CVE-2026-59843
Publication date 21 July 2026
Last updated 31 August 2026
Ubuntu priority
Medium
Description
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libssh | 26.04 LTS resolute |
Fixed 0.11.3-1ubuntu2.1
|
| 24.04 LTS noble |
Fixed 0.10.6-2ubuntu0.5
|
|
| 22.04 LTS jammy |
Fixed 0.9.6-2ubuntu0.22.04.8
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
Notes
mdeslaur
While this was mentioned in the 0.12.1 release notes, it was accidentally omitted and was included in 0.12.2 instead.
Patch details
For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?
| Package | Patch details |
|---|---|
| libssh |
Severity score breakdown
CVSS version: CVSS v3.0
Base score 6.5 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-8699-1
- libssh vulnerabilities
- 31 August 2026