Skip to main content
EPSS 0.9%top 42%

Security update for libssh2_org

0
High
Published: 06/25/2026 (06/25/2026, 11:51:43 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for libssh2_org fixes the following issues - CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). - CVE-2026-55200: out-of-Bounds write via Unchecked packet_length in transport.c (bsc#1268531).

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64libssh2-main@aarch64<1.11.0-4.1ubuntu0.24.04.2<1.11.1-1ubuntu0.25.10.2<1.11.1-1ubuntu0.26.04.2SUSElibssh2-1-1.11.1-160000.4.1.aarch64libssh2-devel-1.11.1-160000.4.1.aarch64ppc64le

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:41:13 UTC

Technical Analysis

CVE-2026-55200 is an out-of-bounds write vulnerability in the libssh2 client library, triggered by processing an SSH packet with an abnormally large length value. This leads to heap corruption and potential application crash. Exploitation requires the client to connect to an attacker-controlled SSH server, which may be achieved via DNS poisoning, man-in-the-middle, or trusted host compromise. While arbitrary code execution is theoretically possible, it is considered unlikely in practice due to ASLR, glibc heap integrity checks, and the need for additional information disclosure vulnerabilities. Red Hat Hardened Images have been updated with libssh2 version 1.11.1-8.hum1 to fix this issue. RHEL 8.1 and later do not include libssh2 and are unaffected. The vulnerability is tracked under CVE-2026-55200 and CVE-2026-55199, with CWE-606 (Unchecked Input for Loop Condition) referenced. No CVSS score is provided by Red Hat, but the impact is rated medium.

Potential Impact

The vulnerability allows remote attackers to cause memory corruption and crash the libssh2 client process, resulting in denial of service. Remote code execution is theoretically possible but highly unlikely due to required conditions including client redirection to attacker-controlled servers, ASLR, and heap metadata integrity checks. The practical impact is limited by the need for victim-initiated connections to malicious servers and network-level mitigations. RHEL 8.1 and later are not affected as they do not include libssh2.

Mitigation Recommendations

Red Hat has released updated libssh2 RPM packages (version 1.11.1-8.hum1) for Red Hat Hardened Images to address this vulnerability. Users should apply these updates promptly. Additionally, strict network access controls should be enforced to ensure libssh2 clients connect only to trusted SSH servers. Firewalls should be used to block untrusted incoming connections if libssh2 is deployed in server-side roles. RHEL 8.1 and later are not affected and require no action. No other mitigations are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Nationaal Cyber Security Centrum
Advisory Id
NCSC-2026-0210
Cve Count
2
Additional Cves
["CVE-2026-55200"]

Threat ID: 6a3aab54eed863c81e3a39f8

Added to database: 06/23/2026, 15:50:44 UTC

Last enriched: 08/16/2026, 17:41:13 UTC

Last updated: 09/22/2026, 01:52:44 UTC

Views: 144

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses