Security update for libssh2_org
This update for libssh2_org fixes the following issues - CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). - CVE-2026-55200: out-of-Bounds write via Unchecked packet_length in transport.c (bsc#1268531).
AI Analysis
Technical Summary
CVE-2026-55200 is an out-of-bounds write vulnerability in the libssh2 client library, triggered by processing an SSH packet with an abnormally large length value. This leads to heap corruption and potential application crash. Exploitation requires the client to connect to an attacker-controlled SSH server, which may be achieved via DNS poisoning, man-in-the-middle, or trusted host compromise. While arbitrary code execution is theoretically possible, it is considered unlikely in practice due to ASLR, glibc heap integrity checks, and the need for additional information disclosure vulnerabilities. Red Hat Hardened Images have been updated with libssh2 version 1.11.1-8.hum1 to fix this issue. RHEL 8.1 and later do not include libssh2 and are unaffected. The vulnerability is tracked under CVE-2026-55200 and CVE-2026-55199, with CWE-606 (Unchecked Input for Loop Condition) referenced. No CVSS score is provided by Red Hat, but the impact is rated medium.
Potential Impact
The vulnerability allows remote attackers to cause memory corruption and crash the libssh2 client process, resulting in denial of service. Remote code execution is theoretically possible but highly unlikely due to required conditions including client redirection to attacker-controlled servers, ASLR, and heap metadata integrity checks. The practical impact is limited by the need for victim-initiated connections to malicious servers and network-level mitigations. RHEL 8.1 and later are not affected as they do not include libssh2.
Mitigation Recommendations
Red Hat has released updated libssh2 RPM packages (version 1.11.1-8.hum1) for Red Hat Hardened Images to address this vulnerability. Users should apply these updates promptly. Additionally, strict network access controls should be enforced to ensure libssh2 clients connect only to trusted SSH servers. Firewalls should be used to block untrusted incoming connections if libssh2 is deployed in server-side roles. RHEL 8.1 and later are not affected and require no action. No other mitigations are indicated by the vendor advisory.
Security update for libssh2_org
Description
This update for libssh2_org fixes the following issues - CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). - CVE-2026-55200: out-of-Bounds write via Unchecked packet_length in transport.c (bsc#1268531).
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-55200 is an out-of-bounds write vulnerability in the libssh2 client library, triggered by processing an SSH packet with an abnormally large length value. This leads to heap corruption and potential application crash. Exploitation requires the client to connect to an attacker-controlled SSH server, which may be achieved via DNS poisoning, man-in-the-middle, or trusted host compromise. While arbitrary code execution is theoretically possible, it is considered unlikely in practice due to ASLR, glibc heap integrity checks, and the need for additional information disclosure vulnerabilities. Red Hat Hardened Images have been updated with libssh2 version 1.11.1-8.hum1 to fix this issue. RHEL 8.1 and later do not include libssh2 and are unaffected. The vulnerability is tracked under CVE-2026-55200 and CVE-2026-55199, with CWE-606 (Unchecked Input for Loop Condition) referenced. No CVSS score is provided by Red Hat, but the impact is rated medium.
Potential Impact
The vulnerability allows remote attackers to cause memory corruption and crash the libssh2 client process, resulting in denial of service. Remote code execution is theoretically possible but highly unlikely due to required conditions including client redirection to attacker-controlled servers, ASLR, and heap metadata integrity checks. The practical impact is limited by the need for victim-initiated connections to malicious servers and network-level mitigations. RHEL 8.1 and later are not affected as they do not include libssh2.
Mitigation Recommendations
Red Hat has released updated libssh2 RPM packages (version 1.11.1-8.hum1) for Red Hat Hardened Images to address this vulnerability. Users should apply these updates promptly. Additionally, strict network access controls should be enforced to ensure libssh2 clients connect only to trusted SSH servers. Firewalls should be used to block untrusted incoming connections if libssh2 is deployed in server-side roles. RHEL 8.1 and later are not affected and require no action. No other mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Nationaal Cyber Security Centrum
- Advisory Id
- NCSC-2026-0210
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-55200"]
Threat ID: 6a3aab54eed863c81e3a39f8
Added to database: 06/23/2026, 15:50:44 UTC
Last enriched: 08/16/2026, 17:41:13 UTC
Last updated: 09/22/2026, 01:52:44 UTC
Views: 144
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.