Описание
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libssh | fixed | 0.12.2-1 | package |
Примечания
https://www.libssh.org/2026/07/28/libssh-0-12-2-security-release/
https://www.libssh.org/security/advisories/CVE-2026-59843.txt
Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=3f785905760d2e2a87037285ab85b37b9924e409 (libssh-0.12.2)
Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=006ddd503566ee13e00db42bc111e898388f8664 (libssh-0.12.2)
EPSS
Связанные уязвимости
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Libssh: libssh: denial of service via zero advertised channel packet size
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
EPSS