digint / digint/btrbk

btrbk security release v0.32.7

Open
#654 1 comment 0 reactions 0 assignees View on GitHub
announcement
Dominant language
Perl
Stars
2.1k
Forks
139
PR merge metrics
No merged PRs in 30d

Description

The btrbk release v0.32.7 fixes a critical security vulnerability (CVE-2026-62943) in "ssh_filter_btrbk.sh", see:
- https://github.com/digint/btrbk/security/advisories/GHSA-pf45-7g54-65h5
- https://github.com/digint/btrbk/releases/tag/v0.32.7

**All users using ssh_filter_btrbk.sh in their authorized_keys configurations should upgrade immediately**

The fix was also merged to master (v0.33.0-dev).

Note that the CVE I got assigned for the github advisory was removed again (after I filled in the missing links), so I requested a CVE again. I hope it will update to the same number (CVE-2026-62943) I referenced in the ChangeLog.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading ssh_filter_btrbk.sh and the linked v0.32.7 release and security advisory. The issue does not define a new implementation task: the vulnerability fix is already released and merged to master, so any follow-up would need to be clarified before work begins.

Written by the indexing model from the issue text.

Assessment

Tech stack
perl, shell
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.