Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 42 libssh 0.11.4 Critical Denial of Service Issues 2026-0d8264f449

fedora
Calendar Grey February 18, 2026
Dist Fedora Esm H88
Libssh update for Fedora 42 addresses multiple security issues including DoS, buffer underflow, and more.
New upstream release fixing various security issues.

Summary

The ssh library was designed to be used by programmers needing a working SSH

implementation by the mean of a library. The complete control of the client is

made by the programmer. With libssh, you can remotely execute programs, transfer

files, use a secure and transparent tunnel for your remote programs. With its

Secure FTP implementation, you can play with remote files easily, without

third-party programs others than libcrypto (from openssl).

Update Information:

New upstream release fixing various security issues.

Change Log

* Tue Feb 10 2026 Jakub Jelen - 0.11.4-1 - New upstream release fixing following security issues: - CVE-2025-14821: libssh loads configuration files from the C:\etc directory on Windows - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname()

References


[ 1 ] Bug #2438452 - libssh-0.12.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2438452

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0d8264f449' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libssh
Product: Fedora 42
Version: 0.11.4
Release: 1.fc42
Summary: A library implementing the SSH protocol

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here