libssh-0.10.4-19.el9_8
エラータID: AXSA:2026-1751:03
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.
Security Fix(es):
* libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843)
* libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844)
* libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845)
* libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846)
* libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847)
* libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848)
* libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-59843
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
CVE-2026-59844
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
CVE-2026-59845
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
CVE-2026-59846
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
CVE-2026-59847
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
CVE-2026-59848
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
CVE-2026-59850
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
Update packages.
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
N/A
SRPMS
- libssh-0.10.4-19.el9_8.src.rpm
MD5: 5f481d7bcc8592fca78fbdbd04874b7d
SHA-256: b853f3f437e4b9cde708572434765589d2d7498d74cb11437db5c2f724b277ba
Size: 701.25 kB
Asianux Server 9 for x86_64
- libssh-0.10.4-19.el9_8.i686.rpm
MD5: 2a20d87026bcb4817676893f27430ec8
SHA-256: cb34b1dcf71e78dfbb4ef31446e2752490d1d89c27262566c6934e70ba4071d1
Size: 230.31 kB - libssh-0.10.4-19.el9_8.x86_64.rpm
MD5: 202910d2293620749d15c2f5613d37f8
SHA-256: 796057c654046b969e91fda4a7ab83372664e6b289f32191a9b67b961b48c801
Size: 214.07 kB - libssh-config-0.10.4-19.el9_8.noarch.rpm
MD5: c6e39c1a180e252e92e4fb37aaaf4423
SHA-256: 4fbde8b9d1d0ac5931f132200f7243ec035a17a54a76af78fd875fc8cf61cdce
Size: 8.21 kB - libssh-devel-0.10.4-19.el9_8.i686.rpm
MD5: 4f71b2e5f25f5c3d02467bf70712ee6f
SHA-256: 75c38088b626547856ae34adca1ede0cfb612d8f860ba3c5b882bfbbf397d2f5
Size: 37.81 kB - libssh-devel-0.10.4-19.el9_8.x86_64.rpm
MD5: fd4c8752e658748706d8781932d39621
SHA-256: b595d9198bea94614af9322083dd8268a57cd8f6cc96f630944e98a68bf95289
Size: 37.81 kB