REDHAT-BUG-2498178: Medium severity libssh vulnerability
A flaw was found in libssh client-side ProxyCommand handling. In sshsocketconnectproxycommand() in src/socket.c, the return value of fork() was not checked before being stored as the proxy child PID. If fork() fails, the value -1 can be retained in state and later used during cleanup, causing signals to be sent across the caller's accessible process tree. In deployments that use ProxyCommand, this can lead to local denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2498178?
The severity of REDHAT-BUG-2498178 is medium with a score of 4.
What issues does REDHAT-BUG-2498178 present?
REDHAT-BUG-2498178 presents a flaw in the libssh client-side ProxyCommand handling that can lead to improper PID management.
How do I fix REDHAT-BUG-2498178?
To fix REDHAT-BUG-2498178, ensure that your version of libssh is updated to the latest available release that addresses this vulnerability.
Which software is affected by REDHAT-BUG-2498178?
The software affected by REDHAT-BUG-2498178 is libssh.
When was REDHAT-BUG-2498178 published?
REDHAT-BUG-2498178 was published on July 8, 2026.