Alerts This Week
Warning Icon 1 690
Alerts This Week
Warning Icon 1 690

Ubuntu 20.04 LTS libssh Important DDoS Risks USN-8051-2 CVE-2025-8277

ubuntu
Calendar Grey February 23, 2026
Dist Ubuntu Esm H88
Critical updates for libssh vulnerabilities in Ubuntu to protect against denial of service attacks and remote code execution.
Several security issues were fixed in libssh.

Summary

Several security issues were fixed in libssh.

Software Description:

- libssh: A tiny C SSH library

Details:

USN-8051-1 fixed vulnerabilities in libssh. This update provides the

corresponding updates for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu

20.04 LTS.

Original advisory details:

It was discovered that libssh clients incorrectly handled the key exchange

process. A remote attacker could possibly use this issue to cause libssh

clients to crash, resulting in a denial of service. (CVE-2025-8277)

It was discovered that the libssh SCP client incorrectly sanitized paths

received from servers. A remote attacker could use this issue to cause

libssh SCP clients to overwrite files outside of the working directory and

possibly execute arbitrary code. (CVE-2026-0964)

It was discovered that libssh incorrectly handled parsing configuration

files. A local attacker could possibly use this issue to cause libssh to

access non-regular files, resulting in a denial of service. (C...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
  libssh-4                        0.9.3-2ubuntu2.5+esm3
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  libssh-4                        0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  libssh-4                        0.6.3-4.3ubuntu0.6+esm4
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8051-2

https://ubuntu.com/security/notices/USN-8051-1

CVE-2025-8277, CVE-2026-0964, CVE-2026-0965, CVE-2026-0966,

CVE-2026-0967, CVE-2026-0968

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8051-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here