Alerts This Week
Warning Icon 1 1,123
Alerts This Week
Warning Icon 1 1,123

Fedora 44 libssh2 Critical Remote Code Execution Advisory 2026-ca858b3ed8

fedora
Calendar Grey June 28, 2026
Dist Fedora Esm H88
Update for Fedora addressing critical security issues in libssh2, includes remote code execution risk and denial of service.
This update addresses a few security issues, one of which could plausibly result in remote code execution.

Summary

libssh2 is a library implementing the SSH2 protocol as defined by

Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25),

SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*,

SECSH-DHGEX(04), and SECSH-NUMBERS(10).

Update Information:

This update addresses a few security issues, one of which could plausibly result in remote code execution.

Change Log

* Thu Jun 25 2026 Paul Howarth - 1.11.1-9 - Fix CVE-2025-15661: Information disclosure and denial of service via crafted SFTP response * Tue Jun 23 2026 Mikel Olasagasti Uranga - 1.11.1-8 - Fix CVE-2026-55200 & CVE-2026-55199 * Fri Jun 12 2026 Yaakov Selkowitz - 1.11.1-7 - Rebuilt for openssl 4.0

References


[ 1 ] Bug #2491730 - CVE-2026-55199 libssh2: libssh2: Denial of Service via crafted SSH_MSG_EXT_INFO message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491730 [ 2 ] Bug #2491738 - CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491738 [ 3 ] Bug #2492698 - CVE-2025-15661 libssh2: libssh2: Information disclosure and denial of service via crafted SFTP response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492698

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ca858b3ed8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libssh2
Product: Fedora 44
Version: 1.11.1
Release: 9.fc44
Summary: A library implementing the SSH2 protocol

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here