Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0968

Опубликовано: 10 фев. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an SSH_FXP_NAME message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

Отчет

The vulnerability in libssh has been rated as Low by Red Hat Product Security. This issue affects the libssh client when processing responses from an SFTP server. Successful exploitation requires a user to initiate a connection to a malicious or compromised SFTP server and perform specific operations, such as listing directory contents. As a result, exploitation is not possible without user interaction. Additionally, the vulnerability depends on specially crafted protocol responses from a malicious server, increasing the attack complexity and reducing the likelihood of successful exploitation in typical deployments. The impact of this flaw is limited to a client-side denial-of-service condition, such as an application crash. There is no evidence that this issue can be leveraged to execute arbitrary code, access sensitive information, or modify data. Due to the requirement for user interaction, higher attack complexity, and limited impact on availability only, Red Hat considers this vulnerability to have a lower risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Not affected
Red Hat Enterprise Linux 7libssh2Not affected
Red Hat Enterprise Linux 8libsshFix deferred
Red Hat Hardened Imageslibssh2Not affected
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10libsshFixedRHSA-2026:1816019.05.2026
Red Hat Enterprise Linux 9libsshFixedRHSA-2026:1868319.05.2026
Red Hat Enterprise Linux 9libsshFixedRHSA-2026:1868319.05.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2436982libssh: libssh: Denial of Service due to malformed SFTP message

EPSS

Процентиль: 36%
0.00442
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
4 месяца назад

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

CVSS3: 3.1
nvd
4 месяца назад

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

CVSS3: 3.1
msrc
4 месяца назад

Libssh: libssh: denial of service due to malformed sftp message

CVSS3: 3.1
debian
4 месяца назад

A flaw was found in libssh in which a malicious SFTP (SSH File Transfe ...

CVSS3: 3.1
github
4 месяца назад

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

EPSS

Процентиль: 36%
0.00442
Низкий

3.1 Low

CVSS3