PT-2026-64380 · Libssh2+2 · Libssh2+2

·

CVE-2026-66033

·

Published

2026-07-24

·

Updated

2026-09-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions libssh2 versions prior to 1.11.1
Description A pre-authentication integer underflow exists in the ssh2 cipher crypt() function within src/openssl.c. A malicious SSH server can trigger this issue during the handshake by negotiating AES-GCM ciphers. The underflow occurs during the calculation of blocksize minus aadlen minus authentication tag length, leading to an out-of-bounds read and a memcpy call with a length argument near SIZE MAX, which results in an immediate process crash.
Recommendations Update to the version containing commit a2ed82d.

Exploit

Fix

DoS

Integer Underflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93402
AZL-97428
CVE-2026-66033
ECHO-BD2E-2758-1B23
JLSEC-2026-1086
OESA-2026-3392
OESA-2026-3395
OESA-2026-3479
OPENSUSE-SU-2026:11454-1
OPENSUSE-SU-2026:21549-1
RHSA-2026:46927
SUSE-SU-2026:23049-1
SUSE-SU-2026:23187-1
SUSE-SU-2026:23214-1
SUSE-SU-2026:23225-1
SUSE-SU-2026:23245-1
SUSE-SU-2026:3525-1
SUSE-SU-2026:3526-1
SUSE-SU-2026:3541-1
USN-8722-1

Affected Products

Linuxmint
Ubuntu
Libssh2