ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 16
ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 16
GHSA-mf77-5hj2-98w9
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
CVE-2026-58050
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
CVE-2026-58050
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
CVE-2026-58050
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
CVE-2026-58050
libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
CVE-2026-58050
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...
BDU:2026-08915
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ ΡΡΠ½ΠΊΡΠΈΠΈ publickey_response_success() Π±ΠΈΠ±Π»ΠΈΠΎΡΠ΅ΠΊΠΈ libssh2, ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ Π½Π°ΡΡΡΠΈΡΠ΅Π»Ρ Π²ΡΠ·Π²Π°ΡΡ ΠΎΡΠΊΠ°Π· Π² ΠΎΠ±ΡΠ»ΡΠΆΠΈΠ²Π°Π½ΠΈΠΈ ΠΈΠ»ΠΈ Π²ΡΠΏΠΎΠ»Π½ΠΈΡΡ ΠΏΡΠΎΠΈΠ·Π²ΠΎΠ»ΡΠ½ΡΠΉ ΠΊΠΎΠ΄
ROS-20260907-80-0031
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ nmap
ROS-20260907-73-0030
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ nmap
ROS-20260810-80-0021
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ libssh2
ROS-20260810-73-0034
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ libssh2
openSUSE-SU-2026:21549-1
Security update for libssh2_org
SUSE-SU-2026:4095-1
Security update for libssh2_org
SUSE-SU-2026:3541-1
Security update for libssh2_org
SUSE-SU-2026:3526-1
Security update for libssh2_org
SUSE-SU-2026:3525-1
Security update for libssh2_org
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ | CVSS | EPSS | ΠΠΏΡΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ | |
|---|---|---|---|---|
GHSA-mf77-5hj2-98w9 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 3 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |
CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 3 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |
CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 3 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |
CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 3 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |
CVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 3 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | ||
CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ... | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 3 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |
BDU:2026-08915 Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ ΡΡΠ½ΠΊΡΠΈΠΈ publickey_response_success() Π±ΠΈΠ±Π»ΠΈΠΎΡΠ΅ΠΊΠΈ libssh2, ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ Π½Π°ΡΡΡΠΈΡΠ΅Π»Ρ Π²ΡΠ·Π²Π°ΡΡ ΠΎΡΠΊΠ°Π· Π² ΠΎΠ±ΡΠ»ΡΠΆΠΈΠ²Π°Π½ΠΈΠΈ ΠΈΠ»ΠΈ Π²ΡΠΏΠΎΠ»Π½ΠΈΡΡ ΠΏΡΠΎΠΈΠ·Π²ΠΎΠ»ΡΠ½ΡΠΉ ΠΊΠΎΠ΄ | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 3 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |
ROS-20260907-80-0031 Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ nmap | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 13 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |
ROS-20260907-73-0030 Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ nmap | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 13 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |
ROS-20260810-80-0021 Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ libssh2 | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 1 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |
ROS-20260810-73-0034 Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ libssh2 | CVSS3: 7 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 1 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |
openSUSE-SU-2026:21549-1 Security update for libssh2_org | ΠΎΠΊΠΎΠ»ΠΎ 1 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2026:4095-1 Security update for libssh2_org | 10 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2026:3541-1 Security update for libssh2_org | ΠΎΠΊΠΎΠ»ΠΎ 1 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2026:3526-1 Security update for libssh2_org | ΠΎΠΊΠΎΠ»ΠΎ 1 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2026:3525-1 Security update for libssh2_org | ΠΎΠΊΠΎΠ»ΠΎ 1 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ |
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ