Release date:
2026-08-11 19:54:37 UTC
Description:
* SECURITY UPDATE: double free in sftp_open() reachable by a malicious
SSH server against an authenticated client opening an SFTP session
- debian/patches/CVE-2026-66032.patch: NULL the response buffer after
freeing it on the FX_OK path, so the if(badness) arm cannot free the
same stale pointer a second time when sftp_packet_require() fails
with anything other than LIBSSH2_ERROR_EAGAIN, in src/sftp.c
- CVE-2026-66032
Updated packages:
-
libssh2-1_1.8.0-1ubuntu0.1+tuxcare.els3_amd64.deb
sha:a769f3979c965039c00d9f4a337fd7c94f6edb62
-
libssh2-1-dev_1.8.0-1ubuntu0.1+tuxcare.els3_amd64.deb
sha:aebbaff0c010529c01cb0750f27ff2b9b949019a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.