[フレーム]

Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Your preferences have been successfully updated. Close notification

Please try again or file a bug report. Close

Security

Search CVE reports


Toggle filters

1 – 10 of 25 results


CVE-2026-66035

Medium priority

Some fixes available 2 of 7

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-66034

Medium priority

Some fixes available 2 of 7

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-66033

Medium priority

Some fixes available 2 of 7

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-66032

Medium priority

Some fixes available 2 of 7

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-58051

Medium priority

Some fixes available 2 of 8

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-58050

Medium priority

Some fixes available 2 of 8

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-15661

Medium priority

Some fixes available 3 of 8

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-55200

Medium priority
Fixed

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-55199

Medium priority
Fixed

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-7598

Medium priority

Some fixes available 3 of 8

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer...

1 affected package

libssh2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages
  1. Previous page
  2. 1
  3. 2
  4. 3
  5. Next page
Export to JSON

AltStyle によって変換されたページ (->オリジナル) /