CVE-2026-66035
EUVD-2026-4872224.07.2026, 17:17
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libssh2 | libssh2 | 𝑥 ≤ 1.11.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libssh2-1 |
| ||||||||||||||||||||||
| libssh2-1-32bit |
| ||||||||||||||||||||||
| libssh2-devel |
|
Amazon Linux Releases
Vulnerability Media Exposure