UbuntuUpdates.org

Bugs fixes in "libssh"

Origin Bug number Title Date fixed
CVE CVE-2026-59850 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data 2026-09-01
CVE CVE-2026-59848 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing 2026-09-01
CVE CVE-2026-59847 A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al 2026-09-01
CVE CVE-2026-59846 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment v 2026-09-01
CVE CVE-2026-59845 A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b 2026-09-01
CVE CVE-2026-59843 A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write 2026-09-01
CVE CVE-2026-59850 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data 2026-09-01
CVE CVE-2026-59848 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing 2026-09-01
CVE CVE-2026-59847 A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al 2026-09-01
CVE CVE-2026-59846 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment v 2026-09-01
CVE CVE-2026-59845 A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b 2026-09-01
CVE CVE-2026-59843 A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write 2026-09-01
CVE CVE-2026-59850 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data 2026-09-01
CVE CVE-2026-59849 A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when 2026-09-01
CVE CVE-2026-59848 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing 2026-09-01
CVE CVE-2026-59847 A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al 2026-09-01
CVE CVE-2026-59846 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment v 2026-09-01
CVE CVE-2026-59845 A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b 2026-09-01
CVE CVE-2026-59844 A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP ser 2026-09-01
CVE CVE-2026-59843 A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write 2026-09-01



About   -   Send Feedback to @ubuntu_updates