6.5
CVE-2026-59844
- EPSS 0.53%
- Veröffentlicht 21.07.2026 11:32:16
- Zuletzt bearbeitet 17.08.2026 22:17:15
- CVE-Watchlists
- Unerledigt
Libssh: libssh: denial of service via oversized sftp read length
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Hardened Images Version-
Redhat ≫ Enterprise Linux Version8.0
Redhat ≫ Enterprise Linux Version9.0
Redhat ≫ Enterprise Linux Version10.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.421 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-789 Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
https://access.redhat.com/security/cve/CVE-2026-59844
https://bugzilla.redhat.com/show_bug.cgi?id=2498177
https://access.redhat.com/errata/RHSA-2026:42922
https://access.redhat.com/errata/RHSA-2026:55855