Release date:
2026-08-11 11:08:40 UTC
Description:
- CVE-2026-59843: reject a peer-supplied maximum packet size of zero to
prevent infinite loops in channel writes
- CVE-2026-59848: track outstanding SFTP request IDs and reject responses
with unknown IDs to prevent unbounded client memory growth
- CVE-2026-59845: handle ProxyCommand fork failures before storing the PID
to prevent cleanup from signaling unrelated processes
Updated packages:
-
libssh-0.10.4-8.el9_2.tuxcare.els14.i686.rpm
sha:6f69643548975f830185c5b25bf5cc78dc678324367e046b7d5f53e68c578fe9
-
libssh-0.10.4-8.el9_2.tuxcare.els14.x86_64.rpm
sha:36af9d3e1411cab87ed6c7cb1a910dd9cbbb10a64a80878dd64b8cf52e3c2c62
-
libssh-config-0.10.4-8.el9_2.tuxcare.els14.noarch.rpm
sha:45402cbae217e66dc359f74206628aeff2f96c02e4992a4f609e3f283f32e2b1
-
libssh-devel-0.10.4-8.el9_2.tuxcare.els14.i686.rpm
sha:2053ea11e4907d2eb74a61ef5f477a74faa3bc84f60638315409b018c31a4dbb
-
libssh-devel-0.10.4-8.el9_2.tuxcare.els14.x86_64.rpm
sha:f8a5e33daaa9b682ce862138537e157efd655c00add945a57e50169527770c6d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.