PT-2026-53083 · Libssh2+3 · Libssh2+3

·

CVE-2026-58051

·

Published

2026-06-26

·

Updated

2026-09-07

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions libssh2 versions prior to 1.11.2
Description An issue exists in the public key parsing process where the software expands its public key list using SSH2 REALLOC but fails to zero-initialize new entries before they are populated. If a parse failure occurs and triggers the cleanup path, the libssh2 publickey list free() function may operate on an uninitialized entry. A malicious SSH server providing the public key subsystem can send a malformed response to cause the client to free an uninitialized attrs pointer, leading to a use-after-free condition.
Recommendations Update libssh2 to version 1.11.2 or later.

Exploit

Fix

DoS

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91385
AZL-97395
AZL-97437
BDU:2026-08974
CVE-2026-58051
ECHO-B4F1-7845-4DDA
JLSEC-2026-663
OPENSUSE-SU-2026:11454-1
OPENSUSE-SU-2026:21549-1
RHSA-2026:46535
RHSA-2026:46927
SUSE-SU-2026:23049-1
SUSE-SU-2026:23187-1
SUSE-SU-2026:23214-1
SUSE-SU-2026:23225-1
SUSE-SU-2026:23245-1
SUSE-SU-2026:3525-1
SUSE-SU-2026:3526-1
SUSE-SU-2026:3541-1
USN-8532-1

Affected Products

Linuxmint
Red Os
Ubuntu
Libssh2