A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data… (CVE-2026-59850)
A vulnerability in libssh allows channel data callbacks to be invoked after the associated data has been freed if data packets are processed after a channel is closed. This can lead to crashes or use-after-free conditions. The issue is identified as CVE-2026-59850 and has a moderate severity rating. Red Hat has released an update for libssh in their Hardened Images RPMs to address this flaw.
AI Analysis
Technical Summary
CVE-2026-59850 is a use-after-free vulnerability in libssh where processing data packets after a channel closure can cause channel data callbacks to be invoked on already freed data. This flaw can result in application crashes or potential memory corruption. The vulnerability is classified under CWE-416 (Use After Free). Red Hat has issued a security advisory (RHSA-2026:42922) providing updated libssh packages (libssh-0.12.1-4.hum1) that fix this issue in their Hardened Images RPMs.
Potential Impact
The vulnerability can cause denial of service through application crashes due to use-after-free conditions. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released an official fix in the form of updated libssh packages (libssh-0.12.1-4.hum1) as part of their Hardened Images RPMs. Users of affected Red Hat Hardened Images should apply this update promptly to remediate the vulnerability. Patch status is confirmed by the vendor advisory. No additional mitigation steps are specified.
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data… (CVE-2026-59850)
Description
A vulnerability in libssh allows channel data callbacks to be invoked after the associated data has been freed if data packets are processed after a channel is closed. This can lead to crashes or use-after-free conditions. The issue is identified as CVE-2026-59850 and has a moderate severity rating. Red Hat has released an update for libssh in their Hardened Images RPMs to address this flaw.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59850 is a use-after-free vulnerability in libssh where processing data packets after a channel closure can cause channel data callbacks to be invoked on already freed data. This flaw can result in application crashes or potential memory corruption. The vulnerability is classified under CWE-416 (Use After Free). Red Hat has issued a security advisory (RHSA-2026:42922) providing updated libssh packages (libssh-0.12.1-4.hum1) that fix this issue in their Hardened Images RPMs.
Potential Impact
The vulnerability can cause denial of service through application crashes due to use-after-free conditions. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released an official fix in the form of updated libssh packages (libssh-0.12.1-4.hum1) as part of their Hardened Images RPMs. Users of affected Red Hat Hardened Images should apply this update promptly to remediate the vulnerability. Patch status is confirmed by the vendor advisory. No additional mitigation steps are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cr6p-6527-344m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-59850"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a6150e19c2644c7f8da17cb
Added to database: 07/22/2026, 23:23:13 UTC
Last enriched: 07/22/2026, 23:35:39 UTC
Last updated: 07/31/2026, 19:24:48 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.