[CLSA-2026:1786549709] libssh: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-12 15:48:42 UTC
Description:
- CVE-2026-59845: check the fork() return code when starting a ProxyCommand so a failed fork is not stored as pid -1 and later killed as a process group - CVE-2026-59843: reject a maximum packet size of 0 in SSH2_MSG_CHANNEL_OPEN and SSH2_MSG_CHANNEL_OPEN_CONFIRMATION and clamp channel writes on remote_maxpacket directly, avoiding the non-progressing loop in channel_write_common() - CVE-2026-59848: track outstanding SFTP request IDs and reject responses carrying an unknown ID instead of queueing them indefinitely
Updated packages:
  • libssh-0.10.4-15.el9_6.tuxcare.els10.i686.rpm
    sha:16ae2f78dbb724875501669af8a9a97f6f707120d2e85b1dc8ee8611c43438b0
  • libssh-0.10.4-15.el9_6.tuxcare.els10.x86_64.rpm
    sha:7a20c83646b6be66c50d8a19b1d9e00747555470b234dc0a60d3da6fa711cb9e
  • libssh-config-0.10.4-15.el9_6.tuxcare.els10.noarch.rpm
    sha:34bd0f1b225a593507c0eb6edaaf266d3524bd869f9ccd9998d407beedbe7977
  • libssh-devel-0.10.4-15.el9_6.tuxcare.els10.i686.rpm
    sha:25cd00b9494d971f5adccca0352618de6cc7bfc66eede818a76f24ab9ee65340
  • libssh-devel-0.10.4-15.el9_6.tuxcare.els10.x86_64.rpm
    sha:1bbc9be578a524ffe5a5f2e3b2854162e923b575ff9de005e8240f1c5b07935a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.