[CLSA-2026:1786447189] Fix CVE(s): CVE-2026-66032
Type:
security
Severity:
Important
Release date:
2026-08-11 11:19:58 UTC
Description:
* SECURITY UPDATE: double free in SFTP open response handling - debian/patches/CVE-2026-66032.patch: nullify the freed response data pointer before requesting a subsequent SFTP handle in sftp_open() - CVE-2026-66032
CVEs fixed:
Updated packages:
  • libssh2-1_1.8.0-2.1ubuntu0.1+tuxcare.els3_amd64.deb
    sha:2d5e23d7e1b344ea119d2f58c0f5fd390374f335
  • libssh2-1-dev_1.8.0-2.1ubuntu0.1+tuxcare.els3_amd64.deb
    sha:0fa83246954b3516ab764bb48409cae475f6492c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.