Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66034

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A missing bounds check in the libssh2 publickey subsystem allows malicious SSH servers to trigger a client-side out-of-bounds read, leaking heap pointers that could enable security bypasses, denial of service, or code execution.

Отчет

This Moderate impact flaw in libssh2 allows a malicious SSH server to trigger an out-of-bounds read on a connecting client. While requiring user interaction to connect to a compromised server and having high attack complexity, successful exploitation could leak heap pointers, potentially aiding in ASLR bypass and leading to arbitrary code execution or denial of service on Red Hat Hardened Images.

Меры по смягчению последствий

To mitigate this, strictly avoid connecting to untrusted SSH servers and enforce this policy using outbound network firewalls to block unknown IP addresses. For defense-in-depth, utilize OS-level memory protections and service sandboxing to contain any accidental exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Out of support scope
Red Hat Enterprise Linux 7libssh2Affected
Red Hat Hardened Imageslibssh2-main-1.11.1-10.2.hum1FixedRHSA-2026:4692727.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2506860libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read

EPSS

Процентиль: 17%
0.00254
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 дней назад

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.

CVSS3: 7.5
nvd
7 дней назад

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.

msrc
6 дней назад

libssh2 Heap Out-of-Bounds Read via publickey subsystem

CVSS3: 7.5
debian
7 дней назад

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bo ...

CVSS3: 7.5
github
7 дней назад

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.

EPSS

Процентиль: 17%
0.00254
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2026-66034