Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for libssh fixes the following issues:
* CVE-2026-59843: denial of service via zero advertised channel packet size
(bsc#1272164).
* CVE-2026-59844: denial of service via oversized SFTP read length
(bsc#1272165).
* CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure
(bsc#1272166).
* CVE-2026-59846: information disclosure via ProxyCommand %r username
expansion (bsc#1272167).
* CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification
(bsc#1272168).
* CVE-2026-59848: denial of service via SFTP responses with unknown request
IDs (bsc#1272169).
* CVE-2026-59850: use-after-free via data callbacks on closed channels
(bsc#1272171).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3330=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3330=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3330=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3330=1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
* openSUSE Leap 15.6 (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libssh4-64bit-0.9.8-150600.11.15.1
* libssh4-64bit-debuginfo-0.9.8-150600.11.15.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
* Basesystem Module 15-SP7 (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
*...
Read the Full Advisory* bsc#1272164
* bsc#1272165
* bsc#1272166
* bsc#1272167
* bsc#1272168
* bsc#1272169
* bsc#1272171
## References:
* https://www.suse.com/security/cve/CVE-2026-59843.html
* https://www.suse.com/security/cve/CVE-2026-59844.html
* https://www.suse.com/security/cve/CVE-2026-59845.html
* https://www.suse.com/security/cve/CVE-2026-59846.html
* https://www.suse.com/security/cve/CVE-2026-59847.html
* https://www.suse.com/security/cve/CVE-2026-59848.html
* https://www.suse.com/security/cve/CVE-2026-59850.html
* https://bugzilla.suse.com/show_bug.cgi?id=1272164
* https://bugzilla.suse.com/show_bug.cgi?id=1272165
* https://bugzilla.suse.com/show_bug.cgi?id=1272166
* https://bugzilla.suse.com/show_bug.cgi?id=1272167
* https://bugzilla.suse.com/show_bug.cgi?id=1272168
* https://bugzilla.suse.com/show_bug.cgi?id=1272169
* https://bugzilla.suse.com/show_bug.cgi?id=1272171
Get the latest Linux and open source security news straight to your inbox.