Updated libssh packages fix security vulnerabilities
Publication date: 20 Sep 2026Modification date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15370 , CVE-2026-59843 , CVE-2026-59844 , CVE-2026-59845 , CVE-2026-59846 , CVE-2026-59847 , CVE-2026-59848 , CVE-2026-59849 , CVE-2026-59850
Description
Stack buffer overflow in SFTP server longname construction.
(CVE-2026-15370)
Denial of service via zero advertised channel packet size.
(CVE-2026-59843)
Denial of service via oversized SFTP read length. (CVE-2026-59844)
Denial of service via unchecked ProxyCommand fork() failure.
(CVE-2026-59845)
Information disclosure via ProxyCommand %r username expansion.
(CVE-2026-59846)
Integrity downgrade via OpenSSL AES-GCM tag verification.
(CVE-2026-59847)
Denial of service via SFTP responses with unknown request IDs.
(CVE-2026-59848)
Denial of service via automatic certificate authentication loop.
(CVE-2026-59849)
Use-after-free via data callbacks on closed channels. (CVE-2026-59850)
References
- https://bugs.mageia.org/show_bug.cgi?id=35983
- https://www.openwall.com/lists/oss-security/2026/07/21/7
- https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIVTLBAG4MPX3WGPMVYDO2UPZB6G3ESR/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YZ324UUCGQ4JEC4ZOJMJODWYVPSFBWUU/
- https://lists.debian.org/debian-security-announce/2026/msg00321.html
- https://ubuntu.com/security/notices/USN-8699-1
- https://www.cve.org/CVERecord?id=CVE-2026-15370
- https://www.cve.org/CVERecord?id=CVE-2026-59843
- https://www.cve.org/CVERecord?id=CVE-2026-59844
- https://www.cve.org/CVERecord?id=CVE-2026-59845
- https://www.cve.org/CVERecord?id=CVE-2026-59846
- https://www.cve.org/CVERecord?id=CVE-2026-59847
- https://www.cve.org/CVERecord?id=CVE-2026-59848
- https://www.cve.org/CVERecord?id=CVE-2026-59849
- https://www.cve.org/CVERecord?id=CVE-2026-59850
SRPMS
10/core
- libssh-0.11.5-1.mga10
9/core
- libssh-0.10.6-1.3.mga9