Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58050

Опубликовано: 28 июн. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

A flaw in libssh2 allows a malicious SSH server to trigger a memory overflow by sending a manipulated attribute count. This can cause the connecting client to crash or allow unauthorized code execution.

Отчет

This Moderate impact flaw in libssh2 allows a malicious SSH server to trigger a heap buffer overflow in a connecting client. By manipulating the publickey-subsystem response, an attacker could cause an integer overflow, potentially leading to denial of service or arbitrary code execution on Red Hat systems using libssh2 to establish SSH connections. Note: Red Hat Enterprise Linux (RHEL) 8 and newer are not affected by this flaw, as they do not ship the libssh2 package.

Меры по смягчению последствий

To mitigate this issue,ensure your applications are running strictly on 64-bit architectures, which naturally prevents the integer overflow from occurring. Additionally, configure your applications to connect only to trusted, verified SSH servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Out of support scope
Red Hat Enterprise Linux 7libssh2Affected
Red Hat Hardened Imageslibssh2Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2493955libssh2: libssh2: Heap buffer overflow via integer overflow in publickey attribute allocation

EPSS

Процентиль: 29%
0.00361
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

CVSS3: 7
nvd
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

msrc
около 1 месяца назад

libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation

CVSS3: 7
debian
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...

CVSS3: 7
github
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

EPSS

Процентиль: 29%
0.00361
Низкий

7 High

CVSS3