PT-2026-50786 · Libssh2 · Libssh2
Joshua Rogers
+1
·
Published
2026-06-18
·
Updated
2026-06-18
·
CVE-2025-15661
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H |
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH FXP NAME response. Attackers can supply a link len value larger than the actual packet data in SSH FXP NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libssh2