diff options
| author | Rajeshkumar Ramasamy <rajeshkumar.ramasamy@windriver.com> | 2025-11-11 12:25:47 +0530 |
|---|---|---|
| committer | Gyorgy Sarvari <skandigraun@gmail.com> | 2025-11-11 08:50:50 +0100 |
| commit | 07ac1890c843b374c27e150f1a2e53ad3db2a8e4 (patch) | |
| tree | e0dc0d5c86ad379eab6c90191b1575d9fdf00972 /meta-python/recipes-devtools/python/python-matplotlib | |
| parent | acd365628a6c277fced03d64e6523769dc2461b9 (diff) | |
| download | meta-openembedded-kirkstone.tar.gz | |
libssh: fix CVE-2025-8277kirkstone
A flaw was found in libssh's handling of key exchange (KEX) processes
when a client repeatedly sends incorrect KEX guesses. The library fails
to free memory during these rekey operations, which can gradually
exhaust system memory. This issue can lead to crashes on the client
side, particularly when using libgcrypt, which impacts application
stability and availability.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-8277
Upstream-patch:
https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=266174a6d36687b65cf90174f06af90b8b27c65f
https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=8e4d67aa9eda455bfad9ac610e54b7a548d0aa08
https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=1c763e29d138db87665e98983f468d2dd0f286c1
Signed-off-by: Rajeshkumar Ramasamy <rajeshkumar.ramasamy@windriver.com>
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python-matplotlib')
0 files changed, 0 insertions, 0 deletions
