CVE-2026-59842

Published: July 22, 2026Last modified: July 28, 2026

Description

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

Severity score breakdown

ParameterValue
Base score3.7
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Notes

Introduced in libssh-0.12.0 according to https://www.libssh.org/security/advisories/CVE-2026-59842.txt

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibsshNot affected (0.10.4-r0)
25 LTSlibsshNot affected (0.11.1-r0)
StreamlibsshFixed (0.12.1-r0)

References

ON THIS PAGE