Advisories ยป MGASA-2026-0425

Updated libssh packages fix security vulnerabilities

Publication date: 20 Sep 2026
Modification date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15370 , CVE-2026-59843 , CVE-2026-59844 , CVE-2026-59845 , CVE-2026-59846 , CVE-2026-59847 , CVE-2026-59848 , CVE-2026-59849 , CVE-2026-59850

Description

Stack buffer overflow in SFTP server longname construction.
(CVE-2026-15370)
Denial of service via zero advertised channel packet size.
(CVE-2026-59843)
Denial of service via oversized SFTP read length. (CVE-2026-59844)
Denial of service via unchecked ProxyCommand fork() failure.
(CVE-2026-59845)
Information disclosure via ProxyCommand %r username expansion.
(CVE-2026-59846)
Integrity downgrade via OpenSSL AES-GCM tag verification.
(CVE-2026-59847)
Denial of service via SFTP responses with unknown request IDs.
(CVE-2026-59848)
Denial of service via automatic certificate authentication loop.
(CVE-2026-59849)
Use-after-free via data callbacks on closed channels. (CVE-2026-59850)
                

References

SRPMS

10/core

9/core