Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59847

Опубликовано: 21 июл. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsshfixed0.12.1-1package

Примечания

  • https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/

  • https://www.libssh.org/security/advisories/CVE-2026-59847.txt

  • Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074 (libssh-0.12.1)

  • Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9 (libssh-0.12.1)

EPSS

Процентиль: 23%
0.00304
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
12 дней назад

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

CVSS3: 5.9
redhat
12 дней назад

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

CVSS3: 5.9
nvd
12 дней назад

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

msrc
8 дней назад

Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification

CVSS3: 5.9
github
12 дней назад

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

EPSS

Процентиль: 23%
0.00304
Низкий