From 53b8152623290c69657a6774d96888b876e6061f Mon Sep 17 00:00:00 2001
From: Jakub Jelen <jjelen@redhat.com>
Date: Thu, 26 Mar 2026 16:32:24 +0100
Subject: [PATCH] CVE-2026-59845 socket: Properly check fork() return code
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
During execution of proxy command, when fork() fails, its return value
is stored in pid and when the parent process attempts to kill it,
it sends the kill signal to all processes the calling application has
access to (except for init).
This caused nard to debug issues when the system under the load was hitting
fork failures, which resulted in killing of all the system processes
(of given user).
Reported and first patch iteration provided by: Halil Oktay (oblivionsage).
This code missing fork return value check is in libssh since 2010
(f31a14b7932ef4cc165ddd8f1f1a5b23eb21beb3), but this issue is exploitable only
since libssh 0.9.0 as previously there was no implementation of killing
ProxyCommand children.
Signed-off-by: Jakub Jelen <jjelen@redhat.com>
Reviewed-by: Pavol Žáčik <pzacik@redhat.com>
(cherry picked from commit 92b6fb9c5e2d1606e8f809fd884ab6dd4d3b7d45)
Conflict:Adapt context in src/socket.c for 0.10.5
Reference:https://gitlab.com/libssh/libssh-mirror/-/commit/53b8152623290c69657a6774d96888b876e6061f
src/socket.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
@@ -964,6 +964,7 @@
int
ssh_socket_connect_proxycommand(ssh_socket s, const char *command)
{
+ char err_msg[SSH_ERRNO_MSG_MAX] = {0};
socket_t pair[2];
ssh_poll_handle h = NULL;
int pid;
@@ -982,7 +983,17 @@
pid = fork();
if (pid == 0) {
ssh_execute_command(command, pair[0], pair[0]);
- /* Does not return */
+ /* child: Does not return */
+ }
+ /* parent */
+ if (pid == -1) {
+ close(pair[0]);
+ close(pair[1]);
+ ssh_set_error(s->session,
+ SSH_FATAL,
+ "fork failed: %s",
+ ssh_strerror(errno, err_msg, SSH_ERRNO_MSG_MAX));
+ return SSH_ERROR;
}
s->proxy_pid = pid;
close(pair[0]);
--
2.33.0