• src/ssh/crypto/botan.cpp src/ssh/deucessh-portable.h src/ssh/kex/curve

    From Deuc¿@VERT to Git commit to main/sbbs/master on Thu Aug 6 18:13:29 2026
    https://gitlab.synchro.net/main/sbbs/-/commit/47feab1e8bf776175b44f40d
    Modified Files:
    src/ssh/crypto/botan.cpp src/ssh/deucessh-portable.h src/ssh/kex/curve25519-sha256.c dh-gex-sha256.c hybrid-pq-kex.c sntrup761.c src/ssh/key_algo/rsa-sha2-256-botan.c rsa-sha2-256-botan.cpp rsa-sha2-256-openssl.c rsa-sha2-512-botan.c rsa-sha2-512-botan.cpp rsa-sha2-512-openssl.c ssh-ed25519-botan.cpp ssh-ed25519-openssl.c src/ssh/ssh-auth.c ssh-conn.c ssh-trans.c
    Log Message:
    Harden buffer bounds checks

    Use a shared subtraction-based bounds helper when parsing
    peer-controlled SSH strings, packets, KEX messages, and key/signature
    blobs.

    Guard related size calculations and truncated KEX reads so 32-bit
    builds cannot wrap offsets before validation.

    Co-Authored-By: OpenAI Codex <noreply@openai.com>

    ---
    þ Synchronet þ Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net