From d0b61d082621d45bf19f0aa04e9bbbc7e47e8f88 Mon Sep 17 00:00:00 2001 From: "djm@openbsd.org" Date: Thu, 2 Apr 2026 07:50:55 +0000 Subject: upstream: move username validity check for usernames specified on MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit the commandline to earlier in main(), specifically before some contexts where a username with shell characters might be expanded by a %u directive in ssh_config. MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit We continue to recommend against using untrusted input on the SSH commandline. Mitigations like this are not 100% guarantees of safety because we can't control every combination of user shell and configuration where they are used. Reported by Florian Kohnhäuser Upstream: https://salsa.debian.org/ssh-team/openssh/-/blob/bookworm/debian/patches/CVE-2026-35386-2.patch Upstream: https://anongit.mindrot.org/openssh.git/commit/?id=76685c9b09a66435cd2ad8373246adf1c53976d3 CVE: CVE-2026-35386 Signed-off-by: Thomas Perale --- ssh.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/ssh.c b/ssh.c index e5ec18a73..ac06bbe74 100644 --- a/ssh.c +++ b/ssh.c @@ -1123,8 +1123,15 @@ main(int ac, char **av) if (!host) usage(); + /* + * Validate commandline-specified values that end up in %tokens + * before they are used in config parsing. + */ + if (options.user != NULL && !ssh_valid_ruser(options.user)) + fatal("remote username contains invalid characters"); if (!ssh_valid_hostname(host)) fatal("hostname contains invalid characters"); + options.host_arg = xstrdup(host); /* Initialize the command to execute on remote host. */