Release date:
2026-08-11 11:19:58 UTC
Description:
* SECURITY UPDATE: double free in SFTP open response handling
- debian/patches/CVE-2026-66032.patch: nullify the freed response data
pointer before requesting a subsequent SFTP handle in sftp_open()
- CVE-2026-66032
Updated packages:
-
libssh2-1_1.8.0-2.1ubuntu0.1+tuxcare.els3_amd64.deb
sha:2d5e23d7e1b344ea119d2f58c0f5fd390374f335
-
libssh2-1-dev_1.8.0-2.1ubuntu0.1+tuxcare.els3_amd64.deb
sha:0fa83246954b3516ab764bb48409cae475f6492c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.