[CLSA-2026:1786012208] libssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-06 10:30:38 UTC
Description:
- CVE-2026-59847: integrity downgrade of AES-GCM ciphers in the OpenSSL backend, where a wrong EVP_DecryptFinal() return-code check let a forged authentication tag pass and silently reduced AES-GCM to AES-CTR - CVE-2026-59850: use-after-free via channel data callbacks invoked on remotely-closed channels, where already-freed channel data could still be handed to application callbacks
Updated packages:
  • libssh-0.9.4-3.el8.tuxcare.els10.i686.rpm
    sha:a6565acf53201959378a70737497868a45243ece929b953e3cf7ae9a4dbcb5f3
  • libssh-0.9.4-3.el8.tuxcare.els10.x86_64.rpm
    sha:f8c0f2f837eece3a161c88581fd7beda0903d8072a5d49ac18cf22c20e51b147
  • libssh-config-0.9.4-3.el8.tuxcare.els10.noarch.rpm
    sha:86e25a78112848d50d66243cb382021973130943606efa5a94f398f138d3116e
  • libssh-devel-0.9.4-3.el8.tuxcare.els10.i686.rpm
    sha:1991e9512dbe0e9b5feb2dc29c5ed390555465a222a9269e93fbaa03ffe1a6e7
  • libssh-devel-0.9.4-3.el8.tuxcare.els10.x86_64.rpm
    sha:f73177801fb485aa5de044ee9a76fa23038100a444742e54a84abd28d972adf1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.