Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15370

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

Меры по смягчению последствий

No workaround available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsshAffected
Red Hat Enterprise Linux 8libsshNot affected
Red Hat Enterprise Linux 9libsshNot affected
Red Hat Hardened Imageslibssh-main-0.12.2-1.hum1FixedRHSA-2026:4776829.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2499049libssh: libssh: stack buffer overflow in SFTP server longname construction

EPSS

Процентиль: 5%
0.00157
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
28 дней назад

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

CVSS3: 6.7
nvd
28 дней назад

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

CVSS3: 6.7
debian
28 дней назад

A flaw was found in libssh. During SFTP server directory listing, the ...

CVSS3: 6.7
github
28 дней назад

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

suse-cvrf
24 дня назад

Security update for libssh

EPSS

Процентиль: 5%
0.00157
Низкий

6.7 Medium

CVSS3