Skip to content

userauth.c: username_len bounds checking - #1858

Merged
willco007 merged 1 commit into
libssh2:masterfrom
willco007:userauth-bounds
Apr 13, 2026
Merged

willco007 merged 1 commit into
libssh2:masterfrom
willco007:userauth-bounds

Conversation

@willco007

@willco007 willco007 commented Apr 13, 2026 •

Copy link
Copy Markdown
Member

Return errors when username_len will exceed bounds, fix existing bounds check.

Credit:
dapickle

return errors when username_len will exceed bounds
@willco007
willco007 merged commit 256d04b into libssh2:master Apr 13, 2026
95 checks passed
@willco007
willco007 deleted the userauth-bounds branch April 13, 2026 18:19
shivammathur added a commit to winlibs/libssh2 that referenced this pull request May 24, 2026
Backport upstream libssh2 fix for username_len bounds checking in src/userauth.c.

CVE-2026-7598: integer overflow in userauth_password via crafted username_len/password_len values, remotely triggerable in libssh2 up to 1.11.1.

CWE: CWE-189, CWE-190

CVSS: 3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L (7.3 HIGH)

Upstream-Commit: 256d04b60d80bf1190e96b0ad1e91b2174d744b1

Upstream-PR: libssh2/libssh2#1858
vszakats added a commit that referenced this pull request Jul 5, 2026
- cap username/password to `MAX_INPUT_LEN` in `userauth_password()`
  to avoid wraparound in 32-bit builds.
  `MAX_INPUT_LEN` is currently set to: 35 KB - 0x100.
  Reported by GitHub Code Quality
  Follow-up to 256d04b #1858

- cap username to `MAX_INPUT_LEN` where the limits were set higher.
  Follow-up to 256d04b #1858

- return `LIBSSH2_ERROR_OUT_OF_BOUNDARY` to indicate out of bounds
  errors. Were `LIBSSH2_ERROR_PROTO`, `LIBSSH2_ERROR_INVAL`,
  `LIBSSH2_ERROR_PUBLICKEY_UNVERIFIED` prior to this patch.

Closes #2223
pratikfarkasest added a commit to pratikfarkasest/libssh2 that referenced this pull request Oct 5, 2026
The userauth request builders size their packet buffer from username_len
plus a fixed overhead. An oversized username_len must be rejected before
any network I/O rather than wrapped around (fix: libssh2#1858, commit 256d04b).

Extend test_simple to call every userauth entry point reachable on an
unconnected session with username_len = 0xFFFFFFFF and assert each one
rejects it: libssh2_userauth_list(), libssh2_userauth_password_ex(),
libssh2_userauth_publickey_fromfile_ex(),
libssh2_userauth_hostbased_fromfile_ex() and
libssh2_userauth_keyboard_interactive_ex(). The checks reuse the session
test_simple already creates, so they add no setup cost.

Ref: libssh2#1858
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant