{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos7els/vex/2026/cve-2026-66033-els_os-centos7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-01T00:27:58Z",
      "generator": {
        "date": "2026-08-01T00:27:57Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-66033-ELS_OS-CENTOS7ELS",
      "initial_release_date": "2026-07-24T17:17:00Z",
      "revision_history": [
        {
          "date": "2026-07-24T17:17:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-31T14:50:32Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-01T00:27:58Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-66033"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.i686",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.i686",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2@1.8.0-4.el7_9.1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.i686",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.i686",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2-devel@1.8.0-4.el7_9.1?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.x86_64",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.x86_64",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2@1.8.0-4.el7_9.1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2-devel@1.8.0-4.el7_9.1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
                "product": {
                  "name": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
                  "product_id": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2-docs@1.8.0-4.el7_9.1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2@1.8.0-4.el7_9.1.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2@1.8.0-4.el7_9.1.tuxcare.els2?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-devel@1.8.0-4.el7_9.1.tuxcare.els2?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-devel@1.8.0-4.el7_9.1.tuxcare.els1?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2@1.8.0-4.el7_9.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2@1.8.0-4.el7_9.1.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-devel@1.8.0-4.el7_9.1.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-devel@1.8.0-4.el7_9.1.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch",
                "product": {
                  "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch",
                  "product_id": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-docs@1.8.0-4.el7_9.1.tuxcare.els2?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
                "product": {
                  "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
                  "product_id": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-docs@1.8.0-4.el7_9.1.tuxcare.els1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch"
        },
        "product_reference": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch"
        },
        "product_reference": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.i686"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.x86_64"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.x86_64"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.i686"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.noarch"
        },
        "product_reference": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-66033",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.i686",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.x86_64",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.i686",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
          "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
          "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
          "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-66033"
        },
        {
          "category": "external",
          "summary": "https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6",
          "url": "https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6"
        },
        {
          "category": "external",
          "summary": "https://github.com/libssh2/libssh2/pull/2401",
          "url": "https://github.com/libssh2/libssh2/pull/2401"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/libssh2-integer-underflow-dos-via-aes-gcm-cipher-negotiation",
          "url": "https://www.vulncheck.com/advisories/libssh2-integer-underflow-dos-via-aes-gcm-cipher-negotiation"
        }
      ],
      "release_date": "2026-07-24T17:17:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-31T21:19:21.965484Z",
          "details": "This is a client-side, pre-authentication denial-of-service only: it requires the client to initiate a connection to a malicious SSH server that negotiates an AES‑GCM cipher, and the impact is limited to crashing the client process with no confidentiality or integrity loss. The flaw resides in libssh2’s OpenSSL backend (src/openssl.c), so builds using other crypto backends are not affected, and the condition is only reachable if AES‑GCM is actually offered and selected during cipher negotiation. In typical centrally managed enterprise environments where clients connect to known hosts, this scenario is rare and operational impact is limited to the availability of the calling application, making it reasonable to deprioritize.",
          "product_ids": [
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.i686",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.x86_64",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.i686",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
            "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
            "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
            "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch"
          ]
        }
      ]
    }
  ]
}