REDHAT-BUG-2498182: Low severity libssh libssh vulnerability
A flaw was found in libssh automatic certificate-based public key authentication. In sshuserauthpublickeyauto() in src/auth.c, the iterator over certificate candidates was not advanced correctly when configured certificates were missing or repeatedly rejected by the server. Under specific non-default certificate configurations, this could cause the client to restart the same authentication attempts indefinitely, leading to denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2498182?
The severity of REDHAT-BUG-2498182 is low.
How do I fix REDHAT-BUG-2498182?
To fix REDHAT-BUG-2498182, ensure that your configurations for certificate-based public key authentication are correct and that valid certificates are available.
What is the impact of REDHAT-BUG-2498182?
The impact of REDHAT-BUG-2498182 can result in failure of automatic certificate-based authentication in libssh.
Which software is affected by REDHAT-BUG-2498182?
The software affected by REDHAT-BUG-2498182 is libssh.
When was REDHAT-BUG-2498182 published?
REDHAT-BUG-2498182 was published on July 8, 2026.