A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libssh | Jul 29, 2026 | Jul 21, 2026 |
| Debian | — | Upgrade libssh | Aug 3, 2026 | Aug 3, 2026 |
| Redhat_linux | — | Upgrade libssh-develUpgrade libssh-debuginfoUpgrade libssh-configUpgrade libsshUpgrade libssh-debugsource | Jul 23, 2026 | Jul 21, 2026 |
| Rocky_linux | — | Upgrade libssh-develUpgrade libssh-debugsourceUpgrade libssh-debuginfoUpgrade libssh | Aug 20, 2026 | Aug 18, 2026 |
| Ubuntu | — | Upgrade libssh-4 | Aug 31, 2026 | Aug 31, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub