A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 2.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libssh-develUpgrade libsshUpgrade libssh-config | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade libssh | Apr 13, 2026 | Mar 26, 2026 |
| Amazon_linux_2023 | — | Upgrade libssh-debugsourceUpgrade libssh-configUpgrade libssh-develUpgrade libssh-debuginfoUpgrade libssh | Mar 27, 2026 | Feb 10, 2026 |
| Debian | — | Upgrade libssh | Aug 3, 2026 | Aug 3, 2026 |
| Redhat_linux | — | Upgrade libssh-configUpgrade libssh-debugsourceUpgrade libssh-develNo solution existsUpgrade libsshUpgrade libssh-debuginfo | May 20, 2026 | Feb 10, 2026 |
| Rocky_linux | — | Upgrade libssh-develUpgrade libssh-debugsourceUpgrade libssh-debuginfoUpgrade libssh | Jun 1, 2026 | May 28, 2026 |
| Suse | — | Upgrade libssh-develUpgrade libssh-configUpgrade libssh4-32bitUpgrade libssh4Upgrade libssh-devel-doc | Mar 4, 2026 | Feb 17, 2026 |
| Ubuntu | — | Upgrade libssh-4 (Ubuntu Pro)Upgrade libssh-4 | Feb 19, 2026 | Feb 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub