libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.
CVSS Details
- CVSS 4.0 Base Score: 7.7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libssh2-docsUpgrade libssh2Upgrade libssh2-debugsourceUpgrade libssh2-develUpgrade cargo-c-debuginfoUpgrade libssh2-debuginfoUpgrade rust-cargo-c-debugsourceUpgrade cargo-c | Aug 18, 2026 | Jul 24, 2026 |
| Debian | — | Upgrade libssh2 | Sep 21, 2026 | Jul 24, 2026 |
| Redhat_linux | — | Upgrade libssh2-docsUpgrade libssh2Upgrade libssh2-debuginfoNo solution existsUpgrade libssh2-devel | Jul 29, 2026 | Jul 24, 2026 |
| Ubuntu | — | Upgrade libssh2-1-devUpgrade libssh2-1 (Ubuntu Pro)Upgrade libssh2-1-dev (Ubuntu Pro)Upgrade libssh2-1 | Sep 2, 2026 | Jul 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub