PT-2026-50527 · Libssh2+1 · Libssh2+1

·

CVE-2026-55199

·

Published

2026-06-17

·

Updated

2026-07-22

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libssh2 versions prior to 1.11.1
Description A pre-authentication denial of service issue exists in the SSH MSG EXT INFO handler within src/packet.c. A malicious SSH server can trigger a CPU exhaustion loop on the client by sending a crafted extension count value. Specifically, by setting nr extensions to 0xFFFFFFFF during key exchange, the client enters a tight CPU loop for over 60 seconds because return values from the libssh2 get string() function are unchecked and session timeouts do not apply to CPU-bound loops.
Recommendations Update to the version containing commit 1762685.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55199
ECHO-3E02-3A01-4AE3
JLSEC-2026-660
OESA-2026-3014
OESA-2026-3015
OESA-2026-3016
OPENSUSE-SU-2026:11109-1
OPENSUSE-SU-2026:21057-1
RHSA-2026:29950
SUSE-SU-2026:22284-1
SUSE-SU-2026:22364-1
SUSE-SU-2026:22438-1
SUSE-SU-2026:3074-1
SUSE-SU-2026:3076-1
SUSE-SU-2026:3082-1
USN-8486-1

Affected Products

Linuxmint
Libssh2