Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59842

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

Меры по смягчению последствий

Disable GSSAPIKeyExchange or remove gss-curve25519-sha256- from GSSAPIKexAlgorithms if appropriate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsshAffected
Red Hat Enterprise Linux 8libsshNot affected
Red Hat Enterprise Linux 9libsshNot affected
Red Hat Hardened Imageslibssh-main-0.12.1-4.hum1FixedRHSA-2026:4292221.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2498168libssh: libssh: information disclosure via short GSSAPI Curve25519 public key

EPSS

Процентиль: 35%
0.0042
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
13 дней назад

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

CVSS3: 3.7
nvd
13 дней назад

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

CVSS3: 3.7
debian
13 дней назад

A flaw was found in libssh. During server-side GSSAPI key exchange, a ...

CVSS3: 3.7
github
13 дней назад

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

EPSS

Процентиль: 35%
0.0042
Низкий

3.7 Low

CVSS3