6.5

CVE-2026-59844

Libssh: libssh: denial of service via oversized sftp read length

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibsshLibssh Version-
RedhatHardened Images Version-
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Version9.0
RedhatEnterprise Linux Version10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.421
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

https://access.redhat.com/security/cve/CVE-2026-59844
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2498177
Vendor Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:42922
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:55855