Updated libssh2 packages fix security vulnerabilities
Publication date: 20 Jul 2026Modification date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-15661 , CVE-2026-7598 , CVE-2026-55199 , CVE-2026-55200 , CVE-2026-58050 , CVE-2026-58051
Description
The updated packages fix security vulnerabilities:
Heap Buffer Over-read via sftp_symlink() in sftp.c. (CVE-2025-15661)
libssh2 userauth.c userauth_password integer overflow. (CVE-2026-7598)
Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler. (CVE-2026-55199)
Out-of-Bounds Write via Unchecked packet_length in transport.c.
(CVE-2026-55200)
Integer Overflow in publickey Subsystem Attribute Allocation.
(CVE-2026-58050)
Free of Uninitialized Pointer in publickey List Cleanup.
(CVE-2026-58051)
References
- https://bugs.mageia.org/show_bug.cgi?id=35616
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NRU63FODXZBBO73NFWUI32A2A36ETDQZ/
- https://www.openwall.com/lists/oss-security/2026/06/23/10
- https://www.openwall.com/lists/oss-security/2026/06/23/11
- https://lists.debian.org/debian-security-announce/2026/msg00276.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZREI4LITT4U2ZXPEEVVNALFKPLXGLAFM/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/SRBHQ76PA4ZHTWY5F4ESYPYF3G2NLGWI/
- https://ubuntu.com/security/notices/USN-8486-1
- https://ubuntu.com/security/notices/USN-8532-1
- https://www.cve.org/CVERecord?id=CVE-2025-15661
- https://www.cve.org/CVERecord?id=CVE-2026-7598
- https://www.cve.org/CVERecord?id=CVE-2026-55199
- https://www.cve.org/CVERecord?id=CVE-2026-55200
- https://www.cve.org/CVERecord?id=CVE-2026-58050
- https://www.cve.org/CVERecord?id=CVE-2026-58051
SRPMS
10/core
- libssh2-1.11.1-2.1.mga10
9/core
- libssh2-1.11.0-1.1.mga9