summaryrefslogtreecommitdiffstats
path: root/meta-python/classes
diff options
context:
space:
mode:
authorRajeshkumar Ramasamy <rajeshkumar.ramasamy@windriver.com>2025-11-11 12:25:47 +0530
committerGyorgy Sarvari <skandigraun@gmail.com>2025-11-11 08:50:50 +0100
commit07ac1890c843b374c27e150f1a2e53ad3db2a8e4 (patch)
treee0dc0d5c86ad379eab6c90191b1575d9fdf00972 /meta-python/classes
parentacd365628a6c277fced03d64e6523769dc2461b9 (diff)
downloadmeta-openembedded-kirkstone.tar.gz
libssh: fix CVE-2025-8277kirkstone
A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-8277 Upstream-patch: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=266174a6d36687b65cf90174f06af90b8b27c65f https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=8e4d67aa9eda455bfad9ac610e54b7a548d0aa08 https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=1c763e29d138db87665e98983f468d2dd0f286c1 Signed-off-by: Rajeshkumar Ramasamy <rajeshkumar.ramasamy@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Diffstat (limited to 'meta-python/classes')
0 files changed, 0 insertions, 0 deletions