{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2026/cve-2026-58051-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-02T00:25:59Z",
      "generator": {
        "date": "2026-07-02T00:25:58Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-58051-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2026-06-28T01:32:00Z",
      "revision_history": [
        {
          "date": "2026-06-28T01:32:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-01T12:36:07Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-02T00:25:59Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-58051"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-1-0:1.8.0-2.1+deb10u1.amd64",
                "product": {
                  "name": "libssh2-1-0:1.8.0-2.1+deb10u1.amd64",
                  "product_id": "libssh2-1-0:1.8.0-2.1+deb10u1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/libssh2-1@1.8.0-2.1%2Bdeb10u1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64",
                "product": {
                  "name": "libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64",
                  "product_id": "libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/libssh2-1-dev@1.8.0-2.1%2Bdeb10u1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
                "product": {
                  "name": "libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
                  "product_id": "libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssh2-1@1.8.0-2.1%2Bdeb10u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
                "product": {
                  "name": "libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
                  "product_id": "libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssh2-1-dev@1.8.0-2.1%2Bdeb10u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64"
        },
        "product_reference": "libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64"
        },
        "product_reference": "libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-0:1.8.0-2.1+deb10u1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssh2-1-0:1.8.0-2.1+deb10u1.amd64"
        },
        "product_reference": "libssh2-1-0:1.8.0-2.1+deb10u1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64"
        },
        "product_reference": "libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-58051",
      "cwe": {
        "id": "CWE-824",
        "name": "Access of Uninitialized Pointer"
      },
      "notes": [
        {
          "category": "description",
          "text": "libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
          "Debian-10:libssh2-1-0:1.8.0-2.1+deb10u1.amd64",
          "Debian-10:libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
          "Debian-10:libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-58051"
        }
      ],
      "release_date": "2026-06-28T01:32:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-01T23:19:25.145993Z",
          "details": "This is a client-side flaw limited to libssh2’s optional RFC 4819 publickey management subsystem: it is only reachable when an application explicitly invokes libssh2_publickey_* APIs against a malicious SSH server, and routine SSH auth/exec/SCP/SFTP flows do not use this code path. The condition is triggered on a parse-failure cleanup path and primarily results in an invalid free of an uninitialized pointer, making the realistic outcome a client-process crash (availability) with no integrity impact and at most low confidentiality exposure. Given these narrow preconditions and the high attack complexity, it is reasonable to deprioritize in managed enterprise systems that do not use the publickey subsystem.",
          "product_ids": [
            "Debian-10:libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
            "Debian-10:libssh2-1-0:1.8.0-2.1+deb10u1.amd64",
            "Debian-10:libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
            "Debian-10:libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Debian-10:libssh2-1-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
            "Debian-10:libssh2-1-0:1.8.0-2.1+deb10u1.amd64",
            "Debian-10:libssh2-1-dev-0:1.8.0-2.1+deb10u1+tuxcare.els1.amd64",
            "Debian-10:libssh2-1-dev-0:1.8.0-2.1+deb10u1.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}