A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
CVSS Details
- CVSS 3.1 Base Score: 3.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libssh-develUpgrade libssh-configUpgrade libssh | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade libssh | Apr 13, 2026 | Mar 26, 2026 |
| Amazon_linux_2023 | — | Upgrade libssh-debugsourceUpgrade libssh-configUpgrade libsshUpgrade libssh-debuginfoUpgrade libssh-devel | May 4, 2026 | Feb 10, 2026 |
| Debian | — | Upgrade libssh | Aug 3, 2026 | Aug 3, 2026 |
| Redhat_linux | — | No solution existsUpgrade libsshUpgrade libssh-develUpgrade libssh-debugsourceUpgrade libssh-configUpgrade libssh-debuginfo | May 20, 2026 | Feb 10, 2026 |
| Rocky_linux | — | Upgrade libssh-debugsourceUpgrade libssh-develUpgrade libsshUpgrade libssh-debuginfo | Jun 1, 2026 | May 28, 2026 |
| Suse | — | Upgrade libssh-configUpgrade libssh-devel-docUpgrade libssh-develUpgrade libssh4-32bitUpgrade libssh4 | Mar 4, 2026 | Feb 17, 2026 |
| Ubuntu | — | Upgrade libssh-4 (Ubuntu Pro)Upgrade libssh-4 | Feb 19, 2026 | Feb 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub