Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE Linux Micro 6.2 libssh Moderate DoS Memory Leak Advisory 2026-21396-1

suse
Calendar Grey April 30, 2026
Dist Suse Esm H88
Critical libssh update addressing seven issues including DoS and memory leaks for SUSE Linux Micro 6.2 users.
An update that solves seven vulnerabilities can now be installed.

Summary

## This update for libssh fixes the following issues: * Update to version 0.11.4: * CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() (bsc#1258049) * CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files (bsc#1258045) * CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054) * CVE-2026-0967: Specially crafted patterns could cause DoS (bsc#1258081) * CVE-2026-0968: OOB Read in sftp_parse_longname() (bsc#1258080) * CVE-2025-8114: Fix NULL pointer dereference after allocation failure (bsc#1246974) * CVE-2025-8277: Fix memory leak of ephemeral key pair during repeated wrong KEX (bsc#1249375) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like

References

* bsc#1246974

* bsc#1249375

* bsc#1258045

* bsc#1258049

* bsc#1258054

* bsc#1258080

* bsc#1258081

Cross-

* CVE-2025-8114

* CVE-2025-8277

* CVE-2026-0964

* CVE-2026-0965

* CVE-2026-0966

* CVE-2026-0967

* CVE-2026-0968

CVSS scores:

* CVE-2025-8114 ( SUSE ): 5.7

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-8114 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-8114 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-8114 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-8277 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-8277 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-0964 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

Announcement ID: SUSE-SU-2026:21396-1
Release Date: 2026-04-29T11:06:27Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here