Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58050

Опубликовано: 28 июн. 2026
Источник: nvd
CVSS3: 7
CVSS3: 7.5
EPSS Низкий

Описание

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*
Версия до 1.11.1 (включая)

EPSS

Процентиль: 26%
0.00333
Низкий

7 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7
ubuntu
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

CVSS3: 7
redhat
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

msrc
около 1 месяца назад

libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation

CVSS3: 7
debian
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...

CVSS3: 7
github
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

EPSS

Процентиль: 26%
0.00333
Низкий

7 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-190