From 97acf3dfda80c91c3a8c9f2372546301d4a1a7a8 Mon Sep 17 00:00:00 2001 From: Will Cosgrove Date: Fri, 12 Jun 2026 15:57:44 -0700 Subject: [PATCH] transport.c: Additional boundary checks for packet length (#2052) Add additional bounds checking on packet length to prevent OOB write. Credit: [TristanInSec](https://github.com/TristanInSec) CVE: CVE-2026-55200 Upstream: https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8 [thomas: backport to 1.11.1, change ntohu32 call] Signed-off-by: Thomas Perale --- src/transport.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/src/transport.c b/src/transport.c index 869fc5a4fa..7925ad33d1 100644 --- a/src/transport.c +++ b/src/transport.c @@ -645,8 +645,12 @@ int ssh2_transport_read(LIBSSH2_SESSION *session) total_num = 4; p->packet_length = _libssh2_ntohu32(block); - if(p->packet_length < 1) + if(p->packet_length < 1) { return LIBSSH2_ERROR_DECRYPT; + } + else if(p->packet_length > LIBSSH2_PACKET_MAXPAYLOAD) { + return LIBSSH2_ERROR_OUT_OF_BOUNDARY; + } /* total_num may include size field, however due to existing * logic it needs to be removed after the entire packet is read