Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7598

Опубликовано: 01 мая 2026
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.

A flaw was found in the libssh2 library. A remote attacker can exploit an integer overflow vulnerability in the userauth_password function by manipulating the username_len or password_len arguments and cause a heap-based buffer overflow. This leads to a crash to the application linked to the library and potentially allows arbitrary code execution.

Отчет

To exploit this flaw, an attacker needs to be able to supply an excessively large value to the arguments of the userauth_password function, typically to an application processing untrusted SSH authentication requests. The primary security impact of this issue is a crash to the application linked to the library due to memory corruption, potentially allowing arbitrary code execution. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to these reasons, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

To mitigate this flaw, applications linked to the libssh2 library should be configured or updated to exclusively use public key authentication. Explicitly disabling password-based logins prevents the application from executing the vulnerable userauth_password function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Will not fix
Red Hat Enterprise Linux 7libssh2Affected
Red Hat OpenShift Container Platform 4conmon-rsNot affected
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Not affected
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Affected
Red Hat Hardened Imagesrust-main-1.95.0-5.hum1FixedRHSA-2026:1673613.05.2026
Red Hat Hardened Imageslibssh2-main-1.11.1-5.1.hum1FixedRHSA-2026:702108.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2464597libssh2: integer overflow via large username or password arguments

EPSS

Процентиль: 38%
0.00466
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.

CVSS3: 7.3
nvd
3 месяца назад

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.

CVSS3: 7.3
msrc
3 месяца назад

libssh2 userauth.c userauth_password integer overflow

CVSS3: 7.3
debian
3 месяца назад

A security vulnerability has been detected in libssh2 up to 1.11.1. Th ...

CVSS3: 7.3
github
3 месяца назад

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.

EPSS

Процентиль: 38%
0.00466
Низкий

9.1 Critical

CVSS3