Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59849

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 3.1

Описание

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.

Меры по смягчению последствий

Do not connect to untrusted SSH servers and do not use certificates until patched.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsshFix deferred
Red Hat Enterprise Linux 8libsshNot affected
Red Hat Enterprise Linux 9libsshNot affected
Red Hat Hardened Imageslibssh-main-0.12.1-4.hum1FixedRHSA-2026:4292221.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2498182libssh: libssh: denial of service via automatic certificate authentication loop

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
13 дней назад

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.

CVSS3: 3.1
nvd
13 дней назад

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.

CVSS3: 3.1
debian
13 дней назад

A flaw was found in libssh. Logic errors in automatic certificate-base ...

CVSS3: 3.1
github
13 дней назад

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.

suse-cvrf
9 дней назад

Security update for libssh

3.1 Low

CVSS3