CVE-2026-58051
EUVD-2026-3997128.06.2026, 02:16
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libssh2 | libssh2 | 𝑥 ≤ 1.11.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libssh2-1 |
| ||||||||||||||||
| libssh2-1-32bit |
| ||||||||||||||||
| libssh2-devel |
|
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| libssh2 |
| ||||
| libssh2-debuginfo |
| ||||
| libssh2-debugsource |
| ||||
| libssh2-devel |
| ||||
| libssh2-docs |
|
Common Weakness Enumeration
Vulnerability Media Exposure