CVE-2026-58051

EUVD-2026-39971
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 36.37%
Affected Products (NVD)
VendorProductVersion
libssh2libssh2
𝑥
≤ 1.11.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libssh2
bookworm
undetermined
bullseye
undetermined
forky
undetermined
sid
undetermined
trixie
undetermined
trixie (security)
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libssh2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
Fixed 1.11.0-4.1ubuntu0.24.04.3
released
questing
ignored
resolute
Fixed 1.11.1-1ubuntu0.26.04.3
released
trusty
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libssh2-1
suse enterprise desktop 15 SP7
1.11.0-150600.20.6.1
fixed
suse enterprise sap 15 SP7
1.11.0-150600.20.6.1
fixed
suse enterprise server 12 SP3
1.4.3-20.20.1
fixed
suse enterprise server 12 SP5
1.11.0-29.18.1
fixed
suse enterprise server 15 SP4
1.11.0-150200.9.8.1
fixed
suse enterprise server 15 SP5
1.11.0-150200.9.8.1
fixed
suse enterprise server 15 SP6
1.11.0-150600.20.6.1
fixed
suse enterprise server 15 SP7
1.11.0-150600.20.6.1
fixed
libssh2-1-32bit
suse enterprise desktop 15 SP7
1.11.0-150600.20.6.1
fixed
suse enterprise sap 15 SP7
1.11.0-150600.20.6.1
fixed
suse enterprise server 12 SP3
1.4.3-20.20.1
fixed
suse enterprise server 12 SP5
1.11.0-29.18.1
fixed
suse enterprise server 15 SP4
1.11.0-150200.9.8.1
fixed
suse enterprise server 15 SP5
1.11.0-150200.9.8.1
fixed
suse enterprise server 15 SP6
1.11.0-150600.20.6.1
fixed
suse enterprise server 15 SP7
1.11.0-150600.20.6.1
fixed
libssh2-devel
suse enterprise desktop 15 SP7
1.11.0-150600.20.6.1
fixed
suse enterprise sap 15 SP7
1.11.0-150600.20.6.1
fixed
suse enterprise server 12 SP5
1.11.0-29.18.1
fixed
suse enterprise server 15 SP4
1.11.0-150200.9.8.1
fixed
suse enterprise server 15 SP5
1.11.0-150200.9.8.1
fixed
suse enterprise server 15 SP6
1.11.0-150600.20.6.1
fixed
suse enterprise server 15 SP7
1.11.0-150600.20.6.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libssh2
Amazon Linux 2
0:1.4.3-12.amzn2.2.8
fixed
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.5
fixed
libssh2-debuginfo
Amazon Linux 2
0:1.4.3-12.amzn2.2.8
fixed
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.5
fixed
libssh2-debugsource
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.5
fixed
libssh2-devel
Amazon Linux 2
0:1.4.3-12.amzn2.2.8
fixed
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.5
fixed
libssh2-docs
Amazon Linux 2
0:1.4.3-12.amzn2.2.8
fixed
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.5
fixed