> The libssh library in Ubuntu 24.04 LTS (0.10.6) has a bug where key
exchange (kex) initialization can generate a trailing comma in the
default cipher list under specific build or runtime configurations. This
trailing comma leads to unexpected parsing behaviors, minor syntax
errors, or handshake failures when interacting with strict SSH clients
or servers that do not tolerate malformed cipher strings.

This sounds very hypothetical. We don't do SRUs for hypothetical bugs
(https://ubuntu.com/project/docs/SRU/explanation/requirements/#real-
world-impact). What actual user is impacted by this, and how? For
example, is there a different implementation that has an
interoperability problem due this bug? If so, which product?

>  3. Observe that the returned cipher string incorrectly ends with a
trailing comma (or requires automated string truncation workarounds).

This will only validate that the change that you think will fix it has
been applied, not that the issue is actually fixed. Please test that the
real user story (that you will describe, as above) is fixed.
https://ubuntu.com/project/docs/SRU/howto/common-issues/#test-plan "The
Test Plan verifies a technical change but not the user story"

> The risk is low because it strictly changes macro definitions for
string concatenation during cipher initialization.

> The modification is short, isolated, and verified by upstream unit
tests.

But we won't be running the upstream unit tests, so that raises the
risk. In mitigation, please spend some time to enhance the test plan to
test with a set of cipher negotiation options that exercise appropriate
edge cases.

> +Origin: upstream, https://gitlab.com/libssh/libssh-
mirror/-/commit/a8b7e17aa0cb51a62f308af0bb456a26d461234e

This does not seem to be the official upstream git repository.

I would validate that the cherry-pick matches a commit in an upstream
release or appropriate upstream branch, but I might as well wait for
changes to avoid doing that twice.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2162736

Title:
  SRU: libssh trailing comma in cipher list causing kex generation
  anomalies

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libssh/+bug/2162736/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to