Search CVE reports


Toggle filters

1 – 10 of 50 results


CVE-2026-0968

Medium priority
Needs evaluation

[Denial of Service due to malformed SFTP message]

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0967

Medium priority
Needs evaluation

[Denial of Service via inefficient regular expression processing]

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0966

Low priority
Needs evaluation

[Buffer underflow in ssh_get_hexa() on invalid input]

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0965

Low priority
Needs evaluation

[Denial of Service via improper configuration file handling]

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0964

Medium priority
Needs evaluation

[Improper sanitation of paths received from SCP servers]

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-14821

Medium priority
Not affected

[Insecure default configuration leads to local man-in-the-middle attacks on Windows]

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-8277

Low priority
Needs evaluation

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory....

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8114

Low priority
Fixed

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-5987

Medium priority
Fixed

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context....

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-5449

Medium priority
Fixed

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh Not affected Not affected Not affected Not affected
Show less packages