Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59842

Опубликовано: 21 июл. 2026
Источник: debian

Описание

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsshfixed0.12.1-1package
libsshnot-affectedtrixiepackage
libsshnot-affectedbookwormpackage
libsshnot-affectedbullseyepackage

Примечания

  • https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/

  • https://www.libssh.org/security/advisories/CVE-2026-59842.txt

  • Introduced with: https://git.libssh.org/projects/libssh.git/commit/?id=88c2ea6752fab7b3da9cc4c51eaf632361a44080 (libssh-0.12.0)

  • Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=5568ae6c5a1adcb008d044985fe5f1d1567bc610 (libssh-0.12.1)

Связанные уязвимости

CVSS3: 3.7
ubuntu
13 дней назад

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

CVSS3: 3.7
redhat
13 дней назад

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

CVSS3: 3.7
nvd
13 дней назад

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

CVSS3: 3.7
github
13 дней назад

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.