PT-2026-61847 · Libssh · Libssh

CVE-2026-15370

·

Published

2026-07-21

·

Updated

2026-08-31

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libssh (affected versions not specified)
Description A flaw exists in libssh during SFTP server directory listing. The longname field is constructed using unsafe concatenation into a fixed-size stack buffer. An attacker can trigger a stack buffer overflow by forcing the server to list filenames of sufficient length, which may result in server crashes or potential arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55855
CVE-2026-15370
ECHO-B5B0-C714-39F4
OPENSUSE-SU-2026:11377-1
OPENSUSE-SU-2026:21444-1
RHSA-2026:47768
RHSA-2026:55855
SUSE-SU-2026:22940-1
SUSE-SU-2026:22948-1
SUSE-SU-2026:22956-1
USN-8699-1

Affected Products

Libssh