6.5
CVE-2026-59844
- EPSS 0.53%
- Veröffentlicht 21.07.2026 11:32:16
- Zuletzt bearbeitet 01.09.2026 21:18:34
- Erkennungen
Libssh: libssh: denial of service via oversized sftp read length
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Hardened Images Version -
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.421 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-789 Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
https://access.redhat.com/security/cve/CVE-2026-59844
https://bugzilla.redhat.com/show_bug.cgi?id=2498177
https://access.redhat.com/errata/RHSA-2026:42922
https://access.redhat.com/errata/RHSA-2026:55855
https://access.redhat.com/errata/RHSA-2026:62218
https://access.redhat.com/errata/RHSA-2026:62217