Updated libssh2 packages fix security vulnerabilities
Publication date: 14 Sep 2026Modification date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66032 , CVE-2026-66033 , CVE-2026-66035
Description
Double-Free Heap Corruption via sftp_open(). (CVE-2026-66032)
Integer Underflow DoS via AES-GCM Cipher Negotiation. (CVE-2026-66033)
Heap Buffer Overflow via ETM Cipher Negotiation. (CVE-2026-66035)
References
SRPMS
10/core
- libssh2-1.11.1-2.2.mga10
9/core
- libssh2-1.11.0-1.2.mga9