[CLSA-2026:1786495157] libssh2: Fix of CVE-2026-66032
Type:
security
Severity:
Important
Release date:
2026-08-12 00:39:33 UTC
Description:
- CVE-2026-66032: sftp_open() nullifies data after freeing it in the FX_OK branch, so a server that answers SSH_FXP_OPEN with SSH_FXP_STATUS/FX_OK and then makes the follow-up HANDLE request fail with anything other than EAGAIN can no longer drive the if(badness) arm into freeing the same pointer twice
CVEs fixed:
Updated packages:
  • libssh2-1.4.3-12.amzn2.2.8.tuxcare.els2.i686.rpm
    sha:2800831cb567a81e5781a7f2e2add0d52ac5dcd0b94d96e50ad728e44eccaa96
  • libssh2-1.4.3-12.amzn2.2.8.tuxcare.els2.x86_64.rpm
    sha:c2e1981e40e1b05cc3bfd9003f145ff7ccf52e920b094a4a9650d3441797f65e
  • libssh2-devel-1.4.3-12.amzn2.2.8.tuxcare.els2.x86_64.rpm
    sha:912a0a5ed311e803407aa9f9a4aef382fa506ce23e74a77174205ae20180d6dc
  • libssh2-docs-1.4.3-12.amzn2.2.8.tuxcare.els2.noarch.rpm
    sha:ca23f1fdaedf0aa3152e73c479da42cabe048a6c485889a2d5d28117bc7738bd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.