High severity8.8NVD Advisory· Published Jul 24, 2026· Updated Aug 7, 2026
CVE-2026-66032
CVE-2026-66032
Description
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/libssh2_org&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libssh2_org&distro=openSUSE%20Tumbleweed
< 1.11.1-160000.5.1+ 1 more
- (no CPE)range: < 1.11.1-160000.5.1
- (no CPE)range: < 1.11.1-4.1
Patches
Vulnerability mechanics
References
3- github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0nvdPatch
- github.com/libssh2/libssh2/pull/2180nvdIssue TrackingPatch
- www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-opennvdPatchThird Party Advisory
News mentions
3- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- libssh2 Vulnerabilities Allow a Malicious SSH Server to Corrupt Client MemoryCyber Security News · Jul 28, 2026
- Libssh2: Three Vulnerabilities Disclosed Together Affecting SFTP and Cipher NegotiationVypr Intelligence · Jul 25, 2026