Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 569
Alerts This Week
Warning Icon 1 569

openSUSE libssh Moderate Denial of Service Flaw 2026-3330-1

opensuse
Calendar Grey July 28, 2026
Scroller Opensuse
Seven vulnerabilities in libssh resolved with critical updates for openSUSE to enhance security and performance.
A security update for libssh addresses seven vulnerabilities affecting various SUSE products, including denial of service and information disclosure issues, with recommended instal...

Description

This update for libssh fixes the following issues:

* CVE-2026-59843: denial of service via zero advertised channel packet size

(bsc#1272164).

* CVE-2026-59844: denial of service via oversized SFTP read length

(bsc#1272165).

* CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure

(bsc#1272166).

* CVE-2026-59846: information disclosure via ProxyCommand %r username

expansion (bsc#1272167).

* CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification

(bsc#1272168).

* CVE-2026-59848: denial of service via SFTP responses with unknown request

IDs (bsc#1272169).

* CVE-2026-59850: use-after-free via data callbacks on closed channels

(bsc#1272171).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3330=1

* Basesystem Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3330=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3330=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-3330=1

Package List

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* libssh4-debuginfo-0.9.8-150600.11.15.1

* libssh-config-0.9.8-150600.11.15.1

* libssh4-0.9.8-150600.11.15.1

* libssh-devel-0.9.8-150600.11.15.1

* libssh-debugsource-0.9.8-150600.11.15.1

* openSUSE Leap 15.6 (x86_64)

* libssh4-32bit-0.9.8-150600.11.15.1

* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1

* openSUSE Leap 15.6 (aarch64_ilp32)

* libssh4-64bit-0.9.8-150600.11.15.1

* libssh4-64bit-debuginfo-0.9.8-150600.11.15.1

* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)

* libssh4-debuginfo-0.9.8-150600.11.15.1

* libssh-config-0.9.8-150600.11.15.1

* libssh4-0.9.8-150600.11.15.1

* libssh-devel-0.9.8-150600.11.15.1

* libssh-debugsource-0.9.8-150600.11.15.1

* Basesystem Module 15-SP7 (x86_64)

* libssh4-32bit-0.9.8-150600.11.15.1

* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)

* libssh4-debuginfo-0.9.8-150600.11.15.1

* libssh-config-0.9.8-150600.11.15.1

*...

Read the Full Advisory

References

* bsc#1272164

* bsc#1272165

* bsc#1272166

* bsc#1272167

* bsc#1272168

* bsc#1272169

* bsc#1272171

## References:

* https://www.suse.com/security/cve/CVE-2026-59843.html

* https://www.suse.com/security/cve/CVE-2026-59844.html

* https://www.suse.com/security/cve/CVE-2026-59845.html

* https://www.suse.com/security/cve/CVE-2026-59846.html

* https://www.suse.com/security/cve/CVE-2026-59847.html

* https://www.suse.com/security/cve/CVE-2026-59848.html

* https://www.suse.com/security/cve/CVE-2026-59850.html

* https://bugzilla.suse.com/show_bug.cgi?id=1272164

* https://bugzilla.suse.com/show_bug.cgi?id=1272165

* https://bugzilla.suse.com/show_bug.cgi?id=1272166

* https://bugzilla.suse.com/show_bug.cgi?id=1272167

* https://bugzilla.suse.com/show_bug.cgi?id=1272168

* https://bugzilla.suse.com/show_bug.cgi?id=1272169

* https://bugzilla.suse.com/show_bug.cgi?id=1272171

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3330-1
Release Date: 2026-07-28T09:36:04Z

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.