53 Commits

Author SHA1 Message Date
bitianyuan
1b877bb2b1 Fix CVE-2025-26465
Signed-off-by: bitianyuan <bitianyuan@huawei.com>
2025-02-19 11:11:15 +08:00
bitianyuan
631079e45e Set OPENSSL_BIN from OpenSSL directory
remove unused patch  skip-tests-for-C-if-there-is-no-openssl-on-local-pat.patch

Signed-off-by: bitianyuan <bitianyuan@huawei.com>
2025-01-14 12:29:42 +00:00
Corwin-Song
93c66046c1 fix CVE-2024-6409
Signed-off-by: Corwin-Song <songjuntao@kylinos.cn>
(cherry picked from commit 7d112ee7f10801f8739d84a43400373e03464709)
2024-07-11 17:02:56 +08:00
renmingshuai
b20004b32b fix CVE-2024-6387 2024-07-02 03:56:43 +00:00
renmingshuai
793acc4534 spelling correction 2024-05-14 02:17:54 +00:00
renmingshuai
ba41459911 Disable SElinux when make tests 2024-04-29 07:15:02 +00:00
renmingshuai
aab85b4d0e fix setting the number of authentication attempts failed 2024-03-14 02:35:42 +00:00
Corwin-Song
0c197991d1 fix memory leak in kex2 exchange function
Signed-off-by: Corwin-Song <songjuntao@kylinos.cn>
(cherry picked from commit 583ca0b2670b91dadc727ae39807cde2e5729a00)
2024-02-17 09:25:29 +08:00
renmingshuai
434bdc3f64 move pam_ssh_agent_auth man page to sub-package
(cherry picked from commit 9481c5a5b866ce8b1f43b4f5456c837164232481)
2024-01-31 16:59:05 +08:00
renmingshuai
f0d299c3b1 fix CVE-2023-48795
(cherry picked from commit cb39294fb32bbb7430f67d91567cdfa501d38777)
2024-01-11 11:46:09 +08:00
renmingshuai
32c6b2239a sync from sp1
(cherry picked from commit 8a8baad0b68d7a8c3e2749460341643700cf6821)
2023-12-28 20:24:39 +08:00
renmingshuai
ba357b40d1 fixCVE-2023-48795 and CVE-2023-51385
(cherry picked from commit fb5bea51cdad8c74fd057ddc78ddd3f38fbd98a7)
2023-12-25 11:31:43 +08:00
renmingshuai
0c4516eae3 In channel_request_remote_forwarding the parameters 2023-08-15 10:43:30 +08:00
renmingshuai
d06655221d fix CVE-2023-38408
(cherry picked from commit bb9ae5684f2460817da393a4114f26a84a09eebe)
2023-07-28 10:54:23 +08:00
renmingshuai
38abdec0fa fix misspeling and enable dt tests 2023-06-13 20:53:12 +08:00
renmingshuai
eeae07d07f fixenvironmentvariable 2023-05-27 14:57:46 +08:00
renmingshuai
342e4965fb fix CVE-2023-25136 2023-03-09 09:59:10 +08:00
renmingshuai
966734b664 set default ssh_config 2023-02-28 20:50:16 +08:00
renmingshuai@huawei.com
a133865887 fix tests failure and enable make tests 2023-01-06 12:26:28 +08:00
renmingshuai
8ebbd9ae82 avoid integer overflow of auth attempts 2023-01-03 19:13:09 +08:00
renmingshuai
842d99b183 add strict scp check for CVE-2020-15778 2022-12-29 19:41:50 +08:00
renmingshuai
65e875d673 add loongarch64 2022-12-29 18:03:14 +08:00
renmingshuai
c130ed1968 backport some upstream patches 2022-12-29 14:42:32 +08:00
renmingshuai
0298398514 Add sw64 architecture 2022-12-29 11:20:38 +08:00
renmingshuai
f91326ebce fix ssh-keygen -Y check novalidate requires name 2022-12-29 10:29:41 +08:00
duyiwei
64c29e1625 enable include /etc/ssh/sshd_config.d/*.config 2022-12-07 14:36:00 +08:00
renmingshuai
fa75764522 PubkeyAcceptedKeyTypes has been renamed to PubkeyAcceptedAlgorithms in openssh-8.5p1 2022-11-28 21:19:45 +08:00
renmingshuai
9bb9a93b8f add better debugging
Signed-off-by: renmingshuai <renmingshuai@huawei.com>
(cherry picked from commit b7232a848cc21e97ff6632d564c11201a8cbf246)
2022-11-28 15:32:36 +08:00
renmingshuai
1d03898897 add ssh-keygen bash completion 2022-11-02 17:10:32 +08:00
kircher
b1e3288a53 add smx support in openssh 2022-10-18 16:48:39 +08:00
Rimsky
21d1fbda5f fix-possible-NULL-deref-when-built-without-FIDO 2022-06-25 17:34:46 +08:00
mylee
8243dc3af0 fix spec changelog date 2022-05-10 13:30:53 +08:00
seuzw
2d18de6ab9 fix incorrect sftp-server binary path in /etc/ssh/sshd_config 2022-05-05 11:24:28 +08:00
kircher
cae10a5ce3 add sshd.tmpfiles
(cherry picked from commit 61b7914415ee171513d073172520c422b4132621)
2022-03-09 10:26:42 +08:00
renmingshuai
f2c3d6e19a update to openssh-8.8p1
Reference:https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-4.3p2-askpass-grab-info.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-5.1p1-askpass-progress.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-5.8p2-sigpipe.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-5.9p1-ipv6man.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.3p1-ctr-evp-fast.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.4p1-fromto-remote.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6.1p1-log-in-chroot.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6.1p1-scp-non-existing-directory.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6.1p1-selinux-contexts.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6p1-allow-ip-opts.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6p1-force_krb.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6p1-GSSAPIEnablek5users.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6p1-keycat.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6p1-keyperm.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6p1-kuserok.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.6p1-privsep-selinux.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.7p1-coverity.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.7p1-sftp-force-permission.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-6.8p1-sshdT-output.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.1p2-audit-race-condition.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.2p2-k5login_directory.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.2p2-s390-closefrom.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.2p2-x11.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.3p1-x11-max-displays.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.4p1-systemd.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.5p1-sandbox.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.6p1-audit.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.6p1-cleanup-selinux.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.7p1-fips.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.7p1-gssapi-new-unique.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.7p1.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.8p1-role-mls.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.8p1-scp-ipv6.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-7.8p1-UsePAM-warning.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.0p1-crypto-policies.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.0p1-gssapi-keyex.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.0p1-keygen-strip-doseol.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.0p1-openssl-evp.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.0p1-openssl-kdf.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.0p1-pkcs11-uri.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.0p1-preserve-pam-errors.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.2p1-visibility.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.2p1-x11-without-ipv6.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/openssh-8.7p1-scp-kill-switch.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/pam_ssh_agent_auth-0.10.2-compat.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/pam_ssh_agent_auth-0.10.2-dereference.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/pam_ssh_agent_auth-0.10.3-seteuid.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/pam_ssh_agent_auth-0.9.2-visibility.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/pam_ssh_agent_auth-0.9.3-agent_structure.patch
https://src.fedoraproject.org/rpms/openssh/blob/rawhide/f/pam_ssh_agent_auth-0.9.3-build.patch
2021-12-09 17:32:49 +08:00
kircher
f21f23324f CVE-2021-41617 2021-10-29 18:11:04 +08:00
wei dong
e5fc9e9134 Fix spelling errors 2021-08-03 11:03:13 +08:00
kircher
584f71f3e8 Remove-debug-message-from-sigchld-handler 2021-07-30 16:05:00 +08:00
seuzw
24ff0a5c9c move closefrom to before first malloc 2021-07-20 20:05:27 +08:00
panchenbo
9ad957a501 fix pam_ssh_agent_auth.8.gz conflicts 2021-07-09 16:22:39 +08:00
seuzw
fcef38e5d9 add strict-scp-check for CVE-2020-15778 2021-05-20 20:28:00 +08:00
chxssg
8c65c058d1 fix CVE-2020-14145 2021-01-04 23:07:12 +08:00
eaglegai
2da07558f4 adjust pam_ssh_agent_auth release number 2020-11-18 16:51:04 +08:00
eaglegai
0de2d05e19 keep pam_ssh_agent_auth change release number with openssh 2020-11-17 17:02:53 +08:00
liuzy518
1462ccaac2 fix CVE-2018-15919.patch
Signed-off-by: liuzy518 <570407222@qq.com>
2020-09-15 16:58:49 +08:00
yu_boyun
ef3d61f407 update to 8.2p1 2020-07-25 15:30:35 +08:00
openeuler-ci-bot
2a0102b834 !10 Adapt for RISC-V arch
Merge pull request !10 from whoisxxx/master
2020-07-21 10:25:03 +08:00
sherlock2010
8a23f54ab3 Fix CVE-2020-12062 2020-07-03 14:10:15 +08:00
whoisxxx
5731e07797 Adapt for RISC-V
Signed-off-by: whoisxxx <zhangxuzhou4@huawei.com>
2020-06-01 19:52:47 +08:00
songnannan
29ee5f4511 bugfixCVE-2018-15919 2020-03-18 20:05:14 +08:00