CVE-2026-59845

Published: July 22, 2026Last modified: July 29, 2026

Description

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

Severity score breakdown

ParameterValue
Base score5.9
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibsshFixed (0.11.5-r0)
25 LTSlibsshFixed (0.11.5-r0)
StreamlibsshFixed (0.12.1-r0)

References

ON THIS PAGE