Debian Patches

Status for dropbear/2022.83-1+deb12u3

Patch Description Author Forwarded Bugs Origin Last update
fix-noremotetcp-behavior.patch src: svr-tcpfwd: Fix noremotetcp behavior
If noremotetcp is set, we should still reply with
send_msg_request_failed. This matches the behavior
of !DROPBEAR_SVR_REMOTETCPFWD.

We were seeing keepalive packets being ignored when
the "-k" option was used.
Justin Chen <justin.chen@broadcom.com> no debian https://github.com/mkj/dropbear/commit/3cf8344769eda55e26eee53c1898b2c66544f188 2023-09-08
Handle-arbitrary-length-paths-and-commands-in-multihop_pa.patch Handle arbitrary length paths and commands in multihop_passthrough_args() Matt Johnston <matt@ucc.asn.au> no https://github.com/mkj/dropbear/commit/d59436a4d56de58b856142a5d489a4a8fc7382ed 2024-04-01
CVE-2025-47203.patch Execute multihop commands directly, no shell
This avoids problems with shell escaping if arguments contain special
characters.
Matt Johnston <matt@ucc.asn.au> no https://github.com/mkj/dropbear/commit/e5a0ef27c227f7ae69d9a9fec98a056494409b9b 2025-05-05
fix-FTBFS-on-hurd-i386.patch Fix FTBFS on hurd-i386.
GNU Hurd defines neither IOV_MAX nor UIO_MAXIOV.
Guilhem Moulin <guilhem@debian.org> yes 2022-04-03
support-running-test_aslr-without-venv.patch Support running test_aslr without venv.
Without this patch the test fails because the remote shell can't parse
the command:

$ ; echo nay
bash: syntax error near unexpected token `;'
Guilhem Moulin <guilhem@debian.org> yes 2022-04-01
raise-connection-delay-in-tests.patch Raise connection delay in tests.
0.1s delay is too short on slower hardware such as the armhf debci
runners (or armhf porterboxes). Ideally the test would wait for the
listener to actually be available instead of doing guess work, but
raising the delay should be good enough for now.
Guilhem Moulin <guilhem@debian.org> no 2022-04-03
CVE-2023-48795.patch Implement Strict KEX mode
As specified by OpenSSH with kex-strict-c-v00@openssh.com and
kex-strict-s-v00@openssh.com.
Matt Johnston <matt@ucc.asn.au> no debian https://github.com/mkj/dropbear/commit/6e43be5c7b99dbee49dc72b6f989f29fdd7e9356 2023-11-20

All known versions for source package 'dropbear'

Links