Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0967

Опубликовано: 10 фев. 2026
Источник: redhat
CVSS3: 2.2
EPSS Низкий

Описание

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the match_pattern() function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

Отчет

The vulnerability in libssh has been rated as Low by Red Hat Product Security. This issue arises from inefficient pattern matching logic that may lead to excessive processing time when handling specially crafted patterns. However, these patterns originate from configuration data, meaning an attacker would need the ability to modify or influence configuration files to exploit the issue. As a result, exploitation requires local access or equivalent local privileges, and cannot be performed remotely without prior compromise. Additionally, triggering the issue depends on specific conditions during pattern evaluation, increasing the attack complexity. The impact of this flaw is limited to potential performance degradation or temporary delays due to increased CPU usage. It does not allow unauthorized access to data, modification of system state, or execution of arbitrary code.

Меры по смягчению последствий

Avoid using complex patterns in configuration files and known_hosts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Not affected
Red Hat Enterprise Linux 7libssh2Not affected
Red Hat Enterprise Linux 8libsshFix deferred
Red Hat Hardened Imageslibssh2Not affected
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10libsshFixedRHSA-2026:1816019.05.2026
Red Hat Enterprise Linux 9libsshFixedRHSA-2026:1868319.05.2026
Red Hat Enterprise Linux 9libsshFixedRHSA-2026:1868319.05.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2436981libssh: libssh: Denial of Service via inefficient regular expression processing

EPSS

Процентиль: 13%
0.00223
Низкий

2.2 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

CVSS3: 5.5
nvd
4 месяца назад

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

CVSS3: 2.2
msrc
4 месяца назад

Libssh: libssh: denial of service via inefficient regular expression processing

CVSS3: 5.5
debian
4 месяца назад

A flaw was found in libssh. A remote attacker, by controlling client c ...

CVSS3: 2.2
github
4 месяца назад

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

EPSS

Процентиль: 13%
0.00223
Низкий

2.2 Low

CVSS3