PT-2026-61858 · Red Hat · Red Hat Enterprise Linux 10+3

CVE-2026-59843

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH MSG CHANNEL OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-59843

Affected Products

Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Red Hat Hardened Images