[ALSA-2026:18683] Moderate: libssh security update
Type:
security
Severity:
moderate
Release date:
2026-05-26
Description:
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications. Security Fix(es): * libssh: Double Free Vulnerability in libssh Key Export Functions (CVE-2025-5351) * libssh: Use of uninitialized variable in privatekey_from_file() (CVE-2025-4878) * libssh: Write beyond bounds in binary to base64 conversion functions (CVE-2025-4877) * libssh: NULL Pointer Dereference in libssh KEX Session ID Calculation (CVE-2025-8114) * libssh: Memory Exhaustion via Repeated Key Exchange in libssh (CVE-2025-8277) * libssh: Buffer underflow in ssh_get_hexa() on invalid input (CVE-2026-0966) * libssh: Improper sanitation of paths received from SCP servers (CVE-2026-0964) * libssh: libssh: Denial of Service via improper configuration file handling (CVE-2026-0965) * libssh: libssh: Denial of Service via inefficient regular expression processing (CVE-2026-0967) * libssh: libssh: Denial of Service due to malformed SFTP message (CVE-2026-0968) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinuxRelease Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libssh-0.10.4-18.el9.aarch64.rpm b791991849786ef16905a0449a30e97195e12798b621afd55b2dfba3f5c9562b
aarch64 libssh-devel-0.10.4-18.el9.aarch64.rpm d2d5253e9979501d620cae239e164c1975afb17cc3bf9ffdc008c2117e292dae
i686 libssh-devel-0.10.4-18.el9.i686.rpm 07fffb6d73d775f1f6a9e34204dde88ece182a3c410172666b536110a05ebcc4
i686 libssh-0.10.4-18.el9.i686.rpm 13095e4f8ada0c6a3f6eaf6ae7ff6407838daeac25d4c4760fe0475f188b5226
noarch libssh-config-0.10.4-18.el9.noarch.rpm 7330cdae173ed5151e36fa6a59a51ccf183102daa3bb599f1b37e35a090bbe48
ppc64le libssh-devel-0.10.4-18.el9.ppc64le.rpm 329d7b84a0230b2487350a1f113c05d0714224f3a4a4ab91ba528776d73e86e0
ppc64le libssh-0.10.4-18.el9.ppc64le.rpm 6a065d5fb8ed42c03658f43ebd5c6acc02d1e704186b299cdea49e6d2cea7d64
s390x libssh-0.10.4-18.el9.s390x.rpm 099db658cd840182c8d9ba90d278f0ebe3355006a9754fbe2ba4f60a2ce9206e
s390x libssh-devel-0.10.4-18.el9.s390x.rpm bce951983a08a23ae8cf9294e6b8790ecaea754005a0291fb065e524553d563a
x86_64 libssh-0.10.4-18.el9.x86_64.rpm 5f932919a42d87de5fa7ce38d53d31eceb6e7fcc5f93e02cff28dce406fafc5c
x86_64 libssh-devel-0.10.4-18.el9.x86_64.rpm 787439250b21c37053233165934ad62e9661784962d874655dff0aca714ee6da
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.