Issued at: 2026-08-18
Updated at: 2026-08-19
Advisory content derived from Red Hat RHSA-2026:55855, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: libssh security update
Description
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.
Security Fix(es):
* libssh: libssh: information disclosure via short GSSAPI Curve25519 public key (CVE-2026-59842)
* libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843)
* libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844)
* libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845)
* libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846)
* libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847)
* libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848)
* libssh: libssh: denial of service via automatic certificate authentication loop (CVE-2026-59849)
* libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850)
* libssh: libssh: authentication bypass via missing GSSAPI principal check (CVE-2026-59851)
* libssh: libssh: stack buffer overflow in SFTP server longname construction (CVE-2026-15370)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.