Описание
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
Меры по смягчению последствий
Disable the aes128-gcm@openssh.com and aes256-gcm@openssh.com ciphers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libssh | Affected | ||
| Red Hat Enterprise Linux 8 | libssh | Affected | ||
| Red Hat Enterprise Linux 9 | libssh | Affected | ||
| Red Hat Hardened Images | libssh-main-0.12.1-4.hum1 | Fixed | RHSA-2026:42922 | 21.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
A flaw was found in libssh. Incorrect AES-GCM finalization checks in b ...
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
EPSS
5.9 Medium
CVSS3