[CLSA-2026:1788943086] Fix CVE(s): CVE-2026-7598
Type:
security
Severity:
Critical
Release date:
2026-09-09 08:38:19 UTC
Description:
* SECURITY UPDATE: unchecked userauth input lengths let crafted username, password, hostname, method-name or public-key sizes wrap the packet-size arithmetic and produce an undersized heap allocation that is then overflowed - debian/patches/CVE-2026-7598.patch: cap every caller-supplied userauth input at MAX_INPUT_LEN before the allocation size is computed and return LIBSSH2_ERROR_OUT_OF_BOUNDARY instead, in userauth_list(), userauth_password(), userauth_hostbased_fromfile(), _libssh2_userauth_publickey() and userauth_keyboard_interactive() in src/userauth.c - CVE-2026-7598
CVEs fixed:
Updated packages:
  • libssh2-1_1.9.0-2+deb11u1+tuxcare.els1_amd64.deb
    sha:0750da30ea5e109898cab7b1dd8144212d52c13c
  • libssh2-1-dev_1.9.0-2+deb11u1+tuxcare.els1_amd64.deb
    sha:5ddb5723676b18832817e16a3fbe1d7f69df60f3
  • libssh2-1_1.9.0-2+deb11u1+tuxcare.els1_arm64.deb
    sha:d5480adc80128ccc90ade269f5860ec265520538
  • libssh2-1-dev_1.9.0-2+deb11u1+tuxcare.els1_arm64.deb
    sha:eda5b8f852c181f18ea35e9fa13a7c5f1f10f45d
  • libssh2-1_1.9.0-2+deb11u1+tuxcare.els1_armel.deb
    sha:55f5582394077d2a9f422068f0e0632494e2f06e
  • libssh2-1-dev_1.9.0-2+deb11u1+tuxcare.els1_armel.deb
    sha:afa83d5d0bc5382bcf58358dc6e8f2f8600853dc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.