[CLSA-2026:1786478300] libssh2: Fix of CVE-2026-66032
Type:
security
Severity:
Important
Release date:
2026-08-11 19:58:28 UTC
Description:
1.11.0.tuxcare.els3-r0: - CVE-2026-66032 null the freed response buffer in sftp_open() to prevent a double free
CVEs fixed:
Updated packages:
  • libssh2-1.11.0.tuxcare.els3-r0.apk
    sha:Q1ItLsYMLCnoTROQUqoHhRpxDpRiU=
  • libssh2-1.11.0.tuxcare.els3-r0.apk
    sha:Q1QYvdvhcB8I1B5ermuaIJoxPVl1w=
  • libssh2-dev-1.11.0.tuxcare.els3-r0.apk
    sha:Q145/pFa2BqO+v2ZvbxpZJPB5TiV0=
  • libssh2-dev-1.11.0.tuxcare.els3-r0.apk
    sha:Q1NpeyAKgDrBQvd4+9GoRpwRDgENs=
  • libssh2-doc-1.11.0.tuxcare.els3-r0.apk
    sha:Q1DG/HYCmXelU9s1Aq3NFlPLjR8lc=
  • libssh2-doc-1.11.0.tuxcare.els3-r0.apk
    sha:Q1aE8nU6/5hD2UcaNRjzt4FkagGgs=
  • libssh2-static-1.11.0.tuxcare.els3-r0.apk
    sha:Q1k2PxakaoaFuuHkaAgxU85QTzoiQ=
  • libssh2-static-1.11.0.tuxcare.els3-r0.apk
    sha:Q1rj3/iLMMoFVSLjIF+4RSACu5zy4=
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.