Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Slackware libssh Critical Denial Of Service Issues SSA-2026-202-01

slackware
Calendar Grey July 21, 2026
Scroller Slackware
New libssh packages for Slackware 15.0 address critical issues including DoS and information disclosure vulnerabilities.
New libssh packages are available for Slackware 15.0 and -current to fix security issues.

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/libssh-0.11.5-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: Stack buffer overflow in SFTP server longname construction. Denial of service via zero advertised channel packet size. Denial of service via oversized SFTP read length. Denial of service via unchecked ProxyCommand fork() failure. Information disclosure via ProxyCommand %r username expansion. Integrity downgrade via OpenSSL AES-GCM tag verification. Denial of service via SFTP responses with unknown request IDs. Denial of service via automatic certificate authentication loop. Use-after-free via data callbacks on closed channels. Zero-initialize every ssh_string. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-15370 https://www.cve.org/CVERecord?id=CVE-2026-59843 https://www.cve.org/CVERecord?id=CVE-2026-59844 https://www.cve.org/CVERecord?id=CVE-2026-59845

Read the Full Advisory

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you.
Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libssh-0.11.5-i586-1_slack15.0.txz
Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libssh-0.11.5-x86_64-1_slack15.0.txz
Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libssh-0.12.1-i686-1.txz
Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libssh-0.12.1-x86_64-1.txz

MD5 Signatures

Slackware 15.0 package: fc3aa3b43df45ca2f56b7ce893349004 libssh-0.11.5-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: f7e6b1f037fec2be10fb188b148f52a1 libssh-0.11.5-x86_64-1_slack15.0.txz
Slackware -current package: 7c71c6735698fa981b7bc002ce6b60c5 l/libssh-0.12.1-i686-1.txz
Slackware x86_64 -current package: 5cbced800f2425577eec6ace1c9b12ea l/libssh-0.12.1-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg libssh-0.11.5-i586-1_slack15.0.txz