shield
Security update for libssh
SUSE-SLE-Micro-6.0-834
This update for libssh fixes the following issues: - CVE-2026-3731: denial of Service via out-of-bounds read in SFTP extension name handler (bsc#1259377). - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171).
-
Release DateAug 6 2026
-
ReferencesBugzilla: 1259377, 1272164, 1272165, 1272166, 1272167, 1272168, 1272169, 1272171
CVEs: CVE-2026-3731, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845, CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59850 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Micro 6.0 s390x
-
Packageslibssh-config
SSH library configuration fileslibssh40.10.6-5.1 lock rpm
SSH library0.10.6-5.1 lock rpm
SUSE Linux Micro 6.0 aarch64
-
Packageslibssh-config
SSH library configuration fileslibssh40.10.6-5.1 lock rpm
SSH library0.10.6-5.1 lock rpm
SUSE Linux Micro 6.0 x86_64
-
Packageslibssh-config
SSH library configuration fileslibssh40.10.6-5.1 lock rpm
SSH library0.10.6-5.1 lock rpm