{"schema_version":"1.7.2","id":"OESA-2026-3321","modified":"2026-08-13T13:57:25Z","published":"2026-08-13T13:57:25Z","upstream":["CVE-2026-59843","CVE-2026-59844","CVE-2026-59845","CVE-2026-59847","CVE-2026-59850"],"summary":"libssh security update","details":"The ssh library was designed to be used by programmers needing a working SSH implementation by the mean of a library. The complete control of the client is made by the programmer. With libssh, you can remotely execute programs, transfer files, use a secure and transparent tunnel for your remote programs. With its Secure FTP implementation, you can play with remote files easily, without third-party programs others than libcrypto (from openssl).\r\n\r\nSecurity Fix(es):\n\nA flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.(CVE-2026-59843)\n\nA flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.(CVE-2026-59844)\n\nA flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller&apos;s accessible process tree, leading to local denial of service.(CVE-2026-59845)\n\nA flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.(CVE-2026-59847)\n\nA flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.(CVE-2026-59850)","affected":[{"package":{"ecosystem":"openEuler:20.03-LTS-SP4","name":"libssh","purl":"pkg:rpm/openEuler/libssh&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.4-21.oe2003sp4"}]}],"ecosystem_specific":{"aarch64":["libssh-0.9.4-21.oe2003sp4.aarch64.rpm","libssh-debuginfo-0.9.4-21.oe2003sp4.aarch64.rpm","libssh-debugsource-0.9.4-21.oe2003sp4.aarch64.rpm","libssh-devel-0.9.4-21.oe2003sp4.aarch64.rpm"],"noarch":["libssh-help-0.9.4-21.oe2003sp4.noarch.rpm"],"src":["libssh-0.9.4-21.oe2003sp4.src.rpm"],"x86_64":["libssh-0.9.4-21.oe2003sp4.x86_64.rpm","libssh-debuginfo-0.9.4-21.oe2003sp4.x86_64.rpm","libssh-debugsource-0.9.4-21.oe2003sp4.x86_64.rpm","libssh-devel-0.9.4-21.oe2003sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3321"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59843"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59844"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59845"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59847"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59850"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"database_specific":{"severity":"High"}}
