[CLSA-2026:1786448214] libssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-11 11:37:06 UTC
Description:
- CVE-2026-59847: integrity downgrade of AES-GCM ciphers in the OpenSSL backend, where a wrong EVP_DecryptFinal() return-code check let a forged authentication tag pass and silently reduced AES-GCM to AES-CTR - CVE-2026-59850: use-after-free via channel data callbacks invoked on remotely-closed channels, where already-freed channel data could still be handed to application callbacks
Updated packages:
  • libssh-0.9.4-3.el8.tuxcare.els10.i686.rpm
    sha:69b2ebbe89ba370790004d6c427a898a551f8ffe3fe26de47dc1d16b419d23f4
  • libssh-0.9.4-3.el8.tuxcare.els10.x86_64.rpm
    sha:3df97b974b6f3e8ffae3bc6a7ba62ed714fe182296e3ab247dc86e9f0f97469e
  • libssh-config-0.9.4-3.el8.tuxcare.els10.noarch.rpm
    sha:9f5804a1ee689145a872ef175c466183d462a37bdfbb26ef126a8787ea36c110
  • libssh-devel-0.9.4-3.el8.tuxcare.els10.i686.rpm
    sha:37330f384f14cc89e8517effdd3870212885b76a4219ecfc9f3bb139d45b92fa
  • libssh-devel-0.9.4-3.el8.tuxcare.els10.x86_64.rpm
    sha:98699342d7c9bdf4d6d0f84aa8a16c2e36d50cda49a273be097fa81bd318cdcf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.