Bugs fixes in "libssh2"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| CVE | CVE-2026-66035 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server | 2026-09-03 |
| CVE | CVE-2026-66033 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in | 2026-09-03 |
| CVE | CVE-2026-66032 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicio | 2026-09-03 |
| CVE | CVE-2026-66035 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server | 2026-09-03 |
| CVE | CVE-2026-66033 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in | 2026-09-03 |
| CVE | CVE-2026-66032 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicio | 2026-09-03 |
| CVE | CVE-2026-66035 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server | 2026-09-03 |
| CVE | CVE-2026-66033 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in | 2026-09-03 |
| CVE | CVE-2026-66032 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicio | 2026-09-03 |
| CVE | CVE-2026-66035 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server | 2026-09-03 |
| CVE | CVE-2026-66033 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in | 2026-09-03 |
| CVE | CVE-2026-66032 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicio | 2026-09-03 |
| CVE | CVE-2026-58050 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attr | 2026-07-13 |
| CVE | CVE-2026-58051 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse | 2026-07-13 |
| CVE | CVE-2026-5805 | A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.p | 2026-07-13 |
| CVE | CVE-2026-58050 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attr | 2026-07-13 |
| CVE | CVE-2026-58051 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse | 2026-07-13 |
| CVE | CVE-2026-5805 | A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.p | 2026-07-13 |
| CVE | CVE-2026-58050 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attr | 2026-07-13 |
| CVE | CVE-2026-58051 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse | 2026-07-13 |
About
-
Send Feedback to @ubuntu_updates