grthtrhthjhtyjytjytkergtrhtrjytjerhrfh4:24 29/09/2026Return-Path: Delivered-To: jagonzalez@bagno-company.com Received: from ambar.servidorlinux16.com by ambar.servidorlinux16.com with LMTP id AshRDbksnWqIdCQAm9P8sg (envelope-from ) for ; Sun, 06 Sep 2026 06:04:57 -0300 Return-path: Envelope-to: jagonzalez@bagno-company.com Delivery-date: Sun, 06 Sep 2026 06:04:57 -0300 Received: from r200-125-33-206.ae-static.anteldata.net.uy ([200.125.33.206]:49858 helo=storagecentral.bagno.company.com) by ambar.servidorlinux16.com with esmtpsa (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.99.5) (envelope-from ) id 1x38o5-0000000A1W4-1E4l for jagonzalez@bagno-company.com; Sun, 06 Sep 2026 06:04:57 -0300 Received: by storagecentral.bagno.company.com (Postfix, from userid 0) id 505777A0251; Sun, 6 Sep 2026 06:04:55 -0300 (-03) Subject: [storagecentral.bagno.company.com] unattended-upgrades result for storagecentral.bagno.company.com: SUCCESS From: soporte@bagno-company.com To: jagonzalez@bagno-company.com Auto-Submitted: auto-generated MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260906090455.505777A0251@storagecentral.bagno.company.com> Date: Sun, 6 Sep 2026 06:04:55 -0300 (-03) Unattended upgrade result: Se han instalado todas las actualizaciones Paquetes que se actualizaron: libssh2-1 Registro de instalaci=C3=B3n de paquete: Log started: 2026-09-06 06:04:37 apt-listchanges: The mail frontend needs an e-mail address to be configured= , using text apt-listchanges: Leyendo lista de cambios... apt-listchanges: Changelogs --------------------------- libssh2 (1.10.0-3+deb12u1) bookworm-security; urgency=3Dhigh * Non-maintainer upload by the LTS Team. * CVE-2025-15661: a malicious server could send an oversized link_len in SSH_FXP_NAME responses (READLINK/REALPATH) and trigger an out-of-bounds memcpy, leaking heap memory or crashing the client (Closes: #1140401). * CVE-2026-7598: The impacted element is the function userauth_password o= f the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. * CVE-2026-58050: libsshw2 reads an attacker-controlled 32-bit attribute without bounds checking, so on 32-bit platforms the multiplication over= flows to an undersized buffer. count from a publickey-subsystem response and = uses it without bounds checking, causing an overflows to an undersized buffer (Closes: #1144415). * CVE-2026-58051: libssh2 grows its publickey list with SSH2_REALLOC but = does not zero-initialize new entries before parsing populates them, so a par= se failure reaching the cleanup path leaves. A malicious SSH server offeri= ng the publickey subsystem can use a malformed response to make cleanup fr= ee an uninitialized, attacker-influenceable attrs pointer in a connecting lib= ssh2 client. * CVE-2026-66032: fix double free in sftp_open() reachable from a malicio= us server during SFTP session setup (SSH_FXP_OPEN answered with SSH_FXP_STATUS/FX_OK followed by a failing sftp_packet_require()) (Clos= es: #1142856). * CVE-2026-66034: fix missing bounds check in libssh2_publickey_list_fetc= h() leading to a heap out-of-bounds read and a free of an uninitialized poi= nter, triggerable by a malicious server via the publickey subsystem. -- Emmanuel Arias Sat, 05 Sep 2026 09:40:39 -0300 apt-listchanges: The mail frontend needs an e-mail address to be configured= , using text apt-listchanges: Leyendo lista de cambios... (Leyendo la base de datos ...=20 (Leyendo la base de datos ... 5% (Leyendo la base de datos ... 10% (Leyendo la base de datos ... 15% (Leyendo la base de datos ... 20% (Leyendo la base de datos ... 25% (Leyendo la base de datos ... 30% (Leyendo la base de datos ... 35% (Leyendo la base de datos ... 40% (Leyendo la base de datos ... 45% (Leyendo la base de datos ... 50% (Leyendo la base de datos ... 55% (Leyendo la base de datos ... 60% (Leyendo la base de datos ... 65% (Leyendo la base de datos ... 70% (Leyendo la base de datos ... 75% (Leyendo la base de datos ... 80% (Leyendo la base de datos ... 85% (Leyendo la base de datos ... 90% (Leyendo la base de datos ... 95% (Leyendo la base de datos ... 100% (Leyendo la base de datos ... 51253 ficheros o directorios instalados actua= lmente.) Preparando para desempaquetar .../libssh2-1_1.10.0-3+deb12u1_amd64.deb ... Desempaquetando libssh2-1:amd64 (1.10.0-3+deb12u1) sobre (1.10.0-3+b1) ... Configurando libssh2-1:amd64 (1.10.0-3+deb12u1) ... Procesando disparadores para libc-bin (2.36-9+deb12u13) ... Log ended: 2026-09-06 06:04:54 Registro de unattended-upgrades: Iniciando gui=C3=B3n de actualizaciones desatendidas Fuentes permitidas: origin=3DDebian,codename=3Dbookworm,label=3DDebian-Secu= rity, origin=3DDebian,codename=3Dbookworm-security,label=3DDebian-Security,= origin=3DDebian,codename=3Dbookworm,label=3DDebian-Security, origin=3DDebi= an,codename=3Dbookworm-security,label=3DDebian-Security Initial blacklist:=20 Initial whitelist (not strict):=20 Paquetes que se actualizar=C3=A1n: libssh2-1 Writing dpkg log to /var/log/unattended-upgrades/unattended-upgrades-dpkg.l= og Se han instalado todas las actualizaciones