ITSECURITYWHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardVulnerabilities › CVE-2026-0968
3.1Low CVE-2026-0968 Libssh

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname'

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

What happened

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

Does it affect you

Not enough information

No products recorded, so this cannot be matched against anything.

What to do

  • Follow the vendor advisory for the fixed release and any interim mitigation.
    libssh.org

Vendor's affected list

rhel
Exactly 9.0

Sources

A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.