[ALSA-2026:55855] Important: libssh security update
Type:
security
Severity:
important
Release date:
2026-08-18
Description:
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications. Security Fix(es): * libssh: libssh: information disclosure via short GSSAPI Curve25519 public key (CVE-2026-59842) * libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843) * libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844) * libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845) * libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846) * libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847) * libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848) * libssh: libssh: denial of service via automatic certificate authentication loop (CVE-2026-59849) * libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850) * libssh: libssh: authentication bypass via missing GSSAPI principal check (CVE-2026-59851) * libssh: libssh: stack buffer overflow in SFTP server longname construction (CVE-2026-15370) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libssh-0.12.0-3.el10_2.aarch64.rpm 08a7eb28a828dbfe8a6fa875caa9d2652648cd6ce2faefeaefea8216996cec28
aarch64 libssh-devel-0.12.0-3.el10_2.aarch64.rpm 142fad30e98dc27dc7e7f71391326a207e449309717cc1bacfad2b63f5a7ab18
noarch libssh-config-0.12.0-3.el10_2.noarch.rpm 42473901905bfd812bc9f2ddd5acb2b88e2b135c977f8b3f96f1c8052c50c3d2
ppc64le libssh-devel-0.12.0-3.el10_2.ppc64le.rpm 116074b67ddf6edb58dd70fb0131f47fd0b8965316bcd78ab36c8ba447007347
ppc64le libssh-0.12.0-3.el10_2.ppc64le.rpm 36845d0955b1257c9efe8266ea235774afc45108bbeb6aabf4d836cc6d30dc27
s390x libssh-devel-0.12.0-3.el10_2.s390x.rpm 16fc93f0aaba5f3e674ad5c9e96385fca35c88794e8328d91bd48398b4d674ce
s390x libssh-0.12.0-3.el10_2.s390x.rpm e7eb7897940b1b0c3ecef014bb59214fe384ced6b2daee540b9705f7fad34349
x86_64 libssh-0.12.0-3.el10_2.x86_64.rpm 242906aab857e57f71b6637ef53618110a18b2cb02c9fcdd4728c9da1a205e0f
x86_64 libssh-devel-0.12.0-3.el10_2.x86_64.rpm e4ac68d4ccd2ec01bcf448d5e424717fa959d2b24742bad7af61b895b6f1af41
x86_64_v2 libssh-devel-0.12.0-3.el10_2.x86_64_v2.rpm cf889169a138c1d2fe2a780dbecef2c94ee338f4bea052c8ec705aec8df146db
x86_64_v2 libssh-0.12.0-3.el10_2.x86_64_v2.rpm e5703f2dc176f26a12f6168203d2d0813db112ae8fe0d4680de5e22d75233d71
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.