A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
CVSS Details
- CVSS 3.1 Base Score: 3.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libsshUpgrade libssh-configUpgrade libssh-devel | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade libssh | Apr 13, 2026 | Mar 26, 2026 |
| Amazon_linux_2023 | — | Upgrade libsshUpgrade libssh-debugsourceUpgrade libssh-configUpgrade libssh-develUpgrade libssh-debuginfo | May 4, 2026 | Feb 10, 2026 |
| Debian | — | Upgrade libssh | Aug 3, 2026 | Aug 3, 2026 |
| Redhat_linux | — | Upgrade libssh-debugsourceUpgrade libssh-debuginfoUpgrade libssh-configUpgrade libssh-develUpgrade libsshNo solution exists | May 20, 2026 | Feb 10, 2026 |
| Rocky_linux | — | Upgrade libssh-develUpgrade libssh-debugsourceUpgrade libsshUpgrade libssh-debuginfo | Jun 1, 2026 | May 28, 2026 |
| Suse | — | Upgrade libssh-develUpgrade libssh4-32bitUpgrade libssh-devel-docUpgrade libssh4Upgrade libssh-config | Mar 4, 2026 | Feb 17, 2026 |
| Ubuntu | — | Upgrade libssh-4 (Ubuntu Pro)Upgrade libssh-4 | Feb 19, 2026 | Feb 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub