{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos7els/vex/2026/cve-2026-66034-els_os-centos7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-01T00:27:59Z",
      "generator": {
        "date": "2026-08-01T00:27:58Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-66034-ELS_OS-CENTOS7ELS",
      "initial_release_date": "2026-07-24T17:17:00Z",
      "revision_history": [
        {
          "date": "2026-07-24T17:17:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-31T14:50:33Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-01T00:27:59Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-66034"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.i686",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.i686",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2@1.8.0-4.el7_9.1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.i686",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.i686",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2-devel@1.8.0-4.el7_9.1?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.x86_64",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.x86_64",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2@1.8.0-4.el7_9.1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2-devel@1.8.0-4.el7_9.1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
                "product": {
                  "name": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
                  "product_id": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/libssh2-docs@1.8.0-4.el7_9.1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2@1.8.0-4.el7_9.1.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2@1.8.0-4.el7_9.1.tuxcare.els2?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-devel@1.8.0-4.el7_9.1.tuxcare.els2?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-devel@1.8.0-4.el7_9.1.tuxcare.els1?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2@1.8.0-4.el7_9.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                  "product_id": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2@1.8.0-4.el7_9.1.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-devel@1.8.0-4.el7_9.1.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                  "product_id": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-devel@1.8.0-4.el7_9.1.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch",
                "product": {
                  "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch",
                  "product_id": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-docs@1.8.0-4.el7_9.1.tuxcare.els2?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
                "product": {
                  "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
                  "product_id": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libssh2-docs@1.8.0-4.el7_9.1.tuxcare.els1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch"
        },
        "product_reference": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch"
        },
        "product_reference": "libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.i686"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-0:1.8.0-4.el7_9.1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.x86_64"
        },
        "product_reference": "libssh2-0:1.8.0-4.el7_9.1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.x86_64"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-devel-0:1.8.0-4.el7_9.1.i686 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.i686"
        },
        "product_reference": "libssh2-devel-0:1.8.0-4.el7_9.1.i686",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.noarch"
        },
        "product_reference": "libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-66034",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.i686",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
          "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.x86_64",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.i686",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
          "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
          "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
          "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
          "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-66034"
        },
        {
          "category": "external",
          "summary": "https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9",
          "url": "https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9"
        },
        {
          "category": "external",
          "summary": "https://github.com/libssh2/libssh2/pull/2202",
          "url": "https://github.com/libssh2/libssh2/pull/2202"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem",
          "url": "https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem"
        }
      ],
      "release_date": "2026-07-24T17:17:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-31T21:19:10.654952Z",
          "details": "Risk is limited to client applications that explicitly open the RFC 4819 “publickey” subsystem and call libssh2_publickey_list_fetch() against a malicious SSH server; standard authentication, exec, SFTP/SCP operations do not reach this code path. The flaw results in a heap out-of-bounds read and possible client-process crash (no integrity impact), with high attack complexity and user interaction required to initiate a connection to an attacker-controlled server. In centrally managed enterprise environments where libssh2 is used for routine file transfers or automation against known hosts and the publickey management APIs are not invoked, practical exploitability is negligible and this CVE can be deprioritized.",
          "product_ids": [
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.i686",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
            "CentOS-7:libssh2-0:1.8.0-4.el7_9.1.x86_64",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.i686",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.i686",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els1.x86_64",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.i686",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.tuxcare.els2.x86_64",
            "CentOS-7:libssh2-devel-0:1.8.0-4.el7_9.1.x86_64",
            "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.noarch",
            "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els1.noarch",
            "CentOS-7:libssh2-docs-0:1.8.0-4.el7_9.1.tuxcare.els2.noarch"
          ]
        }
      ]
    }
  ]
}