Home / mailingsPDF  

[USN-8799-1] libssh2 vulnerabilities

Posted on 22 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8799-1
September 22, 2026

libssh2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in libssh2.

Software Description:
- libssh2: Client-side C library implementing the SSH2 protocol

Details:

It was discovered that libssh2 incorrectly handled certain publickey
subsystem attributes. A remote attacker controlling a malicious SSH server
could use this issue to cause a denial of service or possibly execute
arbitrary code.
(CVE-2026-58050)

It was discovered that libssh2 did not properly initialize publickey list
entries before parsing. A remote attacker controlling a malicious SSH
server could use this issue to cause a denial of service or possibly
execute arbitrary code. (CVE-2026-58051)

It was discovered that libssh2 incorrectly handled certain SFTP server
responses. A remote attacker controlling an SSH server could use this issue
to cause libssh2 to crash or possibly execute arbitrary code.
(CVE-2026-66032)

It was discovered that libssh2 did not properly check bounds in certain
publickey subsystem responses. A remote attacker controlling a malicious
SSH server could use this issue to cause a denial of service or possibly
execute arbitrary code.. (CVE-2026-66034)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
libssh2-1 1.10.0-3ubuntu0.1
libssh2-1-dev 1.10.0-3ubuntu0.1

Ubuntu 20.04 LTS
libssh2-1 1.8.0-2.1ubuntu0.1+esm1
Available with Ubuntu Pro
libssh2-1-dev 1.8.0-2.1ubuntu0.1+esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libssh2-1 1.8.0-1ubuntu0.1+esm1
Available with Ubuntu Pro
libssh2-1-dev 1.8.0-1ubuntu0.1+esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libssh2-1 1.5.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
libssh2-1-dev 1.5.0-2ubuntu0.1+esm3
Available with Ubuntu Pro

Ubuntu 14.04 LTS
libssh2-1 1.4.3-2ubuntu0.2+esm4
Available with Ubuntu Pro
libssh2-1-dev 1.4.3-2ubuntu0.2+esm4
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8799-1
CVE-2026-58050, CVE-2026-58051, CVE-2026-66032, CVE-2026-66034

Package Information:
https://launchpad.net/ubuntu/+source/libssh2/1.10.0-3ubuntu0.1

--===============6930977527501699356==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP