RHSA-2026:24349: Moderate: libssh security update
Moderate: libssh security update
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libsshto a version that resolves this vulnerability.Fixed in 0.9.4-2.el8_4.2 - Upgrade
Upgrade
redhat/libssh-configto a version that resolves this vulnerability.Fixed in 0.9.4-2.el8_4.2 - Upgrade
Upgrade
redhat/libssh-debuginfoto a version that resolves this vulnerability.Fixed in 0.9.4-2.el8_4.2 - Upgrade
Upgrade
redhat/libssh-debugsourceto a version that resolves this vulnerability.Fixed in 0.9.4-2.el8_4.2 - Upgrade
Upgrade
redhat/libssh-develto a version that resolves this vulnerability.Fixed in 0.9.4-2.el8_4.2
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:24349?
The severity of RHSA-2026:24349 is classified as medium with a CVSS score of 4.
What vulnerabilities are fixed in RHSA-2026:24349?
RHSA-2026:24349 addresses the incorrect return code handling in ssh_kdf() in libssh, specifically identified as CVE-2025-5372.
How do I fix RHSA-2026:24349?
To fix RHSA-2026:24349, apply the security update for libssh as detailed in the advisory.
What products are affected by RHSA-2026:24349?
The affected products include redhat/libssh and its related packages such as redhat/libssh-debuginfo and redhat/libssh-devel.
Is RHSA-2026:24349 critical for my systems?
While RHSA-2026:24349 is not critical, it is important to apply the update to mitigate potential security risks.