-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 14 Feb 2025 13:06:51 +0000 Source: openssh Binary: openssh-client openssh-client-dbgsym openssh-client-udeb openssh-server openssh-server-dbgsym openssh-server-udeb openssh-sftp-server openssh-sftp-server-dbgsym openssh-tests openssh-tests-dbgsym ssh-askpass-gnome ssh-askpass-gnome-dbgsym Architecture: armhf Version: 1:9.2p1-2+deb12u5 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Colin Watson Description: openssh-client - secure shell (SSH) client, for secure access to remote machines openssh-client-udeb - secure shell client for the Debian installer (udeb) openssh-server - secure shell (SSH) server, for secure access from remote machines openssh-server-udeb - secure shell server for the Debian installer (udeb) openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot openssh-tests - OpenSSH regression tests ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad Changes: openssh (1:9.2p1-2+deb12u5) bookworm-security; urgency=medium . * CVE-2025-26465: Fix MitM in verify_host_key_callback. * Fix incorrect return values on a number of error paths. Checksums-Sha1: 8a04c88b70c1440e25057ae31b7a0906a57e2d2a 3579928 openssh-client-dbgsym_9.2p1-2+deb12u5_armhf.deb c6fcee2405db2f72ac14c5162e1ee26b546bb7fa 342588 openssh-client-udeb_9.2p1-2+deb12u5_armhf.udeb c6d697b317afb072943456a0500737f9af05b619 899848 openssh-client_9.2p1-2+deb12u5_armhf.deb 41008d5c465f440af564cb98220959d48c76e58d 947496 openssh-server-dbgsym_9.2p1-2+deb12u5_armhf.deb 63ecbf7ec70ac69a3368b88927a9da777ae8a0e4 359968 openssh-server-udeb_9.2p1-2+deb12u5_armhf.udeb 986df5fd1587a362ebd8e9290f68e0952b54f589 418344 openssh-server_9.2p1-2+deb12u5_armhf.deb 673e6cc3a0d5c1afd0be5652dc254bd158d8ca37 168760 openssh-sftp-server-dbgsym_9.2p1-2+deb12u5_armhf.deb 7fa226e079a682623eaad7cda64cd5863a184f56 60512 openssh-sftp-server_9.2p1-2+deb12u5_armhf.deb 0f652c687344c4ae9cf10a781a09603e76a8b353 2807356 openssh-tests-dbgsym_9.2p1-2+deb12u5_armhf.deb 0a5cc09d884e26b1290d839f1db731206b3ad256 956640 openssh-tests_9.2p1-2+deb12u5_armhf.deb a206c77827daa5608ed9ba30c9ed6f7c5aec2f21 18426 openssh_9.2p1-2+deb12u5_armhf-buildd.buildinfo e8a8f6a9bbc3f0f71b139dcbceaef493ccc5689c 16968 ssh-askpass-gnome-dbgsym_9.2p1-2+deb12u5_armhf.deb ea0a3da149106a8e45d929bd37c5a4d824d1de40 187364 ssh-askpass-gnome_9.2p1-2+deb12u5_armhf.deb Checksums-Sha256: 0afcf2f7362e21860371f5ea609a913cda92a6d00967b9207ad60df37eb4c4d8 3579928 openssh-client-dbgsym_9.2p1-2+deb12u5_armhf.deb b50fcabb4a81bc9b0786d1f3847b558b277010fb3106b4656714cdf83a790223 342588 openssh-client-udeb_9.2p1-2+deb12u5_armhf.udeb b7c00ba91cc699c80abb80553fe6ad46087acb1ea7c7e1cdeed0f27509459721 899848 openssh-client_9.2p1-2+deb12u5_armhf.deb 6f08a7aed84a96bad7ac4615bb9322db643e5e5d1eb0174ab5a9b32b77bc4907 947496 openssh-server-dbgsym_9.2p1-2+deb12u5_armhf.deb 0e0e4fc61e1c58af7610bf91cefe32de67e0ed38803d7331530229d610566d46 359968 openssh-server-udeb_9.2p1-2+deb12u5_armhf.udeb 349dd826ed0112bca836a49ff9d137598b2204a1780d791c34bd471ec760e906 418344 openssh-server_9.2p1-2+deb12u5_armhf.deb ccb7eba4a7e01271c9f83eb32a67bcafe987426147d21209894878b496de14f1 168760 openssh-sftp-server-dbgsym_9.2p1-2+deb12u5_armhf.deb 582536873f23ff2f5d58a522b831eab052610c3c4b03de67d65c59d6217fe8e7 60512 openssh-sftp-server_9.2p1-2+deb12u5_armhf.deb 99c6f15cd2a36cd5777851fa7369d07b28ecbc67fcbd3932a6caf1590cfbf620 2807356 openssh-tests-dbgsym_9.2p1-2+deb12u5_armhf.deb 00643a912134654eb37d6949c8cc41d6d47f20597207dda67e75378339219dc8 956640 openssh-tests_9.2p1-2+deb12u5_armhf.deb 3661e580ff69fdd14e91adf172168cb4e3d7dfd6187047b4fe4adbdeca6a3765 18426 openssh_9.2p1-2+deb12u5_armhf-buildd.buildinfo 10a8f1d6a7d69710eb0c7757bb42a82f661b3e824351204753ae949ed3805900 16968 ssh-askpass-gnome-dbgsym_9.2p1-2+deb12u5_armhf.deb 503b6f1f7e6ab99a5cd7a3662d77de4373b58fc3853a510b4376b0d445e3d3ea 187364 ssh-askpass-gnome_9.2p1-2+deb12u5_armhf.deb Files: c46417c360c508d69720ed0f5007d619 3579928 debug optional openssh-client-dbgsym_9.2p1-2+deb12u5_armhf.deb 62114538965ff39c936f9eaf025c70b0 342588 debian-installer optional openssh-client-udeb_9.2p1-2+deb12u5_armhf.udeb 41238afbb5c96a11807fb269b1a77151 899848 net standard openssh-client_9.2p1-2+deb12u5_armhf.deb 8188f965e412e829687eb12e98ee0079 947496 debug optional openssh-server-dbgsym_9.2p1-2+deb12u5_armhf.deb 065cb515f99e0bb5277438448bbfc87b 359968 debian-installer optional openssh-server-udeb_9.2p1-2+deb12u5_armhf.udeb dff881b65217891c60ba0443291576ca 418344 net optional openssh-server_9.2p1-2+deb12u5_armhf.deb c64c20e813e82618bb133864641f0231 168760 debug optional openssh-sftp-server-dbgsym_9.2p1-2+deb12u5_armhf.deb 69365684ae3c609519cebe54281877e2 60512 net optional openssh-sftp-server_9.2p1-2+deb12u5_armhf.deb 6f5373050fc3c15327d59d8fcbb51a90 2807356 debug optional openssh-tests-dbgsym_9.2p1-2+deb12u5_armhf.deb 16a3b44cddae25a8dc838ec7cb8db5ef 956640 net optional openssh-tests_9.2p1-2+deb12u5_armhf.deb e5c059d076cfd9cd2a557303afb9601e 18426 net standard openssh_9.2p1-2+deb12u5_armhf-buildd.buildinfo 15fe4d546fa29f45477936f8eb5d4aa6 16968 debug optional ssh-askpass-gnome-dbgsym_9.2p1-2+deb12u5_armhf.deb 6001fd319793a1e24f6088db357a6b72 187364 gnome optional ssh-askpass-gnome_9.2p1-2+deb12u5_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmevVXMACgkQ4CwlMGxH D8VjfhAAntpie5LPz381lsL86vbTCZmRDuSx2ZlDlwuXWz8UYkFSWb2ebP0wWcWl QQsy+k2aFisbzu0qAuFrCV8WR80ZBkm4nEWDa/GuJK1Dix5Sb6HBije+xeKIrepq 14DKyALLQy8mtI7aLSi7gvRqrfX1ydNH+dtB0nmYAWlVCceyithkq8TWef+nnjuP dJalKI8VuZ/DD7wSeyU47iVsljloOx9upGDIM0vqXSvhALjpxkA6Ya2/BWuCR0ua gS8sne4S2+cShGk3RhsX/xqI8kbDWVRFfFPdPsMXmLjBuiwHdw8c9lA4C2q2/+Qh PpseYB2iEHBWwvI2Frsrbb86xba5k2yv6Uw1HQaIKuGQDHPZu5qMHJVlO6LBrcEi HFS86eikVKbxxTFQcU8Jj84epfCJwzR9InJw+rA9gB/SGm5ivz11xp9QlVsG31KS NfptXqzrQ1QE0eMMlsG/WgqLSAmEHpL0Uz4Bjbo6NtbkTjYMftg+x+W19qLT17XJ kRZmX1Oiu3LscUW+m0GXTqBQNrBkFyPdqWcoB25/5DN5hXK7K2aGE03dXs0EuNe9 iBzz1Q33Tbq9b3Lcep6u7z2lOIhh1gPfTT1kxWPQV5IYYD3WavNJokZ5IleIxn5o J9CKc1Sq2C1ptS+8SpTbl2VXyPwkA4Lj3cUeR/P5pcX0/9sTgtA= =2m1z -----END PGP SIGNATURE-----