Search CVE reports


Toggle filters

11 – 20 of 57 results


CVE-2026-0966

Low priority
Fixed

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-0965

Low priority
Fixed

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-0964

Medium priority
Fixed

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-8277

Low priority

Some fixes available 5 of 6

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory....

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-8114

Low priority
Fixed

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-5987

Medium priority
Fixed

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context....

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-5449

Medium priority
Fixed

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-5372

Medium priority

Some fixes available 4 of 7

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Ignored Ignored
Show less packages

CVE-2025-5351

Medium priority
Fixed

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-4878

Medium priority
Fixed

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Fixed
Show less packages