Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Fedora 43 libssh Critical Denial of Service Buffer Overflow 2026-063caa9112

fedora
Calendar Grey July 22, 2026
Scroller Fedora
Urgent security update for libssh addressing multiple vulnerabilities including denial of service and stack buffer overflow.
Fedora has released a new version of libssh, 0.11.5, addressing multiple security vulnerabilities, including denial of service and information disclosure issues

Summary

The ssh library was designed to be used by programmers needing a working SSH

implementation by the mean of a library. The complete control of the client is

made by the programmer. With libssh, you can remotely execute programs, transfer

files, use a secure and transparent tunnel for your remote programs. With its

Secure FTP implementation, you can play with remote files easily, without

third-party programs others than libcrypto (from openssl).

Update Information:

New upstream security release (#2503148)

Change Log

* Tue Jul 21 2026 Jakub Jelen - 0.11.5-1 - New upstream security release (#2503148)

References


[ 1 ] Bug #2503148 - libssh-0.12.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2503148 [ 2 ] Bug #2503651 - CVE-2026-15370 libssh: libssh: stack buffer overflow in SFTP server longname construction [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2503651 [ 3 ] Bug #2503657 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2503657 [ 4 ] Bug #2503658 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2503658 [ 5 ] Bug #2503668 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2503668 [ 6 ] Bug #2503669 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all] https...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-063caa9112' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libssh
Product: Fedora 43
Version: 0.11.5
Release: 1.fc43
Summary: A library implementing the SSH protocol

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.