Release date:
2026-09-09 08:38:19 UTC
Description:
* SECURITY UPDATE: unchecked userauth input lengths let crafted username,
password, hostname, method-name or public-key sizes wrap the packet-size
arithmetic and produce an undersized heap allocation that is then
overflowed
- debian/patches/CVE-2026-7598.patch: cap every caller-supplied userauth
input at MAX_INPUT_LEN before the allocation size is computed and
return LIBSSH2_ERROR_OUT_OF_BOUNDARY instead, in userauth_list(),
userauth_password(), userauth_hostbased_fromfile(),
_libssh2_userauth_publickey() and userauth_keyboard_interactive() in
src/userauth.c
- CVE-2026-7598
Updated packages:
-
libssh2-1_1.9.0-2+deb11u1+tuxcare.els1_amd64.deb
sha:0750da30ea5e109898cab7b1dd8144212d52c13c
-
libssh2-1-dev_1.9.0-2+deb11u1+tuxcare.els1_amd64.deb
sha:5ddb5723676b18832817e16a3fbe1d7f69df60f3
-
libssh2-1_1.9.0-2+deb11u1+tuxcare.els1_arm64.deb
sha:d5480adc80128ccc90ade269f5860ec265520538
-
libssh2-1-dev_1.9.0-2+deb11u1+tuxcare.els1_arm64.deb
sha:eda5b8f852c181f18ea35e9fa13a7c5f1f10f45d
-
libssh2-1_1.9.0-2+deb11u1+tuxcare.els1_armel.deb
sha:55f5582394077d2a9f422068f0e0632494e2f06e
-
libssh2-1-dev_1.9.0-2+deb11u1+tuxcare.els1_armel.deb
sha:afa83d5d0bc5382bcf58358dc6e8f2f8600853dc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.