Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0965

Опубликовано: 10 фев. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.

Меры по смягчению последствий

Ensure the client and server are using only regular files as configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsshAffected
Red Hat Enterprise Linux 6libssh2Not affected
Red Hat Enterprise Linux 7libssh2Not affected
Red Hat Enterprise Linux 8libsshFix deferred
Red Hat Enterprise Linux 9libsshAffected
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=2436980libssh: libssh: Denial of Service via improper configuration file handling

EPSS

Процентиль: 3%
0.00014
Низкий

3.3 Low

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

[Denial of Service via improper configuration file handling]

debian

[Denial of Service via improper configuration file handling]

CVSS3: 3.3
github
4 дня назад

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.

suse-cvrf
27 дней назад

Security update for libssh

suse-cvrf
27 дней назад

Security update for libssh

EPSS

Процентиль: 3%
0.00014
Низкий

3.3 Low

CVSS3