libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
CVSS Details
- CVSS 4.0 Base Score: 8.3 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libssh2-docsUpgrade libssh2Upgrade libssh2-debuginfoUpgrade libssh2-devel | Jul 22, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade libssh2Upgrade libssh2-docsUpgrade libssh2-debuginfoUpgrade libssh2-debugsourceUpgrade libssh2-devel | Jul 21, 2026 | Jun 28, 2026 |
| Debian | — | Upgrade libssh2 | Sep 21, 2026 | Jun 28, 2026 |
| Redhat_linux | — | Upgrade libssh2Upgrade libssh2-develUpgrade libssh2-docsNo solution existsUpgrade libssh2-debuginfo | Jul 17, 2026 | Jun 28, 2026 |
| Ubuntu | — | Upgrade libssh2-1t64 | Jul 13, 2026 | Jun 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub