5.3

CVE-2026-59848

Libssh: libssh: denial of service via sftp responses with unknown request ids

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibsshLibssh Version-
RedhatHardened Images Version-
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Version9.0
RedhatEnterprise Linux Version10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.241
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://access.redhat.com/security/cve/CVE-2026-59848
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2498181
Vendor Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:42922
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:55855