libssh-0.9.6-17.el8_10
エラータID: AXSA:2026-1742:02
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.
Security Fix(es):
* libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843)
* libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844)
* libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845)
* libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846)
* libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847)
* libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848)
* libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-59843
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
CVE-2026-59844
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
CVE-2026-59845
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
CVE-2026-59846
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
CVE-2026-59847
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
CVE-2026-59848
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
CVE-2026-59850
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
Update packages.
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
N/A
SRPMS
- libssh-0.9.6-17.el8_10.src.rpm
MD5: 8b0f1c62496756c4ce2466cff018b89f
SHA-256: b033fee3b056c9a014271fb28035e58ac54919188af4c0ff867da99ac50a78a7
Size: 1.11 MB
Asianux Server 8 for x86_64
- libssh-0.9.6-17.el8_10.i686.rpm
MD5: 0c2266b7873caf6cadab8a9ce3e6e96c
SHA-256: 55fe164c26394ea6c7c700388c049ed7c1b643492f6aaeb09f8527d5ec5a357c
Size: 240.09 kB - libssh-0.9.6-17.el8_10.x86_64.rpm
MD5: d689c1dddf349704346ebbe6ca3545d7
SHA-256: 4e9a477e2c303221bf7eeb9ceea1ed1c30ee3c563c7e37afb8d314311961c85c
Size: 220.32 kB - libssh-config-0.9.6-17.el8_10.noarch.rpm
MD5: cbf456df168182e73a25a5e3c9c55d6f
SHA-256: 77707a36f48e05cf6af58fc9acadaad034ec66bfe9c8d9d6edd2b86c6a6f903c
Size: 20.45 kB - libssh-devel-0.9.6-17.el8_10.i686.rpm
MD5: 18b9ec2af711bda33a4818fdc8a64eee
SHA-256: f3dde24e8540821dcf7a843f2b7e1fc8f842403db5b1a58b2e2babd6f6e7496d
Size: 443.17 kB - libssh-devel-0.9.6-17.el8_10.x86_64.rpm
MD5: cae03666a66de5a25821e74068b9543f
SHA-256: 4f601bb8683b87b012f8ad1d9cb9ff9989b7dde4d3fdc7e05e82e70d15d32cf6
Size: 443.15 kB