Bug 32676 - CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) - trilead-ssh2
Summary: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Atta...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 32641
  Show dependency treegraph
 
Reported: 2023-12-31 18:36 CET by Marja Van Waes
Modified: 2026-03-24 18:54 CET (History)
11 users (show)

See Also:
Source RPM: trilead-ssh2-217-7.jenkins8.5.mga9
CVE: CVE-2023-48795
Status comment:
marja11: affects_mga9+


Attachments

Description Marja Van Waes 2023-12-31 18:36:57 CET
+++ This bug was initially created as a clone of Bug #32641 +++

That CVE was announced here:
https://www.openwall.com/lists/oss-security/2023/12/18/3
https://www.openwall.com/lists/oss-security/2023/12/19/5
https://www.openwall.com/lists/oss-security/2023/12/20/3

Many SSH implementations that are packaged in Mageia are affected:
<snip>
  -  trilead-ssh2
Marja Van Waes 2023-12-31 18:37:12 CET

Whiteboard: (none) => MGA9TOO

Marja Van Waes 2023-12-31 18:37:56 CET

Assignee: bugsquad => pkg-bugs

Marja Van Waes 2024-01-02 11:59:12 CET

CVE: (none) => CVE-2023-48795

Nicolas Salguero 2024-01-19 16:12:02 CET

Blocks: (none) => 32748

Nicolas Salguero 2024-01-19 16:16:44 CET

Blocks: 32748 => (none)

Comment 1 Nicolas Salguero 2024-03-22 16:24:05 CET
SUSE has issued an advisory today (March 22):
https://lwn.net/Articles/966407/
Comment 2 Marja Van Waes 2025-12-31 14:03:49 CET
Adding the flag: affects_mga9 +
to all bugs with MGA9TOO on the whiteboard, without removing MGA9TOO (for now).

Flags: (none) => affects_mga9+

Comment 3 Marja Van Waes 2026-01-11 17:58:19 CET
https://github.com/jenkinsci/trilead-ssh2/releases/tag/build-217-jenkins-274.276.v58da_75159cb_7

"Backport of Terrapin fix on top of build-217-jenkins-274.va_969b_d35f933."

Was released on Mar 6, 2024..


We have only rebuilt an older version against java (2x)

If no one maintains this package, can't it be obsoleted? only jsch-agent-proxy-trilead-ssh2 depends on it)
Comment 4 Marja Van Waes 2026-01-11 18:04:08 CET
(In reply to Marja Van Waes from comment #3)
> https://github.com/jenkinsci/trilead-ssh2/releases/tag/build-217-jenkins-274.
> 276.v58da_75159cb_7
> 
> "Backport of Terrapin fix on top of build-217-jenkins-274.va_969b_d35f933."
> 
> Was released on Mar 6, 2024....
> 
> 
> We have only rebuilt an older version against java (2x)
> 
> If no one maintains this package, then obsolete it, only
> jsch-agent-proxy-trilead-ssh2 depends on it)

Remove it from the "Packages that need to be obsoleted for Mageia 10 release" tracker (bug 32127) if it gets fixed fast. 

Else jsch-agent-proxy-trilead-ssh2 and trilead-ssh2 need to be obsoleted.

Blocks: (none) => 32127

Comment 5 David GEIGER 2026-03-19 22:52:47 CET
Fixed with trilead-ssh2-217-9.jenkins293.1.mga10!
David GEIGER 2026-03-19 23:00:46 CET

Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9

Comment 6 David GEIGER 2026-03-19 23:03:32 CET
Assigning to QA,


Packages in 9/Core/Updates_testing:
======================
trilead-ssh2-217-8.jenkins293.1.mga9.noarch.rpm
trilead-ssh2-javadoc-217-8.jenkins293.1.mga9.noarch.rpm

From SRPMS
trilead-ssh2-217-8.jenkins293.1.mga9.src.rpm

Assignee: pkg-bugs => qa-bugs

Comment 7 Herman Viaene 2026-03-20 10:50:18 CET
MGA9-64 server Plasma Wayland on Compaq H000SB
No installation issues.
No previous updates, no wiki, so
#  urpmq --whatrequires trilead-ssh2
jsch-agent-proxy-trilead-ssh2
svnkit
trilead-ssh2
Wanting to test at least something, started googling, decided to install svnkit and svnkit-cli.
Further search brought me to https://www.linode.com/docs/guides/subversion-svn-tutorial/ and https://www.linode.com/docs/guides/install-apache-subversion-ubuntu/
but the apache dependencies are probably in other packages for Mageia, so I am stuck there.
As this is largely developers territory, and you judge clean install is OK, plse set the OK, you have my blessing.

CC: (none) => herman.viaene

katnatek 2026-03-20 18:40:32 CET

Keywords: (none) => advisory

Comment 8 katnatek 2026-03-22 20:09:40 CET
Thanks Herman

Whiteboard: (none) => MGA9-64-OK

Comment 9 katnatek 2026-03-22 20:14:34 CET
Thanks Herman
Comment 10 Thomas Andrews 2026-03-22 21:42:55 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 11 Frédéric "LpSolit" Buclin 2026-03-22 22:29:02 CET
(In reply to Marja Van Waes from comment #4)
> > If no one maintains this package, then obsolete it, only
> > jsch-agent-proxy-trilead-ssh2 depends on it)
> 
> Remove it from the "Packages that need to be obsoleted for Mageia 10
> release" tracker (bug 32127) if it gets fixed fast. 
> 
> Else jsch-agent-proxy-trilead-ssh2 and trilead-ssh2 need to be obsoleted.

No longer blocking bug 32127.

Blocks: 32127 => (none)

Comment 12 Mageia Robot 2026-03-24 18:54:38 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0066.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.