Release date:
2026-08-12 00:39:33 UTC
Description:
- CVE-2026-66032: sftp_open() nullifies data after freeing it in the FX_OK
branch, so a server that answers SSH_FXP_OPEN with SSH_FXP_STATUS/FX_OK and
then makes the follow-up HANDLE request fail with anything other than EAGAIN
can no longer drive the if(badness) arm into freeing the same pointer twice
Updated packages:
-
libssh2-1.4.3-12.amzn2.2.8.tuxcare.els2.i686.rpm
sha:2800831cb567a81e5781a7f2e2add0d52ac5dcd0b94d96e50ad728e44eccaa96
-
libssh2-1.4.3-12.amzn2.2.8.tuxcare.els2.x86_64.rpm
sha:c2e1981e40e1b05cc3bfd9003f145ff7ccf52e920b094a4a9650d3441797f65e
-
libssh2-devel-1.4.3-12.amzn2.2.8.tuxcare.els2.x86_64.rpm
sha:912a0a5ed311e803407aa9f9a4aef382fa506ce23e74a77174205ae20180d6dc
-
libssh2-docs-1.4.3-12.amzn2.2.8.tuxcare.els2.noarch.rpm
sha:ca23f1fdaedf0aa3152e73c479da42cabe048a6c485889a2d5d28117bc7738bd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.