Описание
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an SSH_FXP_NAME message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
Отчет
The vulnerability in libssh has been rated as Low by Red Hat Product Security. This issue affects the libssh client when processing responses from an SFTP server. Successful exploitation requires a user to initiate a connection to a malicious or compromised SFTP server and perform specific operations, such as listing directory contents. As a result, exploitation is not possible without user interaction. Additionally, the vulnerability depends on specially crafted protocol responses from a malicious server, increasing the attack complexity and reducing the likelihood of successful exploitation in typical deployments. The impact of this flaw is limited to a client-side denial-of-service condition, such as an application crash. There is no evidence that this issue can be leveraged to execute arbitrary code, access sensitive information, or modify data. Due to the requirement for user interaction, higher attack complexity, and limited impact on availability only, Red Hat considers this vulnerability to have a lower risk.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libssh2 | Not affected | ||
| Red Hat Enterprise Linux 7 | libssh2 | Not affected | ||
| Red Hat Enterprise Linux 8 | libssh | Fix deferred | ||
| Red Hat Hardened Images | libssh2 | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | libssh | Fixed | RHSA-2026:18160 | 19.05.2026 |
| Red Hat Enterprise Linux 9 | libssh | Fixed | RHSA-2026:18683 | 19.05.2026 |
| Red Hat Enterprise Linux 9 | libssh | Fixed | RHSA-2026:18683 | 19.05.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
Libssh: libssh: denial of service due to malformed sftp message
A flaw was found in libssh in which a malicious SFTP (SSH File Transfe ...
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
EPSS
3.1 Low
CVSS3