A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.
CVSS Details
- CVSS 3.0 Base Score: 3.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libsshUpgrade libssh-configUpgrade libssh-devel | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade libssh | Apr 13, 2026 | Mar 26, 2026 |
| Amazon_linux_2023 | — | Upgrade libsshUpgrade libssh-debuginfoUpgrade libssh-configUpgrade libssh-debugsourceUpgrade libssh-devel | Jun 23, 2026 | Feb 10, 2026 |
| Debian | — | Upgrade libssh | Aug 3, 2026 | Aug 3, 2026 |
| Redhat_linux | — | Upgrade libssh-configUpgrade libssh-debugsourceUpgrade libssh-develUpgrade libsshNo solution existsUpgrade libssh-debuginfo | May 20, 2026 | Feb 10, 2026 |
| Rocky_linux | — | Upgrade libssh-debugsourceUpgrade libsshUpgrade libssh-develUpgrade libssh-debuginfo | Jun 1, 2026 | May 28, 2026 |
| Suse | — | Upgrade libssh-configUpgrade libssh-develUpgrade libssh-devel-docUpgrade libssh4-32bitUpgrade libssh4 | Mar 4, 2026 | Feb 17, 2026 |
| Ubuntu | — | Upgrade libssh-4Upgrade libssh-4 (Ubuntu Pro) | Feb 19, 2026 | Feb 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub