This update for libssh2_org fixes the following issues
- CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530).
- CVE-2026-55200: out-of-Bounds write via Unchecked packet_length in transport.c (bsc#1268531).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1078=1
- openSUSE Leap 16.0:
libssh2-1-1.11.1-160000.4.1
libssh2-devel-1.11.1-160000.4.1
* bsc#1268530
* bsc#1268531
References:
* https://www.suse.com/security/cve/CVE-2026-55199.html
* https://www.suse.com/security/cve/CVE-2026-55200.html
Get the latest Linux and open source security news straight to your inbox.