Your message dated Tue, 01 Sep 2026 11:49:03 +0000
with message-id <[email protected]>
and subject line Bug#1141818: fixed in python-asyncssh 2.24.0-1
has caused the Debian Bug report #1141818,
regarding python-asyncssh: CVE-2026-54591
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1141818: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141818
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-asyncssh
Version: 2.23.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for python-asyncssh.
CVE-2026-54591[0]:
| AsyncSSH is a Python package which provides an asynchronous client
| and server implementation of the SSHv2 protocol on top of the Python
| asyncio framework. Prior to 2.23.1, a malicious SSH server can write
| arbitrary files on the asyncssh SCP client's filesystem by sending
| filenames containing ../ traversal sequences because _parse_cd_args
| in scp.py returns server-provided names verbatim and _recv_files
| joins them to the destination path without enforcing the target
| directory boundary. This issue is fixed in version 2.23.1.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-54591
https://www.cve.org/CVERecord?id=CVE-2026-54591
[1] https://github.com/ronf/asyncssh/security/advisories/GHSA-2wxc-x7rj-hg8f
[2]
https://github.com/ronf/asyncssh/commit/d730803b8e4e94c20c7580d90f94d1e05f9f58de
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: python-asyncssh
Source-Version: 2.24.0-1
Done: Jeroen Ploemen <[email protected]>
We believe that the bug you reported is fixed in the latest version of
python-asyncssh, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jeroen Ploemen <[email protected]> (supplier of updated python-asyncssh package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 01 Sep 2026 11:32:18 +0000
Source: python-asyncssh
Built-For-Profiles: noudeb
Architecture: source
Version: 2.24.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Jeroen Ploemen <[email protected]>
Closes: 1141817 1141818
Changes:
python-asyncssh (2.24.0-1) unstable; urgency=medium
.
[ Lester Guerzon ]
* Team upload
* New upstream release
* Release includes fix for CVE-2026-54590, closes: #1141817
* Release includes fix for CVE-2026-54591, closes: #1141818
.
[ Jeroen Ploemen ]
* Copyright: bump upstream years.
* Control: add build-dep on python3-aiofiles, used by
tests/test_process.py.
* CI: add config in salsa-ci.yml.
* Control: add "Built-Using" field to the documentation pkg.
* Control: bump version of python3-cryptography to >=48.0.1.
* Tests: remove deps on python3-cryptography and python3-typing-
extensions (already a hard dependencies of the binary pkg), add
missing dep on python3-aiofiles.
Checksums-Sha1:
fe6245d3283cd47b6d93d3f8e95ad37d2c729670 2787 python-asyncssh_2.24.0-1.dsc
98917f3353e7d5288810a54ddbe4fdbcaf29bda1 544154
python-asyncssh_2.24.0.orig.tar.gz
95999ce604e2887d372666503ebf2045614f2747 9316
python-asyncssh_2.24.0-1.debian.tar.xz
40265082af87f97c2c8c6d2be768fa2a1b7677dd 10164
python-asyncssh_2.24.0-1_source.buildinfo
Checksums-Sha256:
8c30b2c76e10670ea59560256fae49b374ee005b24279ea6b8cb658d7cddd5f4 2787
python-asyncssh_2.24.0-1.dsc
38ad660ac860a1333ae86123a51d7aa6ab1ccc55d0cbaa7afaa51cce589d333a 544154
python-asyncssh_2.24.0.orig.tar.gz
d89332caadc8bfa9cc4aa59042bb57750167b780c9dd7858e4bdb572905ba36b 9316
python-asyncssh_2.24.0-1.debian.tar.xz
84f4476393b6982eaac4edabce23ab042f344295fa31ad00009ef11e6789e280 10164
python-asyncssh_2.24.0-1_source.buildinfo
Files:
14fa3bb6a741931e6c8f4b64096614e3 2787 python - python-asyncssh_2.24.0-1.dsc
75ad4c14295fe227292f0f6c53c0b468 544154 python -
python-asyncssh_2.24.0.orig.tar.gz
eb20268b81a1ec832ecc9181ef3f1a6f 9316 python -
python-asyncssh_2.24.0-1.debian.tar.xz
84e8c405f396bef70790406acc5c6098 10164 python -
python-asyncssh_2.24.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEd8lhnEnWos3N8v+qQoMEoXSNzHoFAmqWuBkACgkQQoMEoXSN
zHrvsw/8Dqv4dWFhBtnInGTbAUHHhQcMXgRaoTuZoZ213O7uP8G9NmpCJEtXl7bT
FZYVGjDtESFXD9VbkZJVFTXBEuZz4Z9VYgReGtVmBAFN858988RCKKhP73oZmUeP
tiz/XYZ5S41dWHWB88pUgjuNSAGEJWlhltYpWaSo8a7jB4VmGtXu9+gjhmPRpKLX
VhNhEFSb5zcgW2OF9tb5RokVNIuutrvZep4/hrQJRneKnoeQIzV3H/5XbvmLd0Bx
vZVby8PG64GV/zqlhUAELrP0SVttdnr3TiDkp3BTAQX0h/DnNeIXc5HrR/9+HvQM
+6NhEgiBQiehGdbTCM9ouvqn3UUImJpzMal0c8uqYG+Of9ET7elrXyzrofeED3F6
qSOngqCP2HBbX8NZSEdUpjMzXVTpYJ2vdaU52HPjOiAgrHiN4muFBVrkZVuL1A0c
Tpo+UUL81yWSaqpO8yd0VJKyd9XLQ2HmVXpqNj9RaOJ3oBJix38kdL9iEiHRir4R
KIFA+dfOkJv/yVRmQj0l5KaXHcz88sL5yBzkJSgrlH/DHbmCwydviSiWlv3kjDyT
/Tc+reCskd3a22r8fQT0Un/uk6xtKR9bLt4IXQ7AZpGte9KZ8uJIHyT1iE5ob3V6
JqW/rUa0vhhsUH3jwNElEAxletAfGsz4YEXeA6T7FgamqoSRFGs=
=eoPS
-----END PGP SIGNATURE-----
pgpTP64HYEx7N.pgp
Description: PGP signature
--- End Message ---