7.5

CVE-2026-59847

Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibsshLibssh Version-
RedhatHardened Images Version-
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Version9.0
RedhatEnterprise Linux Version10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.241
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
RedHat 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-1310 Missing Ability to Patch ROM Code

Missing an ability to patch ROM code may leave a System or System-on-Chip (SoC) in a vulnerable state.

CWE-253 Incorrect Check of Function Return Value

The product incorrectly checks a return value from a function, which prevents it from detecting errors or exceptional conditions.

https://access.redhat.com/security/cve/CVE-2026-59847
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2498180
Vendor Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:42922
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:55855