rpm package
opensuse/libssh&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/libssh&distro=openSUSE%20Leap%2016.0
Vulnerabilities (9)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-59850 | Med | 4.3 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. | |
| CVE-2026-59849 | Low | 3.1 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. | |
| CVE-2026-59848 | Med | 5.3 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. | |
| CVE-2026-59847 | Med | 5.9 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection. | |
| CVE-2026-59846 | Low | 3.9 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. | |
| CVE-2026-59845 | Med | 5.3 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. | |
| CVE-2026-59844 | Med | 6.5 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. | |
| CVE-2026-59843 | Med | 6.5 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. | |
| CVE-2026-15370 | Med | 6.7 | < 0.11.5-160000.1.1 | 0.11.5-160000.1.1 | Jul 21, 2026 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buf |
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
- affected < 0.11.5-160000.1.1fixed 0.11.5-160000.1.1
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buf