[CLSA-2026:1786012443] libssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-06 10:34:26 UTC
Description:
- CVE-2026-59847: integrity downgrade of AES-GCM ciphers in the OpenSSL backend, where a wrong EVP_DecryptFinal() return-code check let a forged authentication tag pass and silently reduced AES-GCM to AES-CTR - CVE-2026-59850: use-after-free via channel data callbacks invoked on remotely-closed channels, where already-freed channel data could still be handed to application callbacks
Updated packages:
  • libssh-0.9.6-14.el8.tuxcare.els6.i686.rpm
    sha:6ded7382103b68cff521fd8f2f09a6795b57eaf80f79b81ee03a0c8711c1e1b3
  • libssh-0.9.6-14.el8.tuxcare.els6.x86_64.rpm
    sha:f6f2980ce5adbeaf0b764b0fe2923b73d86858b22d64093bc0f7e4d3ae60dbf1
  • libssh-config-0.9.6-14.el8.tuxcare.els6.noarch.rpm
    sha:6fa796e37b7de385725b6b72433da2a3b52e1b6c05e6ae4d8d27b3784b4ef77b
  • libssh-devel-0.9.6-14.el8.tuxcare.els6.i686.rpm
    sha:02afdeccd1505ccbf17a19fdef9a52843b9c1d4df3453e089e54f5b36cb1b262
  • libssh-devel-0.9.6-14.el8.tuxcare.els6.x86_64.rpm
    sha:64c5d67754b2d235d9de084eaab185af72177140b17987426aaafe5d8ad2b6ec
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.