PT-2026-23936 · Libssh+3 · Libssh+3

CVE-2026-3731

·

Published

2025-12-11

·

Updated

2026-08-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libssh versions up to 0.11.3
Description A flaw exists in libssh related to the SFTP Extension Name Handler component, specifically within the sftp extensions get name and sftp extensions get data functions in the src/sftp.c file. A manipulation of the idx argument can lead to an out-of-bounds read. This issue is potentially exploitable remotely.
Recommendations Upgrade to version 0.11.4 or 0.12.0.

Exploit

Fix

DoS

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-79544
AZL-79547
BDU:2026-06714
CVE-2026-3731
ECHO-9DB6-4921-AEC5
OESA-2026-1560
OESA-2026-1652
OESA-2026-1653
OESA-2026-1654
OESA-2026-1655
OESA-2026-1656
RHSA-2026:7067
SUSE-SU-2026:0936-1
SUSE-SU-2026:1310-1
SUSE-SU-2026:1344-1
SUSE-SU-2026:1565-1
SUSE-SU-2026:20767-1
SUSE-SU-2026:23056-1
SUSE-SU-2026:3302-1
USN-8093-1
USN-8093-2

Affected Products

Linuxmint
Red Os
Ubuntu
Libssh