Alerts This Week
Warning Icon 1 1,495
Alerts This Week
Warning Icon 1 1,495

Ubuntu 25.10 Libssh Critical DoS Issues CVE-2025-8277 USN-8051-1

ubuntu
Calendar Grey February 18, 2026
Dist Ubuntu Esm H88
Address critical libssh vulnerabilities in Ubuntu affecting several versions with recommended updates to prevent DoS attacks.
Several security issues were fixed in libssh.

Summary

Several security issues were fixed in libssh.

Software Description:

- libssh: A tiny C SSH library

Details:

It was discovered that libssh clients incorrectly handled the key exchange

process. A remote attacker could possibly use this issue to cause libssh

clients to crash, resulting in a denial of service. (CVE-2025-8277)

It was discovered that the libssh SCP client incorrectly sanitized paths

received from servers. A remote attacker could use this issue to cause

libssh SCP clients to overwrite files outside of the working directory and

possibly execute arbitrary code. (CVE-2026-0964)

It was discovered that libssh incorrectly handled parsing configuration

files. A local attacker could possibly use this issue to cause libssh to

access non-regular files, resulting in a denial of service. (CVE-2026-0965)

It was discovered that libssh incorrectly handled the ssh_get_hexa()

function. A remote attacker could possibly use this issue to cause libssh

to crash, resulting in a denial of...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  libssh-4                        0.11.2-1ubuntu0.2

Ubuntu 24.04 LTS
  libssh-4                        0.10.6-2ubuntu0.3

Ubuntu 22.04 LTS
  libssh-4                        0.9.6-2ubuntu0.22.04.6

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8051-1

CVE-2025-8277, CVE-2026-0964, CVE-2026-0965, CVE-2026-0966,

CVE-2026-0967, CVE-2026-0968

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8051-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here