Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66032

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in libssh2. A malicious SSH (Secure Shell) server can exploit a double-free vulnerability in the sftp_open() function. This flaw allows the server to corrupt the heap memory of an authenticated client when it opens an SFTP (SSH File Transfer Protocol) session. This heap corruption can lead to arbitrary code execution on the client system, giving the attacker control over the affected system.

Отчет

Moderate: A double-free vulnerability in libssh2 allows a malicious SSH server to corrupt the heap of an authenticated client during an SFTP session. This flaw requires user interaction, as a client must connect to a specially crafted server and initiate an SFTP transfer, which can lead to arbitrary code execution on the client system.

Меры по смягчению последствий

Restrict your libssh2 clients to connect only to fully trusted, internal SFTP servers to eliminate exposure to malicious server responses. Additionally, configure dependent applications with Restart=on-failure in systemd so RHEL's glibc memory protections can safely crash and auto-recover the process during an attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Out of support scope
Red Hat Enterprise Linux 7libssh2Affected
Red Hat Hardened Imageslibssh2-main-1.11.1-10.2.hum1FixedRHSA-2026:4692727.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2506857libssh2: libssh2: Arbitrary code execution via double-free in SFTP session

EPSS

Процентиль: 21%
0.00288
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
7 дней назад

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.

CVSS3: 8.8
nvd
7 дней назад

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.

msrc
6 дней назад

libssh2 Double-Free Heap Corruption via sftp_open()

CVSS3: 8.8
debian
7 дней назад

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-fre ...

CVSS3: 8.8
github
7 дней назад

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.

EPSS

Процентиль: 21%
0.00288
Низкий

6.5 Medium

CVSS3