PT-2026-53082 · Libssh2+3 · Libssh2+3

·

CVE-2026-58050

·

Published

2026-06-27

·

Updated

2026-09-07

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libssh2 versions prior to 1.11.2
Description An integer overflow occurs when the software reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response. This value is used in the allocation num attrs * sizeof(libssh2 publickey attribute) without bounds checking. On 32-bit platforms, this multiplication can overflow, resulting in an undersized buffer. A malicious SSH server can then exploit this to write past the allocation, leading to a heap buffer overflow in a connecting client.
Recommendations Update libssh2 to a version newer than 1.11.1.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97407
AZL-97434
BDU:2026-08915
CVE-2026-58050
ECHO-DAFD-2EC3-4DF0
JLSEC-2026-662
OESA-2026-3392
OESA-2026-3393
OESA-2026-3394
OESA-2026-3395
OESA-2026-3479
OPENSUSE-SU-2026:11454-1
OPENSUSE-SU-2026:21549-1
RHSA-2026:54070
RHSA-2026:61752
SUSE-SU-2026:23049-1
SUSE-SU-2026:23187-1
SUSE-SU-2026:23214-1
SUSE-SU-2026:23225-1
SUSE-SU-2026:23245-1
SUSE-SU-2026:3525-1
SUSE-SU-2026:3526-1
SUSE-SU-2026:3541-1
USN-8532-1

Affected Products

Linuxmint
Red Os
Ubuntu
Libssh2