- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Nicolas Mora
- Date:
- 2026-09-12 08:07:35 UTC
- Severity:
- normal
- Tags:
[ Reason ] Fix CVEs CVE-2026-66032 CVE-2026-66033 CVE-2026-66034 CVE-2026-66035 CVE-2026-58050 CVE-2026-58051 [ Impact ] Denial of service, heap corruption or information disclosure [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] Backport of the packages 1.11.1-6 and 1.11.1-5 in unstable
Control: tags -1 + confirmed Please go ahead. Regards, Adam
Le 2026-09-04 à 07 h 03, Adam D. Barratt a écrit : Uploaded, thanks /Nicolas
package release.debian.org tags 1145104 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: libssh2 Version: 1.11.1-1+deb13u2 Explanation: fix buffer overflow issues [CVE-2026-58050 CVE-2026-66035 CVE-2026-58051]; fix double free issue [CVE-2026-66032]; fix integer underflow issue [CVE-2026-66033]; fix data leak issue [CVE-2026-66034]
package release.debian.org tags 1145104 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: libssh2 Version: 1.11.1-1+deb13u2 Explanation: fix buffer overflow issues [CVE-2026-58050 CVE-2026-66035 CVE-2026-58051]; fix double free issue [CVE-2026-66032]; fix integer underflow issue [CVE-2026-66033]; fix data leak issue [CVE-2026-66034]
This update was released as part of 13.7.