Issued at: 2026-09-02
Updated at: 2026-09-03
Advisory content derived from Red Hat RHSA-2026:62218, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Moderate: libssh security update
Description
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.
Security Fix(es):
* libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843)
* libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844)
* libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845)
* libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846)
* libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847)
* libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848)
* libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.