Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3330-1

Опубликовано: 28 июл. 2026
Источник: suse-cvrf

Описание

Security update for libssh

This update for libssh fixes the following issues:

  • CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164).
  • CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165).
  • CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166).
  • CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167).
  • CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168).
  • CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169).
  • CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171).

Список пакетов

Container bci/spack:latest
libssh-devel-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container private-registry/harbor-trivy-adapter:latest
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container suse/kea:2.6
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container suse/kiosk/firefox-esr:latest
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container suse/ltss/sle15.6/sle15:latest
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container suse/postgres:16
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container suse/postgres:16.14
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container suse/postgres:17
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container suse/postgres:17.10
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Container suse/postgres:latest
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
Image SLES15-SP7-BYOS-EC2
libssh-config-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
libssh-config-0.9.8-150600.11.15.1
libssh-devel-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
libssh4-32bit-0.9.8-150600.11.15.1
SUSE Linux Enterprise Server 15 SP6-LTSS
libssh-config-0.9.8-150600.11.15.1
libssh-devel-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
libssh4-32bit-0.9.8-150600.11.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
libssh-config-0.9.8-150600.11.15.1
libssh-devel-0.9.8-150600.11.15.1
libssh4-0.9.8-150600.11.15.1
libssh4-32bit-0.9.8-150600.11.15.1

Описание

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.


Затронутые продукты
Container bci/spack:latest:libssh-devel-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh4-0.9.8-150600.11.15.1
Container private-registry/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1

Ссылки

Описание

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.


Затронутые продукты
Container bci/spack:latest:libssh-devel-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh4-0.9.8-150600.11.15.1
Container private-registry/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1

Ссылки

Описание

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.


Затронутые продукты
Container bci/spack:latest:libssh-devel-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh4-0.9.8-150600.11.15.1
Container private-registry/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1

Ссылки

Описание

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.


Затронутые продукты
Container bci/spack:latest:libssh-devel-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh4-0.9.8-150600.11.15.1
Container private-registry/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1

Ссылки

Описание

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.


Затронутые продукты
Container bci/spack:latest:libssh-devel-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh4-0.9.8-150600.11.15.1
Container private-registry/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1

Ссылки

Описание

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.


Затронутые продукты
Container bci/spack:latest:libssh-devel-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh4-0.9.8-150600.11.15.1
Container private-registry/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1

Ссылки

Описание

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.


Затронутые продукты
Container bci/spack:latest:libssh-devel-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1
Container private-registry/1.2/harbor-trivy-adapter:latest:libssh4-0.9.8-150600.11.15.1
Container private-registry/harbor-trivy-adapter:latest:libssh-config-0.9.8-150600.11.15.1

Ссылки
Уязвимость SUSE-SU-2026:3330-1