Ubuntu alert USN-8699-1 (libssh)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8699-1] libssh vulnerabilities | |
| Date: | Mon, 31 Aug 2026 14:09:36 +0000 | |
| Message-ID: | <E1x12hc-0004do-1L@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8699-1 August 31, 2026 libssh vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in libssh. Software Description: - libssh: A tiny C SSH library Details: It was discovered that libssh had a stack buffer overflow in its SFTP server when constructing directory listing entries for long filenames. An attacker could possibly use this issue to cause libssh to crash or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15370) It was discovered that libssh did not correctly handle SSH channel open messages advertising a zero maximum packet size. An authenticated remote attacker could possibly use this issue to cause libssh to consume excessive CPU resources, leading to a denial of service. (CVE-2026-59843) It was discovered that libssh did not correctly limit SFTP read request lengths in its server implementation. An authenticated remote attacker could possibly use this issue to cause libssh to allocate excessive memory, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-59844) It was discovered that libssh did not correctly handle ProxyCommand fork() failures. A local attacker could possibly use this issue to cause a denial of service. (CVE-2026-59845) It was discovered that libssh did not correctly sanitize shell metacharacters when expanding usernames in ProxyCommand strings. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-59846) It was discovered that libssh had incorrect AES-GCM tag verification when built with the OpenSSL backend. A machine-in-the-middle attacker could possibly use this issue to modify encrypted traffic without detection. (CVE-2026-59847) It was discovered that libssh did not correctly handle SFTP server responses for unknown request IDs. An attacker could possibly use this issue to cause libssh to use excessive memory, leading to a denial of service. (CVE-2026-59848) It was discovered that libssh had logic errors in certificate-based authentication that could cause clients to loop indefinitely when certificates were rejected. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-59849) It was discovered that libssh could invoke data callbacks on channels after they had been closed. An attacker could possibly use this issue to cause libssh to crash or execute arbitrary code. (CVE-2026-59850) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssh-4 0.11.3-1ubuntu2.1 Ubuntu 24.04 LTS libssh-4 0.10.6-2ubuntu0.5 Ubuntu 22.04 LTS libssh-4 0.9.6-2ubuntu0.22.04.8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8699-1 CVE-2026-15370, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845, CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849, CVE-2026-59850 Package Information: https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubunt... https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubunt... https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmqVe9cACgkQcpJm3tlz hgHwqA/+KjX4zFsdCYf9B1iTuA2pVvG5326Yww4sXGi6YWfB9h5UTkiq7HEmH1L7 mPmUZEloKz8HOQRzHQ9py/gPrEAJ6RZ8HE2gkE3FBr2I7A/CF3q0LD1ekLroMk1K 1cjmFLkmXdpB+0HaJgWGP5g63kzJfvRhGFkS1VX7/6QBZQek60J+hY3Mre+4BzvC VPPXJe+qupBVUpvfxC5S35/j1EzN+XRp8rPeEABUaHMDEy3JwDphK78LvtsRKxQE tyGIb06KCiwxK1EGCTSUHxd1kA7ejFPMQW3sqafUQrq8wghq6WTfv5wXRQzhIMfG 9Dx2Hq9OAO61isgwndUHhpI5aVouM8Xk5tqjOURkrZnU7j4X6YIvoibwWZYwbq85 cxr97uXysTfXMHyftsobvgPcRqjqqvpa/U5OaCv7h6smbn/PBzkJnhyp6nPry9aq Jb4yTOpaP2ebbKbd9JMwrVCL01LIdCapql+wnPDxrqn1Pff7o/l1861Xcz3yt1tF dYN0ml9LpLLELIaYYWgAxyDN3HbqmGBykwPdI2Nq6Oyn+OuyVI6hIw7xAgUq89ph 5QOyfaOrOSclTBVDZIPfzUH37y0iZZtpOsjZTX4+M3nEsNxOAATYBg0ly58zm5o/ YYE2+FTTWTTBVcwO4Ag/XxT5sHx+8SVNoraHYd3xmwL9S7lQ+mQ= =O8at -----END PGP SIGNATURE-----
