Описание
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
Отчет
This Moderate flaw in libssh client-side ProxyCommand handling can lead to a local denial of service. When ProxyCommand is configured, an unchecked fork() failure may result in signals being sent across the process tree, disrupting local system availability. This issue specifically impacts environments utilizing ProxyCommand functionality.
Меры по смягчению последствий
To mitigate this issue, avoid using the ProxyCommand feature in libssh client configurations. This prevents the vulnerable code path from being exercised, thereby eliminating the risk of local denial of service due to unchecked fork() failures.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libssh | Affected | ||
| Red Hat Enterprise Linux 8 | libssh | Fix deferred | ||
| Red Hat Enterprise Linux 9 | libssh | Fix deferred | ||
| Red Hat Hardened Images | libssh-main-0.12.1-4.hum1 | Fixed | RHSA-2026:42922 | 21.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
Libssh: libssh: denial of service via unchecked proxycommand fork() failure
A flaw was found in libssh. When ProxyCommand is used, an unchecked fo ...
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
EPSS
5.3 Medium
CVSS3