[CLSA-2026:1786471937] libssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-13 05:19:37 UTC
Description:
- CVE-2026-59847: fix AES-GCM tag verification and encryption finalization checks in the OpenSSL backend to preserve integrity protection - CVE-2026-59850: avoid processing DATA packets on remotely closed channels to prevent use-after-free on channel data callbacks
Updated packages:
  • libssh-0.10.4-15.el9_6.tuxcare.els9.i686.rpm
    sha:e29214922d01d6ada040b0f7be92208b3d7f6fff65c98df720176d6067c88b00
  • libssh-0.10.4-15.el9_6.tuxcare.els9.x86_64.rpm
    sha:19960f95c54f8755355db613aa70356ad1b3034affaaef11239fafce41d9e53e
  • libssh-config-0.10.4-15.el9_6.tuxcare.els9.noarch.rpm
    sha:eab0e4ae5f143f768bdc1e7ad0c94faa71af9b2287140272bcd2cda65586bf93
  • libssh-devel-0.10.4-15.el9_6.tuxcare.els9.i686.rpm
    sha:d8c9296eda0cf059a28035a994b24694e23b774d46903213a9e7b9add84cc69c
  • libssh-devel-0.10.4-15.el9_6.tuxcare.els9.x86_64.rpm
    sha:fa853047831f7017298ad1d1a618f22013ba4c447886dc63bc964024e099047b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.