Количество 16
Количество 16
BDU:2026-08974
Уязвимость функции libssh2_publickey_list_fetch() библиотеки libssh2, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260907-80-0030
Уязвимость nmap
ROS-20260907-73-0029
Уязвимость nmap
ROS-20260810-80-0020
Уязвимость libssh2
ROS-20260810-73-0033
Уязвимость libssh2
CVE-2026-58051
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
CVE-2026-58051
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
CVE-2026-58051
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
CVE-2026-58051
libssh2 - Free of Uninitialized Pointer in publickey List Cleanup
CVE-2026-58051
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ...
GHSA-c5f3-hwj2-xp5p
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
openSUSE-SU-2026:21549-1
Security update for libssh2_org
SUSE-SU-2026:4095-1
Security update for libssh2_org
SUSE-SU-2026:3541-1
Security update for libssh2_org
SUSE-SU-2026:3526-1
Security update for libssh2_org
SUSE-SU-2026:3525-1
Security update for libssh2_org
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-08974 Уязвимость функции libssh2_publickey_list_fetch() библиотеки libssh2, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
ROS-20260907-80-0030 Уязвимость nmap | CVSS3: 6.5 | 0% Низкий | 13 дней назад | |
ROS-20260907-73-0029 Уязвимость nmap | CVSS3: 6.5 | 0% Низкий | 13 дней назад | |
ROS-20260810-80-0020 Уязвимость libssh2 | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260810-73-0033 Уязвимость libssh2 | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58051 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-58051 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-58051 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-58051 libssh2 - Free of Uninitialized Pointer in publickey List Cleanup | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-58051 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ... | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-c5f3-hwj2-xp5p libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21549-1 Security update for libssh2_org | около 1 месяца назад | |||
SUSE-SU-2026:4095-1 Security update for libssh2_org | 10 дней назад | |||
SUSE-SU-2026:3541-1 Security update for libssh2_org | около 1 месяца назад | |||
SUSE-SU-2026:3526-1 Security update for libssh2_org | около 1 месяца назад | |||
SUSE-SU-2026:3525-1 Security update for libssh2_org | около 1 месяца назад |
Уязвимостей на страницу