Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59848

Опубликовано: 21 июл. 2026
Источник: debian

Описание

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsshfixed0.12.1-1package

Примечания

  • https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/

  • https://www.libssh.org/security/advisories/CVE-2026-59848.txt

  • Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=9563afc950f473daa355ca594e2e5f4d520460ac (libssh-0.12.1)

  • Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=e3dc89de9754790e49b26f03b70e8e4acc88bde8 (libssh-0.12.1)

Связанные уязвимости

CVSS3: 5.3
ubuntu
12 дней назад

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.

CVSS3: 5.3
redhat
12 дней назад

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.

CVSS3: 5.3
nvd
12 дней назад

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.

msrc
8 дней назад

Libssh: libssh: denial of service via sftp responses with unknown request ids

CVSS3: 5.3
github
12 дней назад

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.