Описание
[Denial of Service via improper configuration file handling]
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libssh | fixed | 0.12.0-1 | package | |
| libssh | no-dsa | trixie | package | |
| libssh | no-dsa | bookworm | package | |
| libssh | postponed | bullseye | package |
Примечания
https://www.libssh.org/security/advisories/CVE-2026-0965.txt
Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=bf390a042623e02abc8f421c4c5fadc0429a8a76 (libssh-0.11.4)
EPSS
Связанные уязвимости
[Denial of Service via improper configuration file handling]
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.
EPSS