gpp_maybe
Security update for libssh2_org
SUSE-SL-Micro-6.2-1445
This update for libssh2_org fixes the following issues: - CVE-2025-15661: out-of-bounds heap read vulnerability in the `sftp_symlink()` function in `src/sftp.c` (bsc#1268546). - CVE-2026-7598: integer overflow in function `userauth_password` of file `src/userauth.c` (bsc#1263890). - CVE-2026-58050: heap buffer overflow due to missing bounds check in attribute count of publickey-subsystem response (bsc#1269568). - CVE-2026-58051: uninitialized pointer freed when malformed responses are sent by an SSH server (bsc#1269567). - CVE-2026-66032: arbitrary code execution via double-free in SFTP session (bsc#1272737). - CVE-2026-66033: denial of service via integer underflow in AES-GCM cipher negotiation (bsc#1272736). - CVE-2026-66034: information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735). - CVE-2026-66035: arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734).
-
Release DateAug 10 2026
-
ReferencesBugzilla: 1263890, 1268546, 1269567, 1269568, 1272734, 1272735, 1272736, 1272737
CVEs: CVE-2025-15661, CVE-2026-7598, CVE-2026-58050, CVE-2026-58051, CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Micro 6.2 ppc64le
-
Packages
SUSE Linux Micro 6.2 aarch64
-
Packages
SUSE Linux Micro 6.2 s390x
-
Packages
SUSE Linux Micro 6.2 x86_64
-
Packages