Ubuntu alert USN-8486-1 (libssh2)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8486-1] libssh2 vulnerabilities | |
| Date: | Tue, 30 Jun 2026 15:08:09 +0000 | |
| Message-ID: | <E1wea4H-00034D-Ox@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8486-1 June 30, 2026 libssh2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: Several security issues were fixed in libssh2. Software Description: - libssh2: Client-side C library implementing the SSH2 protocol Details: It was discovered that libssh2 incorrectly handled the sftp_symlink() function. A malicious SSH server or machine-in-the-middle attacker could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2025-15661) It was discovered that libssh2 had a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler. A malicious SSH server could possibly use this issue to cause a client CPU exhaustion loop, resulting in a denial of service. (CVE-2026-55199) It was discovered that libssh2 incorrectly handled packet length fields. A remote attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-55200) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssh2-1t64 1.11.1-1ubuntu0.26.04.2 Ubuntu 25.10 libssh2-1t64 1.11.1-1ubuntu0.25.10.2 Ubuntu 24.04 LTS libssh2-1t64 1.11.0-4.1ubuntu0.24.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8486-1 CVE-2025-15661, CVE-2026-55199, CVE-2026-55200 Package Information: https://launchpad.net/ubuntu/+source/libssh2/1.11.1-1ubun... https://launchpad.net/ubuntu/+source/libssh2/1.11.1-1ubun... https://launchpad.net/ubuntu/+source/libssh2/1.11.0-4.1ub...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpD23EACgkQcpJm3tlz hgFNxg/+IRc7w0WvKEkz8jO92+DaemUoQ8XmxUCfsn0vTgbZip6Ne0w3iBGinwRC VP3XGIvI3Nhsdh1SxIJbzXfDSl+DaondgzlK4re+6K5Um8bSqYfmMT9xN5uvyis2 485hJ1u19oi5Zj7I86OkMydHWVXn500rptHuwRp0pdRvnl+9zjhWfal2lo9NOGLz azdLstlEulU0fwigo5d4fEWuIeKdDDkfuTQCZ724yvafAVuw15ks6g2IPeFrgvxy kYeKSXayqKjdJGTbw66oLNmn9kVi4/3DK1R9p+2EWcpQ1PBMtbM4Gv+x7Oyu4Qyl lTCrtqF4mYd6ph2HIQx/Vdra/94f/xd3SpqscPyWiQErL4b1Cj/DZfkwxJepcnYE 9NjUkklOtXlamUmAuW1LI1lyks+ecnABxQKwneVGMlWhg7cMMjiVOnZPtgrqCPgE XNt6IvcjUSLz3fdZ6TT4hd0iPUZ+a+2N4pDqKYHbrWxXCw2L5K5ZHOd7JDRH1FWy Dqnqs5l8ZPObJNPfm7Gx2gYasUmBZbFp28r4av9nKnxk7R7s+oVi9tjbVRrshLD7 PopAvEthNYjevPOIhhdD8lQSpep5a1GDECmRxmF9T4/Bqjuas8Vc7jvAQQbhTmOW x/8QaGV9axsKLG7l5uhtjRX1A+gKZ3ubuZJVK/vR9H1y9xkiyAY= =uPAi -----END PGP SIGNATURE-----
