PT-2026-50528 · Libssh2+1 · Libssh2+1
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
libssh2 versions prior to 1.11.2
Description
An out-of-bounds write issue exists in the
ssh2 transport read() function due to an integer overflow and a failure to enforce upper bounds on the packet length field. A remote attacker operating a malicious SSH server can send crafted SSH packets with excessively large packet length values to trigger heap memory corruption on a connecting client. This flaw allows for remote code execution without requiring user credentials or interaction. The library is widely embedded in applications such as curl, Git, and PHP, potentially enabling service crashes, system takeover, and lateral movement via compromised jump hosts or file-transfer services.Recommendations
Update libssh2 to a version containing the fix implemented in commit 7acf3df.
Restrict outbound SSH connections to only trusted servers to minimize the risk of connecting to a malicious server.
Inventory all systems, applications, and appliances to identify bundled or static copies of libssh2 for patching.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Libssh2