CVE-2026-0966
EUVD-2026-1633026.03.2026, 21:17
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libssh | libssh | 𝑥 < 0.11.4 |
| redhat | hardened_images | - |
| redhat | openshift_container_platform | 4.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| libssh-config |
| ||||||||
| libssh-devel |
| ||||||||
| libssh4 |
| ||||||||
| libssh4-32bit |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| libssh |
| ||
| libssh-config |
| ||
| libssh-debuginfo |
| ||
| libssh-debugsource |
| ||
| libssh-devel |
|
Common Weakness Enumeration
References