Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59845

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

Отчет

This Moderate flaw in libssh client-side ProxyCommand handling can lead to a local denial of service. When ProxyCommand is configured, an unchecked fork() failure may result in signals being sent across the process tree, disrupting local system availability. This issue specifically impacts environments utilizing ProxyCommand functionality.

Меры по смягчению последствий

To mitigate this issue, avoid using the ProxyCommand feature in libssh client configurations. This prevents the vulnerable code path from being exercised, thereby eliminating the risk of local denial of service due to unchecked fork() failures.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsshAffected
Red Hat Enterprise Linux 8libsshFix deferred
Red Hat Enterprise Linux 9libsshFix deferred
Red Hat Hardened Imageslibssh-main-0.12.1-4.hum1FixedRHSA-2026:4292221.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2498178libssh: libssh: denial of service via unchecked ProxyCommand fork() failure

EPSS

Процентиль: 1%
0.00106
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
12 дней назад

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

CVSS3: 5.3
nvd
12 дней назад

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

msrc
8 дней назад

Libssh: libssh: denial of service via unchecked proxycommand fork() failure

CVSS3: 5.3
debian
12 дней назад

A flaw was found in libssh. When ProxyCommand is used, an unchecked fo ...

CVSS3: 5.3
github
12 дней назад

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

EPSS

Процентиль: 1%
0.00106
Низкий

5.3 Medium

CVSS3