shield
Security update for libssh
SUSE-SLE-Micro-5.4-2026-3463
This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171).
-
Release DateAug 3 2026
-
ReferencesBugzilla: 1272164, 1272165, 1272166, 1272167, 1272168, 1272169, 1272171
CVEs: CVE-2026-59843, CVE-2026-59844, CVE-2026-59845, CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59850 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Micro 5.4 aarch64
-
Packageslibssh
The SSH librarylibssh-config0.9.8-150400.3.20.1 lock src
SSH library configuration fileslibssh40.9.8-150400.3.20.1 lock rpm
SSH library0.9.8-150400.3.20.1 lock rpm
SUSE Linux Enterprise Micro 5.4 s390x
-
Packageslibssh
The SSH librarylibssh-config0.9.8-150400.3.20.1 lock src
SSH library configuration fileslibssh40.9.8-150400.3.20.1 lock rpm
SSH library0.9.8-150400.3.20.1 lock rpm
SUSE Linux Enterprise Micro 5.4 x86_64
-
Packageslibssh
The SSH librarylibssh-config0.9.8-150400.3.20.1 lock src
SSH library configuration fileslibssh40.9.8-150400.3.20.1 lock rpm
SSH library0.9.8-150400.3.20.1 lock rpm