SECURITY UPDATE: fix integer overflow in username_len bounds checks across userauth_list, userauth_password and password change paths in src/userauth.c
debian/patches/CVE-2026-7598.patch: fix integer overflow in username_len bounds checks across userauth_list, userauth_password and password change paths in src/userauth.c