Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in libssh2.. ========================================================================== Ubuntu Security Notice USN-8532-1 July 13, 2026 libssh2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS Summary: Several security issues were fixed in libssh2. Software Description: - libssh2: Client-side C library implementing the SSH2 protocol Details: It was discovered that libssh2 incorrectly handled certain publickey subsystem attributes. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58050) It was discovered that libssh2 did not properly initialize publickey list entries before parsing. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58051) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssh2-1t64 1.11.1-1ubuntu0.26.04.3 Ubuntu 24.04 LTS libssh2-1t64 1.11.0-4.1ubuntu0.24.04.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8532-1 CVE-2026-58050, CVE-2026-58051 Package Information: https://launchpad.net/ubuntu/+source/libssh2/1.11.1-1ubuntu0.26.04.3 https://launchpad.net/ubuntu/+source/libssh2/1.11.0-4.1ubuntu0.24.04.3 . Recent fixes for libssh2 address critical security issues in Ubuntu affecting remote code execution and denial of service.. Ubuntu libssh2 security fix, remote code execution Ubuntu, denial of service vulnerability, libssh2 issues, security update Ubuntu. . Severity: Critical. LinuxSecurity.com Team
This update addresses a few security issues, one of which could plausibly result in remote code execution.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-eed9e67393 2026-07-12 00:58:35.903616+00:00 -------------------------------------------------------------------------------- Name : libssh2 Product : Fedora 43 Version : 1.11.1 Release : 9.fc43 URL : https://www.libssh2.org/ Summary : A library implementing the SSH2 protocol Description : libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10). -------------------------------------------------------------------------------- Update Information: This update addresses a few security issues, one of which could plausibly result in remote code execution. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Paul Howarth - 1.11.1-9 - Fix CVE-2025-15661: Information disclosure and denial of service via crafted SFTP response * Tue Jun 23 2026 Mikel Olasagasti Uranga - 1.11.1-8 - Fix CVE-2026-55200 & CVE-2026-55199 * Fri Jun 12 2026 Yaakov Selkowitz - 1.11.1-7 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2491730 - CVE-2026-55199 libssh2: libssh2: Denial of Service via crafted SSH_MSG_EXT_INFO message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491730 [ 2 ] Bug #2491738 - CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491738 [ 3 ] Bug #2492698 - CVE-2025-15661 libssh2: libssh2: Information disclosure and denial of service via crafted SFTP response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492698 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-eed9e67393' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for libssh2_org Announcement ID: SUSE-SU-2026:22438-1 Release Date: 2026-07-01T09:39:44Z Rating: moderate References: * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libssh2_org fixes the following issue * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-775=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libssh2_org-debugsource-1.11.0-3.1 * libssh2-1-debuginfo-1.11.0-3.1 * libssh2-1-1.11.0-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 . The SUSE update for libssh2_org addresses a moderate DoS issue with CVE-2026-55199.. SUSE Linux Micro libssh2 DoS security update. . Severity: moderate. LinuxSecurity.com Team
Several security issues were fixed in libssh2.. ========================================================================== Ubuntu Security Notice USN-8486-1 June 30, 2026 libssh2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: Several security issues were fixed in libssh2. Software Description: - libssh2: Client-side C library implementing the SSH2 protocol Details: It was discovered that libssh2 incorrectly handled the sftp_symlink() function. A malicious SSH server or machine-in-the-middle attacker could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2025-15661) It was discovered that libssh2 had a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler. A malicious SSH server could possibly use this issue to cause a client CPU exhaustion loop, resulting in a denial of service. (CVE-2026-55199) It was discovered that libssh2 incorrectly handled packet length fields. A remote attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-55200) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssh2-1t64 1.11.1-1ubuntu0.26.04.2 Ubuntu 25.10 libssh2-1t64 1.11.1-1ubuntu0.25.10.2 Ubuntu 24.04 LTS libssh2-1t64 1.11.0-4.1ubuntu0.24.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8486-1 CVE-2025-15661, CVE-2026-55199, CVE-2026-55200 Package Information: https://launchpad.net/ubuntu/+source/libssh2/1.11.1-1ubuntu0.26.04.2 https://launchpad.net/ubuntu/+source/libssh2/1.11.1-1ubuntu0.25.10.2 https://launchpad.net/ubuntu/+source/libssh2/1.11.0-4.1ubuntu0.24.04.2 . Multiple security flaws have been addressed in libssh2 affecting multiple Ubuntu versions. Update recommended to ensure security.. libssh2 update Ubuntu security issues. . Severity: Important. LinuxSecurity.com Team
This update addresses a few security issues, one of which could plausibly result in remote code execution.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ca858b3ed8 2026-06-29 00:57:02.525499+00:00 -------------------------------------------------------------------------------- Name : libssh2 Product : Fedora 44 Version : 1.11.1 Release : 9.fc44 URL : https://www.libssh2.org/ Summary : A library implementing the SSH2 protocol Description : libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10). -------------------------------------------------------------------------------- Update Information: This update addresses a few security issues, one of which could plausibly result in remote code execution. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Paul Howarth - 1.11.1-9 - Fix CVE-2025-15661: Information disclosure and denial of service via crafted SFTP response * Tue Jun 23 2026 Mikel Olasagasti Uranga - 1.11.1-8 - Fix CVE-2026-55200 & CVE-2026-55199 * Fri Jun 12 2026 Yaakov Selkowitz - 1.11.1-7 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2491730 - CVE-2026-55199 libssh2: libssh2: Denial of Service via crafted SSH_MSG_EXT_INFO message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491730 [ 2 ] Bug #2491738 - CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491738 [ 3 ] Bug #2492698 - CVE-2025-15661 libssh2: libssh2: Information disclosure and denial of service via crafted SFTP response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492698 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ca858b3ed8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 4 vulnerabilities can now be installed.. # libssh2-1-1.11.1-3.1 on GA media Announcement ID: openSUSE-SU-2026:11109-1 Rating: moderate Cross-References: * CVE-2025-15661 * CVE-2026-55199 * CVE-2026-55200 * CVE-2026-7598 CVSS scores: * CVE-2025-15661 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55200 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7598 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7598 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Tumbleweed An update that solves 4 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the libssh2-1-1.11.1-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * libssh2-1 1.11.1-3.1 * libssh2-1-32bit 1.11.1-3.1 * libssh2-devel 1.11.1-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15661.html * https://www.suse.com/security/cve/CVE-2026-55199.html * https://www.suse.com/security/cve/CVE-2026-55200.html * https://www.suse.com/security/cve/CVE-2026-7598.html . An update is now available for libssh2-1 with moderate severity addressing critical security issues in openSUSE Tumbleweed.. libssh2-1 vulnerabilities, openSUSE update, libssh2 security, moderate severity, security advisory. . Severity: moderate. LinuxSecurity.com Team
Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6365-1
This update addresses CVE-2026-7598, a potential heap buffer overflow, which could be triggered remotely by supplying very long username and/or password strings.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1b9134cdc9 2026-06-07 01:06:43.462152+00:00 -------------------------------------------------------------------------------- Name : libssh2 Product : Fedora 43 Version : 1.11.1 Release : 6.fc43 URL : https://www.libssh2.org/ Summary : A library implementing the SSH2 protocol Description : libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10). -------------------------------------------------------------------------------- Update Information: This update addresses CVE-2026-7598, a potential heap buffer overflow, which could be triggered remotely by supplying very long username and/or password strings. -------------------------------------------------------------------------------- ChangeLog: * Fri May 22 2026 Paul Howarth - 1.11.1-6 - Fix CVE-2026-7598: integer overflow via large username or password arguments (https://github.com/libssh2/libssh2/pull/1858) * Fri Jan 16 2026 Fedora Release Engineering - 1.11.1-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2468328 - CVE-2026-7598 libssh2: integer overflow via large username or password arguments [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2468328 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1b9134cdc9' at the command line. For more information, refer tothe dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.