Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-133421

Rebase libssh to 0.12.0

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • rhel-10.2
    • rhel-10.2
    • libssh
    • libssh-0.12.0-1.el10
    • No
    • Moderate
    • rhel-security-crypto-diamonds
    • 26
    • 0
    • QE ack, Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • None
    • Hide

      AC1) upstream tests pass  in upstream-testsuit for CVE-2025-5449, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968

      AC2) interoperability test between libssh client and openssh server passes

      AC3) extended sanity/libssh-with-PKCS-11-URI test to check Ed25519 keys passes

      Show
      AC1) upstream tests pass  in upstream-testsuit for CVE-2025-5449, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968 AC2) interoperability test between libssh client and openssh server passes AC3) extended sanity/libssh-with-PKCS-11-URI test to check Ed25519 keys passes
    • Pass
    • Automated
    • Rebase
    • Hide
      Version: 0.12.0

      List of highlights:
      - adds support for hybrid post-quantum key exchange mechanisms, in particular:
        * sntrup761x25519-sha512
        * sntrup761x25519-sha512@openssh.com
        * mlkem768nistp256-sha256
        * mlkem768x25519-sha256
        * mlkem1024nistp384-sha384
      - adds support for GSSAPI Key Exchange (RFC 4462, RFC 8732)
      - adds support for Ed25519 keys through PKCS#11
      - adds support for FIDO/U2F keys, compatible with OpenSSH
      - adds new configuration options:
        * RequiredRsaSize
        * AddressFamily (client)
        * GSSAPIKeyExchange
        * GSSAPIKexAlgorithms
      - adds more OpenSSH-compatible percent expansion characters
      - adds API functions for signing arbitrary data with SSH keys
      - bumps minimal RSA key size to 1024
      - improves the stability and compatibility of ProxyJump
      - adds functionality to obtain a list of configured identities
      - adds new PKI context structure for key operations
      Show
      Version: 0.12.0 List of highlights: - adds support for hybrid post-quantum key exchange mechanisms, in particular:   * sntrup761x25519-sha512   * sntrup761x25519-sha512@openssh.com   * mlkem768nistp256-sha256   * mlkem768x25519-sha256   * mlkem1024nistp384-sha384 - adds support for GSSAPI Key Exchange (RFC 4462, RFC 8732) - adds support for Ed25519 keys through PKCS#11 - adds support for FIDO/U2F keys, compatible with OpenSSH - adds new configuration options:   * RequiredRsaSize   * AddressFamily (client)   * GSSAPIKeyExchange   * GSSAPIKexAlgorithms - adds more OpenSSH-compatible percent expansion characters - adds API functions for signing arbitrary data with SSH keys - bumps minimal RSA key size to 1024 - improves the stability and compatibility of ProxyJump - adds functionality to obtain a list of configured identities - adds new PKI context structure for key operations
    • Proposed
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      The 0.12 release of libssh is expected in December. Rebase to this release to bring hybrid PQC key exchange to RHEL 10.

              pzacik@redhat.com Pavol Zacik
              pzacik@redhat.com Pavol Zacik
              Pavol Zacik Pavol Zacik
              Ganna Starovoytova Ganna Starovoytova
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated: