Количество 16
Количество 16
CVE-2026-55199
libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.
CVE-2026-55199
libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.
CVE-2026-55199
libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.
CVE-2026-55199
libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler
CVE-2026-55199
libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authen ...
SUSE-SU-2026:3082-1
Security update for libssh2_org
SUSE-SU-2026:3076-1
Security update for libssh2_org
SUSE-SU-2026:3074-1
Security update for libssh2_org
ROS-20260907-80-0002
Уязвимость nmap
ROS-20260907-73-0002
Уязвимость nmap
ROS-20260810-80-0017
Уязвимость libssh2
ROS-20260810-73-0030
Уязвимость libssh2
GHSA-3cfq-4xx4-rmpg
libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.
BDU:2026-14976
Уязвимость функции _libssh2_packet_add() компонента src/packet.c библиотеки реализации протокола SSH2 Libssh2, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2026:21057-1
Security update for libssh2_org
SUSE-SU-2026:3525-1
Security update for libssh2_org
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55199 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops. | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
CVE-2026-55199 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops. | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
CVE-2026-55199 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops. | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
CVE-2026-55199 libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
CVE-2026-55199 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authen ... | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
SUSE-SU-2026:3082-1 Security update for libssh2_org | 1% Низкий | 2 месяца назад | ||
SUSE-SU-2026:3076-1 Security update for libssh2_org | 1% Низкий | 2 месяца назад | ||
SUSE-SU-2026:3074-1 Security update for libssh2_org | 1% Низкий | 2 месяца назад | ||
ROS-20260907-80-0002 Уязвимость nmap | CVSS3: 7.5 | 1% Низкий | 17 дней назад | |
ROS-20260907-73-0002 Уязвимость nmap | CVSS3: 7.5 | 1% Низкий | 17 дней назад | |
ROS-20260810-80-0017 Уязвимость libssh2 | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
ROS-20260810-73-0030 Уязвимость libssh2 | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
GHSA-3cfq-4xx4-rmpg libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops. | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
BDU:2026-14976 Уязвимость функции _libssh2_packet_add() компонента src/packet.c библиотеки реализации протокола SSH2 Libssh2, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
openSUSE-SU-2026:21057-1 Security update for libssh2_org | 3 месяца назад | |||
SUSE-SU-2026:3525-1 Security update for libssh2_org | около 2 месяцев назад |
Уязвимостей на страницу