From mboxrd@z Thu Jan 1 00:00:00 1970 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 From: Paul Howarth To: git-commits@fedoraproject.org Subject: [rpms/libssh2] rawhide: Address CVE-2025-15661 Date: Thu, 25 Jun 2026 12:25:36 GMT Message-ID: <178239033627.1.9828129653214860983.rpms-libssh2-13fb9aee68b7@fedoraproject.org> List-ID: X-Git-Repo: rpms/libssh2 X-Git-Branch: rawhide X-Git-Rev: 13fb9aee68b781a29ad5ae4e7a825a0eab20c355 ICAgICAgICAgICAgQSBuZXcgY29tbWl0IGhhcyBiZWVuIHB1c2hlZC4KCiAgICAgICAgICAgIFJl cG8gICA6IHJwbXMvbGlic3NoMgogICAgICAgICAgICBCcmFuY2ggOiByYXdoaWRlCiAgICAgICAg ICAgIENvbW1pdCA6IDEzZmI5YWVlNjhiNzgxYTI5YWQ1YWU0ZTdhODI1YTBlYWIyMGMzNTUKICAg ICAgICAgICAgQXV0aG9yIDogUGF1bCBIb3dhcnRoIDxwYXVsQGNpdHktZmFuLm9yZz4KICAgICAg ICAgICAgRGF0ZSAgIDogMjAyNi0wNi0yNVQxMzowOTo1MCswMTowMAogICAgICAgICAgICBTdGF0 cyAgOiArMTUxLy0xIGluIDIgZmlsZShzKQogICAgICAgICAgICBVUkwgICAgOiBodHRwczovL3Ny Yy5mZWRvcmFwcm9qZWN0Lm9yZy9ycG1zL2xpYnNzaDIvYy8xM2ZiOWFlZTY4Yjc4MWEyOWFkNWFl NGU3YTgyNWEwZWFiMjBjMzU1P2JyYW5jaD1yYXdoaWRlCgogICAgICAgICAgICBMb2c6CiAgICAg ICAgICAgIEFkZHJlc3MgQ1ZFLTIwMjUtMTU2NjEKCkluZm9ybWF0aW9uIGRpc2Nsb3N1cmUgYW5k IGRlbmlhbCBvZiBzZXJ2aWNlIHZpYSBjcmFmdGVkIFNGVFAgcmVzcG9uc2UKLSBodHRwczovL2dp dGh1Yi5jb20vbGlic3NoMi9saWJzc2gyL3B1bGwvMTcwNQotIGh0dHBzOi8vZ2l0aHViLmNvbS9s aWJzc2gyL2xpYnNzaDIvcHVsbC8xNzE3CgotLS0KZGlmZiAtLWdpdCBhLzJkYWUzMDItbGlic3No Mi0xLjExLjEucGF0Y2ggYi8yZGFlMzAyLWxpYnNzaDItMS4xMS4xLnBhdGNoCm5ldyBmaWxlIG1v ZGUgMTAwNjQ0CmluZGV4IDAwMDAwMDAuLjdiYTA3NzQKLS0tIC9kZXYvbnVsbAorKysgYi8yZGFl MzAyLWxpYnNzaDItMS4xMS4xLnBhdGNoCkBAIC0wLDAgKzEsMTM4IEBACitGcm9tIDJkYWUzMDI0 ODk3ZTE4OThkMzg5ODM1MTUxZjRlOTYwNjIyNzcyMWQgTW9uIFNlcCAxNyAwMDowMDowMCAyMDAx CitGcm9tOiBXaWxsIENvc2dyb3ZlIDx3aWxsQHBhbmljLmNvbT4KK0RhdGU6IEZyaSwgMTAgT2N0 IDIwMjUgMDg6MjY6MjAgLTA3MDAKK1N1YmplY3Q6IFtQQVRDSF0gVXBkYXRlIHNmdHBfc3ltbGlu ayB0byBhdm9pZCBvdXQgb2YgYm91bmRzIHJlYWQgb24gbWFsZm9ybWVkCisgcGFja2V0ICMxNzA1 ICgjMTcxNykKKworVXNlIGJ1ZmZlciBzdHJ1Y3QgdG8gZ3VhcmQgYWdhaW5zdCBvdXQgb2YgYm91 bmRzIHJlYWRzIGFuZCBpbnZhbGlkIHBhY2tldHMuCisKK0Rpc2NvdmVyeSBDcmVkaXQ6CitKb3No dWEgUm9nZXJzCistLS0KKyBzcmMvc2Z0cC5jIHwgNjYgKysrKysrKysrKysrKysrKysrKysrKysr KysrKysrKysrKysrKystLS0tLS0tLS0tLS0tLS0tCisgMSBmaWxlIGNoYW5nZWQsIDQ3IGluc2Vy dGlvbnMoKyksIDE5IGRlbGV0aW9ucygtKQorCitkaWZmIC0tZ2l0IGEvc3JjL3NmdHAuYyBiL3Ny Yy9zZnRwLmMKK2luZGV4IDcyYjAwN2Y2ZWIuLjcwZDc2ODZkYWYgMTAwNjQ0CistLS0gYS9zcmMv c2Z0cC5jCisrKysgYi9zcmMvc2Z0cC5jCitAQCAtMzc5NSwxNSArMzc5NSwxOSBAQCBzdGF0aWMg aW50IHNmdHBfc3ltbGluayhMSUJTU0gyX1NGVFAgKnNmdHAsIGNvbnN0IGNoYXIgKnBhdGgsCisg eworICAgICBMSUJTU0gyX0NIQU5ORUwgKmNoYW5uZWwgPSBzZnRwLT5jaGFubmVsOworICAgICBM SUJTU0gyX1NFU1NJT04gKnNlc3Npb24gPSBjaGFubmVsLT5zZXNzaW9uOworLSAgICBzaXplX3Qg ZGF0YV9sZW4gPSAwLCBsaW5rX2xlbjsKKysgICAgc2l6ZV90IGRhdGFfbGVuID0gMCwgbGtfbGVu OworICAgICAvKiAxMyA9IHBhY2tldF9sZW4oNCkgKyBwYWNrZXRfdHlwZSgxKSArIHJlcXVlc3Rf aWQoNCkgKyBwYXRoX2xlbig0KSAqLworICAgICBzc2l6ZV90IHBhY2tldF9sZW4gPQorICAgICAg ICAgcGF0aF9sZW4gKyAxMyArCisgICAgICAgICAoKGxpbmtfdHlwZSA9PSBMSUJTU0gyX1NGVFBf U1lNTElOSykgPyAoNCArIHRhcmdldF9sZW4pIDogMCk7CisgICAgIHVuc2lnbmVkIGNoYXIgKnMs ICpkYXRhID0gTlVMTDsKKysgICAgc3RydWN0IHN0cmluZ19idWYgYnVmOworICAgICBzdGF0aWMg Y29uc3QgdW5zaWduZWQgY2hhciBsaW5rX3Jlc3BvbnNlc1syXSA9CisgICAgICAgICB7IFNTSF9G WFBfTkFNRSwgU1NIX0ZYUF9TVEFUVVMgfTsKKyAgICAgaW50IHJldGNvZGU7CisrICAgIHVuc2ln bmVkIGNoYXIgcGFja2V0X3R5cGU7CisrICAgIHVpbnQzMl90IHRtcF91MzI7CisrICAgIHVuc2ln bmVkIGNoYXIgKmxrX3RhcmdldDsKKyAKKyAgICAgaWYoc2Z0cC0+c3ltbGlua19zdGF0ZSA9PSBs aWJzc2gyX05CX3N0YXRlX2lkbGUpIHsKKyAgICAgICAgIHNmdHAtPmxhc3RfZXJybm8gPSBMSUJT U0gyX0ZYX09LOworQEAgLTM4OTEsOCArMzg5NSwyNSBAQCBzdGF0aWMgaW50IHNmdHBfc3ltbGlu ayhMSUJTU0gyX1NGVFAgKnNmdHAsIGNvbnN0IGNoYXIgKnBhdGgsCisgCisgICAgIHNmdHAtPnN5 bWxpbmtfc3RhdGUgPSBsaWJzc2gyX05CX3N0YXRlX2lkbGU7CisgCistICAgIGlmKGRhdGFbMF0g PT0gU1NIX0ZYUF9TVEFUVVMpIHsKKy0gICAgICAgIHJldGNvZGUgPSBfbGlic3NoMl9udG9odTMy KGRhdGEgKyA1KTsKKysgICAgYnVmLmRhdGEgPSAodW5zaWduZWQgY2hhciAqKVNTSDJfVU5DT05T VChkYXRhKTsKKysgICAgYnVmLmRhdGFwdHIgPSBidWYuZGF0YTsKKysgICAgYnVmLmxlbiA9IGRh dGFfbGVuOworKworKyAgICBpZihfbGlic3NoMl9nZXRfYnl0ZSgmYnVmLCAmcGFja2V0X3R5cGUp KSB7CisrICAgICAgICBMSUJTU0gyX0ZSRUUoc2Vzc2lvbiwgZGF0YSk7CisrICAgICAgICByZXR1 cm4gX2xpYnNzaDJfZXJyb3Ioc2Vzc2lvbiwgTElCU1NIMl9FUlJPUl9TRlRQX1BST1RPQ09MLAor KyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICJTRlRQIFByb3RvY29sIEVycm9yICh0eXBl KSIpOworKyAgICB9CisrCisrICAgIGlmKHBhY2tldF90eXBlID09IFNTSF9GWFBfU1RBVFVTKSB7 CisrICAgICAgICBpZihfbGlic3NoMl9nZXRfdTMyKCZidWYsICZ0bXBfdTMyKSkgeworKyAgICAg ICAgICAgIExJQlNTSDJfRlJFRShzZXNzaW9uLCBkYXRhKTsKKysgICAgICAgICAgICByZXR1cm4g X2xpYnNzaDJfZXJyb3Ioc2Vzc2lvbiwgTElCU1NIMl9FUlJPUl9TRlRQX1BST1RPQ09MLAorKyAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAiU0ZUUCBQcm90b2NvbCBFcnJvciAoY29k ZSkiKTsKKysgICAgICAgIH0KKysKKysgICAgICAgIHJldGNvZGUgPSAoaW50KXRtcF91MzI7Cisr CisgICAgICAgICBMSUJTU0gyX0ZSRUUoc2Vzc2lvbiwgZGF0YSk7CisgICAgICAgICBpZihyZXRj b2RlID09IExJQlNTSDJfRlhfT0spCisgICAgICAgICAgICAgcmV0dXJuIExJQlNTSDJfRVJST1Jf Tk9ORTsKK0BAIC0zOTAzLDMwICszOTI0LDM3IEBAIHN0YXRpYyBpbnQgc2Z0cF9zeW1saW5rKExJ QlNTSDJfU0ZUUCAqc2Z0cCwgY29uc3QgY2hhciAqcGF0aCwKKyAgICAgICAgIH0KKyAgICAgfQor IAorLSAgICBpZihfbGlic3NoMl9udG9odTMyKGRhdGEgKyA1KSA8IDEpIHsKKysgICAgLyogYWR2 YW5jZSBwYXN0IGlkICovCisrICAgIGlmKF9saWJzc2gyX2dldF91MzIoJmJ1ZiwgJnRtcF91MzIp KSB7CisgICAgICAgICBMSUJTU0gyX0ZSRUUoc2Vzc2lvbiwgZGF0YSk7CisgICAgICAgICByZXR1 cm4gX2xpYnNzaDJfZXJyb3Ioc2Vzc2lvbiwgTElCU1NIMl9FUlJPUl9TRlRQX1BST1RPQ09MLAor LSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICJJbnZhbGlkIFJFQURMSU5LL1JFQUxQQVRI IHJlc3BvbnNlLCAiCistICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIm5vIG5hbWUgZW50 cmllcyIpOworKyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICJTRlRQIFByb3RvY29sIEVy cm9yIChpZCkiKTsKKyAgICAgfQorIAorLSAgICBpZihkYXRhX2xlbiA8IDEzKSB7CistICAgICAg ICBpZihkYXRhX2xlbiA+IDApIHsKKy0gICAgICAgICAgICBMSUJTU0gyX0ZSRUUoc2Vzc2lvbiwg ZGF0YSk7CistICAgICAgICB9CisrICAgIC8qIGxvb2sgZm9yIGF0IGxlYXN0IG9uZSBsaW5rICov CisrICAgIGlmKF9saWJzc2gyX2dldF91MzIoJmJ1ZiwgJnRtcF91MzIpIHx8IHRtcF91MzIgPCAx KSB7CisrICAgICAgICBMSUJTU0gyX0ZSRUUoc2Vzc2lvbiwgZGF0YSk7CisgICAgICAgICByZXR1 cm4gX2xpYnNzaDJfZXJyb3Ioc2Vzc2lvbiwgTElCU1NIMl9FUlJPUl9TRlRQX1BST1RPQ09MLAor LSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICJTRlRQIHN0YXQgcGFja2V0IHRvbyBzaG9y dCIpOworKyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAiSW52YWxpZCBSRUFE TElOSy9SRUFMUEFUSCByZXNwb25zZSwgIgorKyAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAibm8gbmFtZSBlbnRyaWVzIik7CisgICAgIH0KKyAKKy0gICAgLyogdGhpcyByZWFk cyBhIHUzMiBhbmQgc3RvcmVzIGl0IGludG8gYSBzaWduZWQgMzJiaXQgdmFsdWUgKi8KKy0gICAg bGlua19sZW4gPSBfbGlic3NoMl9udG9odTMyKGRhdGEgKyA5KTsKKy0gICAgaWYobGlua19sZW4g PCB0YXJnZXRfbGVuKSB7CistICAgICAgICBtZW1jcHkodGFyZ2V0LCBkYXRhICsgMTMsIGxpbmtf bGVuKTsKKy0gICAgICAgIHRhcmdldFtsaW5rX2xlbl0gPSAwOworLSAgICAgICAgcmV0Y29kZSA9 IChpbnQpbGlua19sZW47CisrICAgIGlmKF9saWJzc2gyX2dldF9zdHJpbmcoJmJ1ZiwgJmxrX3Rh cmdldCwgJmxrX2xlbikgPT0gTElCU1NIMl9FUlJPUl9OT05FKSB7CisrICAgICAgICBpZihsa19s ZW4gPCB0YXJnZXRfbGVuKSB7CisrICAgICAgICAgICAgbWVtY3B5KHRhcmdldCwgbGtfdGFyZ2V0 LCBsa19sZW4pOworKyAgICAgICAgICAgIHRhcmdldFtsa19sZW5dID0gJ1wwJzsKKysgICAgICAg ICAgICByZXRjb2RlID0gKGludClsa19sZW47CisrICAgICAgICB9CisrICAgICAgICBlbHNlIHsK KysgICAgICAgICAgICByZXRjb2RlID0gTElCU1NIMl9FUlJPUl9CVUZGRVJfVE9PX1NNQUxMOwor KyAgICAgICAgfQorICAgICB9CistICAgIGVsc2UKKy0gICAgICAgIHJldGNvZGUgPSBMSUJTU0gy X0VSUk9SX0JVRkZFUl9UT09fU01BTEw7CisrICAgIGVsc2UgeworKyAgICAgICAgTElCU1NIMl9G UkVFKHNlc3Npb24sIGRhdGEpOworKyAgICAgICAgcmV0dXJuIF9saWJzc2gyX2Vycm9yKHNlc3Np b24sIExJQlNTSDJfRVJST1JfU0ZUUF9QUk9UT0NPTCwKKysgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAiU0ZUUCBQcm90b2NvbCBFcnJvciAoZmlsZW5hbWUpIik7CisrICAgIH0KKysKKyAg ICAgTElCU1NIMl9GUkVFKHNlc3Npb24sIGRhdGEpOworIAorICAgICByZXR1cm4gcmV0Y29kZTsK Ky0tLSBhL3NyYy9saWJzc2gyX3ByaXYuaAorKysrIGIvc3JjL2xpYnNzaDJfcHJpdi5oCitAQCAt MTE3LDYgKzExNywxNCBAQAorICNkZWZpbmUgVUlOVDMyX01BWCAweGZmZmZmZmZmVQorICNlbmRp ZgorIAorKyNpZmRlZiBfV0lONjQKKysjZGVmaW5lIFNTSDJfVU5DT05TVChwKSAgKCh2b2lkICop KGxpYnNzaDJfdWludDY0X3QpKGNvbnN0IHZvaWQgKikocCkpCisrI2VsaWYgZGVmaW5lZChfTVND X1ZFUikKKysjZGVmaW5lIFNTSDJfVU5DT05TVChwKSAgKCh2b2lkICopKHVuc2lnbmVkIGludCko Y29uc3Qgdm9pZCAqKShwKSkKKysjZWxzZQorKyNkZWZpbmUgU1NIMl9VTkNPTlNUKHApICAoKHZv aWQgKikodWludHB0cl90KShjb25zdCB2b2lkICopKHApKQorKyNlbmRpZgorKworICNpZiAoZGVm aW5lZChfX0dOVUNfXykgfHwgZGVmaW5lZChfX2NsYW5nX18pKSAmJiBcCisgICAgIGRlZmluZWQo X19TVERDX1ZFUlNJT05fXykgJiYgKF9fU1REQ19WRVJTSU9OX18gPj0gMTk5OTAxTCkgJiYgXAor ICAgICAhZGVmaW5lZChMSUJTU0gyX05PX0ZNVF9DSEVDS1MpCgpkaWZmIC0tZ2l0IGEvbGlic3No Mi5zcGVjIGIvbGlic3NoMi5zcGVjCmluZGV4IGRjMmZjZjYuLjcwYWI2OTcgMTAwNjQ0Ci0tLSBh L2xpYnNzaDIuc3BlYworKysgYi9saWJzc2gyLnNwZWMKQEAgLTYsNyArNiw3IEBACiAKIE5hbWU6 CQlsaWJzc2gyCiBWZXJzaW9uOgkxLjExLjEKLVJlbGVhc2U6CTglez9kaXN0fQorUmVsZWFzZToJ OSV7P2Rpc3R9CiBTdW1tYXJ5OglBIGxpYnJhcnkgaW1wbGVtZW50aW5nIHRoZSBTU0gyIHByb3Rv Y29sCiBMaWNlbnNlOglCU0QtMy1DbGF1c2UKIFVSTDoJCWh0dHBzOi8vd3d3LmxpYnNzaDIub3Jn LwpAQCAtMTcsNiArMTcsNyBAQCBTb3VyY2UyOglodHRwczovL2RhbmllbC5oYXh4LnNlL215a2V5 LmFzYwogUGF0Y2gwOgkJbGlic3NoMi0xLjExLjEtQ1ZFLTIwMjYtNzU5OC5wYXRjaAogUGF0Y2gx OgkJOTdhY2YzZGZkYTgwYzkxYzNhOGM5ZjIzNzI1NDYzMDFkNGExYTdhOC1saWJzc2gyLTEuMTEu MS5wYXRjaAogUGF0Y2gyOgkJMTc2MjY4NTdkMjBiM2M5YTFhZGRmYTQ1OTc5ZGFkY2VlMWNkODRh NC5wYXRjaAorUGF0Y2gzOgkJMmRhZTMwMi1saWJzc2gyLTEuMTEuMS5wYXRjaAogCiBCdWlsZFJl cXVpcmVzOgljb3JldXRpbHMKIEJ1aWxkUmVxdWlyZXM6CWZpbmR1dGlscwpAQCAtNjgsMTQgKzY5 LDIxIEBAIGRldmVsb3BpbmcgYXBwbGljYXRpb25zIHRoYXQgdXNlIGxpYnNzaDIuCiAjIENWRS0y MDI2LTc1OTggbGlic3NoMjogaW50ZWdlciBvdmVyZmxvdyB2aWEgbGFyZ2UgdXNlcm5hbWUgb3Ig cGFzc3dvcmQgYXJndW1lbnRzCiAjIGh0dHBzOi8vZ2l0aHViLmNvbS9saWJzc2gyL2xpYnNzaDIv cHVsbC8xODU4CiAlcGF0Y2ggLVAwCisKICMgQ1ZFLTIwMjYtNTUyMDAgdHJhbnNwb3J0LmM6IEFk ZGl0aW9uYWwgYm91bmRhcnkgY2hlY2tzIGZvciBwYWNrZXQgbGVuZ3RoCiAjIFBhdGNoIG1vZGlm aWVkIGZvciBkb3duc3RyZWFtCiAjIGh0dHBzOi8vZ2l0aHViLmNvbS9saWJzc2gyL2xpYnNzaDIv cHVsbC8yMDUyCiAlcGF0Y2ggLXAxIC1QMQorCiAjIENWRS0yMDI2LTU1MTk5IHBhY2tldC5jOiBj aGVjayBfbGlic3NoMl9nZXRfc3RyaW5nKCkgcmV0dXJuIGluIEVYVF9JTkZPIGhhbmRsZXIKICMg aHR0cHM6Ly9naXRodWIuY29tL2xpYnNzaDIvbGlic3NoMi9wdWxsLzE4NjQKICVwYXRjaCAtcDEg LVAyCiAKKyMgQ1ZFLTIwMjUtMTU2NjE6IEluZm9ybWF0aW9uIGRpc2Nsb3N1cmUgYW5kIGRlbmlh bCBvZiBzZXJ2aWNlIHZpYSBjcmFmdGVkIFNGVFAgcmVzcG9uc2UKKyMgaHR0cHM6Ly9naXRodWIu Y29tL2xpYnNzaDIvbGlic3NoMi9wdWxsLzE3MDUKKyMgaHR0cHM6Ly9naXRodWIuY29tL2xpYnNz aDIvbGlic3NoMi9wdWxsLzE3MTcKKyVwYXRjaCAtcDEgLVAzCisKICMgUmVwbGFjZSBoYXJkIHdp cmVkIHBvcnQgbnVtYmVyIGluIHRoZSB0ZXN0IHN1aXRlIHRvIGF2b2lkIGNvbGxpc2lvbnMKICMg YmV0d2VlbiAzMi1iaXQgYW5kIDY0LWJpdCBidWlsZHMgcnVubmluZyBvbiBhIHNpbmdsZSBidWls ZC1ob3N0CiBzZWQgLWkgcy80NzExLzQ3JXs/X19pc2FfYml0c30vIHRlc3RzL3tvcGVuc3NoX2Zp eHR1cmUuYyx0ZXN0X3NzaHsyLmMsZC50ZXN0fX0KQEAgLTEzMCw2ICsxMzgsMTAgQEAgTENfQUxM PWVuX1VTLlVURi04IG1ha2UgLUMgdGVzdHMgY2hlY2sKICV7X2xpYmRpcn0vcGtnY29uZmlnL2xp YnNzaDIucGMKIAogJWNoYW5nZWxvZworKiBUaHUgSnVuIDI1IDIwMjYgUGF1bCBIb3dhcnRoIDxw YXVsQGNpdHktZmFuLm9yZz4gLSAxLjExLjEtOQorLSBGaXggQ1ZFLTIwMjUtMTU2NjE6IEluZm9y bWF0aW9uIGRpc2Nsb3N1cmUgYW5kIGRlbmlhbCBvZiBzZXJ2aWNlIHZpYSBjcmFmdGVkCisgIFNG VFAgcmVzcG9uc2UKKwogKiBUdWUgSnVuIDIzIDIwMjYgTWlrZWwgT2xhc2FnYXN0aSBVcmFuZ2Eg PG1pa2VsQG9sYXNhZ2FzdGkuaW5mbz4gLSAxLjExLjEtOAogLSBGaXggQ1ZFLTIwMjYtNTUyMDAg JiBDVkUtMjAyNi01NTE5OQogCg==