[フレーム]

Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Your preferences have been successfully updated. Close notification

Please try again or file a bug report. Close

Security

Search CVE reports


Toggle filters

1 – 10 of 72 results


CVE-2026-66035

Medium priority

Some fixes available 2 of 7

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-66034

Medium priority

Some fixes available 2 of 7

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-66033

Medium priority

Some fixes available 2 of 7

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-66032

Medium priority

Some fixes available 2 of 7

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59851

Medium priority
Not affected

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-59850

Medium priority

Some fixes available 3 of 6

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-59849

Medium priority
Fixed

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading...

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-59848

Medium priority

Some fixes available 3 of 6

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-59847

Medium priority

Some fixes available 3 of 6

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-59846

Medium priority

Some fixes available 3 of 6

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

1 affected package

libssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages
  1. Previous page
  2. 1
  3. 2
  4. 3
  5. 4
  6. 5
  7. Next page
Export to JSON

AltStyle によって変換されたページ (->オリジナル) /