summaryrefslogtreecommitdiffstats
path: root/meta
diff options
context:
space:
mode:
Diffstat (limited to 'meta')
-rw-r--r--meta/recipes-connectivity/openssh/openssh/CVE-2024-39894.patch35
-rw-r--r--meta/recipes-connectivity/openssh/openssh_9.6p1.bb1
2 files changed, 36 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2024-39894.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2024-39894.patch
new file mode 100644
index 0000000000..898295340d
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2024-39894.patch
@@ -0,0 +1,35 @@
1From 146c420d29d055cc75c8606327a1cf8439fe3a08 Mon Sep 17 00:00:00 2001
2From: "djm@openbsd.org" <djm@openbsd.org>
3Date: Mon, 1 Jul 2024 04:31:17 +0000
4Subject: [PATCH] upstream: when sending ObscureKeystrokeTiming chaff packets,
5 we
6
7can't rely on channel_did_enqueue to tell that there is data to send. This
8flag indicates that the channels code enqueued a packet on _this_ ppoll()
9iteration, not that data was enqueued in _any_ ppoll() iteration in the
10timeslice. ok markus@
11
12OpenBSD-Commit-ID: 009b74fd2769b36b5284a0188ade182f00564136
13
14Upstream-Status: Backport [import from ubuntu https://git.launchpad.net/ubuntu/+source/openssh/tree/debian/patches/CVE-2024-39894.patch?h=ubuntu/noble-security
15Upstream commit https://github.com/openssh/openssh-portable/commit/146c420d29d055cc75c8606327a1cf8439fe3a08]
16CVE: CVE-2024-39894
17Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
18---
19 clientloop.c | 7 ++++---
20 1 file changed, 4 insertions(+), 3 deletions(-)
21
22--- a/clientloop.c
23+++ b/clientloop.c
24@@ -612,8 +612,9 @@ obfuscate_keystroke_timing(struct ssh *s
25 if (timespeccmp(&now, &chaff_until, >=)) {
26 /* Stop if there have been no keystrokes for a while */
27 stop_reason = "chaff time expired";
28- } else if (timespeccmp(&now, &next_interval, >=)) {
29- /* Otherwise if we were due to send, then send chaff */
30+ } else if (timespeccmp(&now, &next_interval, >=) &&
31+ !ssh_packet_have_data_to_write(ssh)) {
32+ /* If due to send but have no data, then send chaff */
33 if (send_chaff(ssh))
34 nchaff++;
35 }
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 3cdf0327b0..8bc4f4269a 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -28,6 +28,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
28 file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ 28 file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \
29 file://0001-systemd-Add-optional-support-for-systemd-sd_notify.patch \ 29 file://0001-systemd-Add-optional-support-for-systemd-sd_notify.patch \
30 file://CVE-2024-6387.patch \ 30 file://CVE-2024-6387.patch \
31 file://CVE-2024-39894.patch \
31 " 32 "
32SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" 33SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
33 34