
81+/* $OpenBSD: auth2-pubkeyfile.c,v 1.8 2026/04/02 07:48:13 djm Exp $ */
82 /*
83 * Copyright (c) 2000 Markus Friedl. All rights reserved.
84 * Copyright (c) 2010 Damien Miller. All rights reserved.
85@@ -50,6 +50,7 @@
86 #include "authfile.h"
87 #include "match.h"
88 #include "ssherr.h"
89+#include "xmalloc.h"
90
91 int
92 auth_authorise_keyopts(struct passwd *pw, struct sshauthopt *opts,
93@@ -146,20 +147,23 @@ auth_authorise_keyopts(struct passwd *pw, struct sshauthopt *opts,
94 static int
95 match_principals_option(const char *principal_list, struct sshkey_cert *cert)
96 {
97- char *result;
98+ char *list, *olist, *entry;
99 u_int i;
100
101- /* XXX percent_expand() sequences for authorized_principals? */
102-
103- for (i = 0; i < cert->nprincipals; i++) {
104- if ((result = match_list(cert->principals[i],
105- principal_list, NULL)) != NULL) {
106- debug3("matched principal from key options \"%.100s\"",
107- result);
108- free(result);
109- return 1;
110+ olist = list = xstrdup(principal_list);
111+ for (;;) {
112+ if ((entry = strsep(&list, ",")) == NULL || *entry == '\0')
113+ break;
114+ for (i = 0; i < cert->nprincipals; i++) {
115+ if (strcmp(entry, cert->principals[i]) == 0) {
116+ debug3("matched principal from key i"
117+ "options \"%.100s\"", entry);
118+ free(olist);
119+ return 1;
120+ }
121 }
122 }
123+ free(olist);
124 return 0;
125 }
126
127diff --git a/sshconnect2.c b/sshconnect2.c
128index a5f92f04c..a296c9b8c 100644
129--- a/sshconnect2.c
130+++ b/sshconnect2.c
131@@ -1,4 +1,4 @@
132-/* $OpenBSD: sshconnect2.c,v 1.371 2023/12/18 14:45:49 djm Exp $ */
133+/* $OpenBSD: sshconnect2.c,v 1.385 2026/04/02 07:48:13 djm Exp $ */
134 /*
135 * Copyright (c) 2000 Markus Friedl. All rights reserved.
136 * Copyright (c) 2008 Damien Miller. All rights reserved.
137@@ -91,6 +91,7 @@ extern Options options;
138 static char *xxx_host;
139 static struct sockaddr *xxx_hostaddr;
140 static const struct ssh_conn_info *xxx_conn_info;
141+static int key_type_allowed(struct sshkey *, const char *);
142
143 static int
144 verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh)
145@@ -100,6 +101,10 @@ verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh)
146 if ((r = sshkey_check_rsa_length(hostkey,
147 options.required_rsa_size)) != 0)
148 fatal_r(r, "Bad server host key");
149+ if (!key_type_allowed(hostkey, options.hostkeyalgorithms)) {
150+ fatal("Server host key %s not in HostKeyAlgorithms",
151+ sshkey_ssh_name(hostkey));
152+ }
153 if (verify_host_key(xxx_host, xxx_hostaddr, hostkey,
154 xxx_conn_info) != 0)
155 fatal("Host key verification failed.");
156@@ -1608,34 +1613,37 @@ load_identity_file(Identity *id)
157 }
158
159 static int
160-key_type_allowed_by_config(struct sshkey *key)
161+key_type_allowed(struct sshkey *key, const char *allowlist)
162 {
163- if (match_pattern_list(sshkey_ssh_name(key),
164- options.pubkey_accepted_algos, 0) == 1)
165+ if (match_pattern_list(sshkey_ssh_name(key), allowlist, 0) == 1)
166 return 1;
167
168 /* RSA keys/certs might be allowed by alternate signature types */
169 switch (key->type) {
170 case KEY_RSA:
171- if (match_pattern_list("rsa-sha2-512",
172- options.pubkey_accepted_algos, 0) == 1)
173+ if (match_pattern_list("rsa-sha2-512", allowlist, 0) == 1)
174 return 1;
175- if (match_pattern_list("rsa-sha2-256",
176- options.pubkey_accepted_algos, 0) == 1)
177+ if (match_pattern_list("rsa-sha2-256", allowlist, 0) == 1)
178 return 1;
179 break;
180 case KEY_RSA_CERT:
181 if (match_pattern_list("rsa-sha2-512-cert-v01@openssh.com",
182- options.pubkey_accepted_algos, 0) == 1)
183+ allowlist, 0) == 1)
184 return 1;
185 if (match_pattern_list("rsa-sha2-256-cert-v01@openssh.com",
186- options.pubkey_accepted_algos, 0) == 1)
187+ allowlist, 0) == 1)
188 return 1;
189 break;
190 }
191 return 0;
192 }
193
194+static int
195+key_type_allowed_by_config(struct sshkey *key)
196+{
197+ return key_type_allowed(key, options.pubkey_accepted_algos);
198+}
199+
200 /* obtain a list of keys from the agent */
201 static int
202 get_agent_identities(struct ssh *ssh, int *agent_fdp,
203--
2042.43.0
205
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 3a9010a7a4..9267bbd2c9 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -35,6 +35,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
35 file://CVE-2025-61985.patch \ 35 file://CVE-2025-61985.patch \
36 file://CVE-2025-61984.patch \ 36 file://CVE-2025-61984.patch \
37 file://CVE-2026-35385.patch \ 37 file://CVE-2026-35385.patch \
38 file://CVE-2026-35387.patch \
38 " 39 "
39SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" 40SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
40 41