6.5

CVE-2026-59844

Libssh: libssh: denial of service via oversized sftp read length

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libssh ≫ Libssh Version -
Redhat ≫ Hardened Images Version -
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.421
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

https://access.redhat.com/security/cve/CVE-2026-59844
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2498177
Vendor Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:42922
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:55855
https://access.redhat.com/errata/RHSA-2026:62218
https://access.redhat.com/errata/RHSA-2026:62217