Skip to content

Commit 8872416

Browse files
committed
2025.88 changelog
1 parent e5a0ef2 commit 8872416

File tree

3 files changed

+34
-1
lines changed

3 files changed

+34
-1
lines changed

CHANGES

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,30 @@
1+
2025.88 - 7 May 2025
2+
3+
- Security: Don't allow dbclient hostname arguments to be interpreted
4+
by the shell.
5+
6+
dbclient hostname arguments with a comma (for multihop) would be
7+
passed to the shell which could result in running arbitrary shell
8+
commands locally. That could be a security issue in situations
9+
where dbclient is passed untrusted hostname arguments.
10+
11+
Now the multihop command is executed directly, no shell is involved.
12+
Thanks to Marcin Nowak for the report, tracked as CVE-2025-47203
13+
14+
- Fix compatibility for htole64 and htole32, regression in 2025.87
15+
Patch from Peter Fichtner to work with old GCC versions, and
16+
patch from Matt Robinson to check different header files.
17+
18+
- Fix building on older compilers or libc that don't support
19+
static_assert(). Regression in 2025.87
20+
21+
- Support ~R in the client to force a key re-exchange.
22+
23+
- Improve strict KEX handling. Dropbear previously would allow other
24+
packets at the end of key exchange prior to receiving the remote
25+
peer's NEWKEYS message, which should be forbidden by strict KEX.
26+
Reported by Fabian Bäumer.
27+
128
2025.87 - 5 March 2025
229

330
Note >> for compatibility/configuration changes

debian/changelog

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,9 @@
1+
dropbear (2025.88-0.1) unstable; urgency=low
2+
3+
* New upstream release.
4+
5+
-- Matt Johnston <matt@ucc.asn.au> Wed, 7 May 2025 22:51:57 +0800
6+
17
dropbear (2025.87-0.1) unstable; urgency=low
28

39
* New upstream release.

src/sysoptions.h

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
*******************************************************************/
55

66
#ifndef DROPBEAR_VERSION
7-
#define DROPBEAR_VERSION "2025.87"
7+
#define DROPBEAR_VERSION "2025.88"
88
#endif
99

1010
/* IDENT_VERSION_PART is the optional part after "SSH-2.0-dropbear". Refer to RFC4253 for requirements. */

0 commit comments

Comments
 (0)