A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libssh-develUpgrade libssh-configUpgrade libssh | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade libssh | Apr 13, 2026 | Mar 26, 2026 |
| Amazon_linux_2023 | — | Upgrade libssh-develUpgrade libsshUpgrade libssh-configUpgrade libssh-debuginfoUpgrade libssh-debugsource | Mar 16, 2026 | Feb 10, 2026 |
| Debian | — | Upgrade libssh | Aug 3, 2026 | Aug 3, 2026 |
| Redhat_linux | — | Upgrade libssh-configUpgrade libssh-debugsourceUpgrade libssh-debuginfoNo solution existsUpgrade libsshUpgrade libssh-devel | May 20, 2026 | Feb 10, 2026 |
| Rocky_linux | — | Upgrade libssh-develUpgrade libssh-debuginfoUpgrade libsshUpgrade libssh-debugsource | Jun 1, 2026 | May 28, 2026 |
| Suse | — | Upgrade libssh-devel-docUpgrade libssh4Upgrade libssh-develUpgrade libssh4-32bitUpgrade libssh-config | Mar 4, 2026 | Feb 17, 2026 |
| Ubuntu | — | Upgrade libssh-4Upgrade libssh-4 (Ubuntu Pro) | Feb 19, 2026 | Feb 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub