Home / mailings [USN-8799-1] libssh2 vulnerabilities
Posted on 22 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8799-1
September 22, 2026
libssh2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in libssh2.
Software Description:
- libssh2: Client-side C library implementing the SSH2 protocol
Details:
It was discovered that libssh2 incorrectly handled certain publickey
subsystem attributes. A remote attacker controlling a malicious SSH server
could use this issue to cause a denial of service or possibly execute
arbitrary code.
(CVE-2026-58050)
It was discovered that libssh2 did not properly initialize publickey list
entries before parsing. A remote attacker controlling a malicious SSH
server could use this issue to cause a denial of service or possibly
execute arbitrary code. (CVE-2026-58051)
It was discovered that libssh2 incorrectly handled certain SFTP server
responses. A remote attacker controlling an SSH server could use this issue
to cause libssh2 to crash or possibly execute arbitrary code.
(CVE-2026-66032)
It was discovered that libssh2 did not properly check bounds in certain
publickey subsystem responses. A remote attacker controlling a malicious
SSH server could use this issue to cause a denial of service or possibly
execute arbitrary code.. (CVE-2026-66034)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
libssh2-1 1.10.0-3ubuntu0.1
libssh2-1-dev 1.10.0-3ubuntu0.1
Ubuntu 20.04 LTS
libssh2-1 1.8.0-2.1ubuntu0.1+esm1
Available with Ubuntu Pro
libssh2-1-dev 1.8.0-2.1ubuntu0.1+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libssh2-1 1.8.0-1ubuntu0.1+esm1
Available with Ubuntu Pro
libssh2-1-dev 1.8.0-1ubuntu0.1+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libssh2-1 1.5.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
libssh2-1-dev 1.5.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libssh2-1 1.4.3-2ubuntu0.2+esm4
Available with Ubuntu Pro
libssh2-1-dev 1.4.3-2ubuntu0.2+esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8799-1
CVE-2026-58050, CVE-2026-58051, CVE-2026-66032, CVE-2026-66034
Package Information:
https://launchpad.net/ubuntu/+source/libssh2/1.10.0-3ubuntu0.1
--===============6930977527501699356==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
