RHSA-2026:55855: Important: libssh security update
Important: libssh security update
Other sources
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.Security Fix(es): libssh: libssh: information disclosure via short GSSAPI Curve25519 public key (CVE-2026-59842) libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843) libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844) libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845) libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846) libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847) libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848) libssh: libssh: denial of service via automatic certificate authentication loop (CVE-2026-59849) libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850) libssh: libssh: authentication bypass via missing GSSAPI principal check (CVE-2026-59851) libssh: libssh: stack buffer overflow in SFTP server longname construction (CVE-2026-15370) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libsshto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2 - Upgrade
Upgrade
redhat/libssh-configto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2 - Upgrade
Upgrade
redhat/libssh-debuginfoto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2 - Upgrade
Upgrade
redhat/libssh-debugsourceto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2 - Upgrade
Upgrade
redhat/libssh-develto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2 - Upgrade
Upgrade
redhat/libsshto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2.aa - Upgrade
Upgrade
redhat/libssh-debuginfoto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2.aa - Upgrade
Upgrade
redhat/libssh-debugsourceto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2.aa - Upgrade
Upgrade
redhat/libssh-develto a version that resolves this vulnerability.Fixed in 0.12.0-3.el10_2.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:55855?
The severity of RHSA-2026:55855 is rated as high with a score of 7.
What vulnerabilities are addressed by RHSA-2026:55855?
RHSA-2026:55855 addresses information disclosure via a short GSSAPI Curve25519 public key and denial of service vulnerabilities.
How do I fix RHSA-2026:55855?
To fix RHSA-2026:55855, you should update the libssh packages to the latest available versions provided by Red Hat.
Which software is affected by RHSA-2026:55855?
The affected software includes redhat/libssh, redhat/libssh-debuginfo, redhat/libssh-debugsource, and redhat/libssh-devel.
In which environments is RHSA-2026:55855 applicable?
RHSA-2026:55855 is applicable in Red Hat Enterprise Linux for ARM 64 and IBM z Systems, among other extended life cycle systems.