[AutoPR- Security] Patch libssh for CVE-2026-59850, CVE-2026-59847, CVE-2026-59845, CVE-2026-59844, CVE-2026-59843, CVE-2026-59848 [MEDIUM] - #18238
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
Patch Analysis: Resolved using Older 0.10.6 cleanup uses, equivalent to upstream’s goto error.
CVE-2026-59847 Upstream patch link in astrolabe is incomplete following two patches required. AI patch contains both patch reference. Missing patch https://git.libssh.org/projects/libssh.git/patch/?id=e3dc89de9754790e49b26f03b70e8e4acc88bde
0 test(s) run, so sftp_fsync() is never tested. Result on this modified PR branch
|
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Patch Analysis (
CVE-2026-59847 core logic matches upstream
CVE-2026-59843 core logic matches upstream
CVE-2026-59845 matches upstream
CVE-2026-59844 matches upstream
CVE-2026-59848 core logic matches upstream
CVE-2026-59850 core logic matches upstream)
- Buddy Build
- patch applied during the build (check
rpm.log) - patch include an upstream reference
- PR has security tag







Auto Patch libssh for CVE-2026-59850, CVE-2026-59847, CVE-2026-59845, CVE-2026-59844, CVE-2026-59843, CVE-2026-59848.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1169536&view=results
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1169569&view=results
CVE-2026-59850 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1169543&view=results
CVE-2026-59847 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1169542&view=results
CVE-2026-59843 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1169547&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology