Debian Patches

Status for libssh2/1.10.0-3+deb12u1

Patch Description Author Forwarded Bugs Origin Last update
ssh2-sh.patch Fix ssh2 test Nicolas Mora <babelouest@debian.org> not-needed
manpage.patch Fix typo Nicolas Mora <babelouest@debian.org> not-needed
0001-Add-lgpg-error-to-.pc-to-facilitate-static-linking.patch Add -lgpg-error to .pc to facilitate static linking
Note that this patch is Debian-specific as we know that libssh2 is linked
to gcrypt.

Patching configure.ac to add gpg-error as a dependent library is not good, as it
would cause overlinking of libssh2, and there is no separate variable for
"static dependencies".

All this mess ought to be solved in gcrypt inself by providing .pc file,
but it is not.
Mikhail Gusarov <dottedmag@dottedmag.net> no 2014-09-03
0001-Do-not-expose-private-libraries-nor-link-flags-to-us.patch Do not expose private libraries nor link flags to users of libssh2

Reported in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747417
Mikhail Gusarov <dottedmag@dottedmag.net> no 2014-05-19
0005-Update-sftp_symlink-to-avoid-out-of-bounds-read-on-m.patch Update sftp_symlink to avoid out of bounds read on malformed packet #1705 (#1717)

Use buffer struct to guard against out of bounds reads and invalid packets.

Discovery Credit:
Joshua Rogers
Will Cosgrove <will@panic.com> no backport, https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d 2025-10-10
0006-userauth.c-username_len-bounds-checking-1858.patch userauth.c: username_len bounds checking (#1858)
Return errors when username_len will exceed bounds, fix existing bounds
check.

Credit:
[dapickle](https://github.com/dapickle)
Will Cosgrove <will@panic.com> no backport, https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1 2026-04-13
0007-publickey-fix-potential-multiplication-overflow-in-3.patch publickey: fix potential multiplication overflow in 32-bit `libssh2_publickey_list_fetch()`

Cap list size at 1024 elements.


Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9

Closes #2128
Viktor Szakats <commit@vsz.me> no backport, https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12 2026-06-28
0008-publickey-fix-potential-arbitrary-free-in-libssh2_pu.patch publickey: fix potential arbitrary free in `libssh2_publickey_list_fetch()` (#2127)

Due to uninitialized list entry.


Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9
Viktor Szakats <vszakats@users.noreply.github.com> no https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a 2026-06-29
0009-Prevent-dangling-pointer-by-nullifying-data-2180.patch Prevent dangling pointer by nullifying data (#2180)
Set data to NULL after freeing it to avoid dangling pointer. fixes
GHSA-px3w-7g75-hg7w.
Will Cosgrove <will@panic.com> no backport, https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0 2026-07-02
0010-publickey-fix-potential-OOB-read-in-libssh2_publicke.patch publickey: fix potential OOB read in `libssh2_publickey_list_fetch()`

Fixes GHSA-w6g9-cpfp-22gc

Closes #2202
Viktor Szakats <commit@vsz.me> no backport, https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9 2026-07-04

All known versions for source package 'libssh2'

Links