[CLSA-2026:1786466122] libssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 01:37:01 UTC
Description:
- CVE-2026-59847: fix incorrect return-code check of EVP_EncryptFinal / EVP_DecryptFinal that could bypass AES-GCM tag verification - CVE-2026-59850: reject SSH_MSG_CHANNEL_DATA received after remote close to avoid processing data on closed channels
Updated packages:
  • libssh-0.10.4-8.el9_2.tuxcare.els13.i686.rpm
    sha:b56c279edb8b336aacedb56eacee142e97a4b8debd63dd4ed9ddcb0e983e3240
  • libssh-0.10.4-8.el9_2.tuxcare.els13.x86_64.rpm
    sha:33f789bd9edb40f26dd85d8b544a86cb1eb2fd474bfe61ef5364be791ab033b0
  • libssh-config-0.10.4-8.el9_2.tuxcare.els13.noarch.rpm
    sha:6ec6ae4b20309949c48e9c9dc782aaa0b6be7fea4ec0223cdd970fc644d4c2e5
  • libssh-devel-0.10.4-8.el9_2.tuxcare.els13.i686.rpm
    sha:108e6e6b50350cf061b76503a3db6d85c70a353c9659c2110a32ae02ce12e733
  • libssh-devel-0.10.4-8.el9_2.tuxcare.els13.x86_64.rpm
    sha:49d6e4a3fe58cb02544bacd6642e2bfdb82672a18086307f3a061fc47de991c0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.