Home / mailingsPDF  

[USN-8699-1] libssh vulnerabilities

Posted on 31 August 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8699-1
August 31, 2026

libssh vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in libssh.

Software Description:
- libssh: A tiny C SSH library

Details:

It was discovered that libssh had a stack buffer overflow in its SFTP
server when constructing directory listing entries for long filenames. An
attacker could possibly use this issue to cause libssh to crash or execute
arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15370)

It was discovered that libssh did not correctly handle SSH channel open
messages advertising a zero maximum packet size. An authenticated remote
attacker could possibly use this issue to cause libssh to consume excessive
CPU resources, leading to a denial of service. (CVE-2026-59843)

It was discovered that libssh did not correctly limit SFTP read request
lengths in its server implementation. An authenticated remote attacker
could possibly use this issue to cause libssh to allocate excessive memory,
leading to a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-59844)

It was discovered that libssh did not correctly handle ProxyCommand fork()
failures. A local attacker could possibly use this issue to cause a denial
of service. (CVE-2026-59845)

It was discovered that libssh did not correctly sanitize shell
metacharacters when expanding usernames in ProxyCommand strings. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-59846)

It was discovered that libssh had incorrect AES-GCM tag verification when
built with the OpenSSL backend. A machine-in-the-middle attacker could
possibly use this issue to modify encrypted traffic without detection.
(CVE-2026-59847)

It was discovered that libssh did not correctly handle SFTP server
responses for unknown request IDs. An attacker could possibly use this
issue to cause libssh to use excessive memory, leading to a denial of
service. (CVE-2026-59848)

It was discovered that libssh had logic errors in certificate-based
authentication that could cause clients to loop indefinitely when
certificates were rejected. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-59849)

It was discovered that libssh could invoke data callbacks on channels after
they had been closed. An attacker could possibly use this issue to cause
libssh to crash or execute arbitrary code. (CVE-2026-59850)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libssh-4 0.11.3-1ubuntu2.1

Ubuntu 24.04 LTS
libssh-4 0.10.6-2ubuntu0.5

Ubuntu 22.04 LTS
libssh-4 0.9.6-2ubuntu0.22.04.8

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8699-1
CVE-2026-15370, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845,
CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849,
CVE-2026-59850

Package Information:
https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1
https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5
https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8

--===============2922738565303980865==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP