RHSA-2026:61752: Important: libssh2 security update
Important: libssh2 security update
Other sources
The libssh2 packages provide a library that implements the SSH2 protocol.Security Fix(es): libssh2: integer overflow via large username or password arguments (CVE-2026-7598) libssh2: libssh2: Heap buffer overflow via integer overflow in publickey attribute allocation (CVE-2026-58050) libssh2: libssh2: Arbitrary code execution via double-free in SFTP session (CVE-2026-66032) libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read (CVE-2026-66034) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libssh2to a version that resolves this vulnerability.Fixed in 1.8.0-4.el7_9.2 - Upgrade
Upgrade
redhat/libssh2-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-4.el7_9.2 - Upgrade
Upgrade
redhat/libssh2-develto a version that resolves this vulnerability.Fixed in 1.8.0-4.el7_9.2 - Upgrade
Upgrade
redhat/libssh2-docsto a version that resolves this vulnerability.Fixed in 1.8.0-4.el7_9.2 - Upgrade
Upgrade
libssh2to a version that resolves this vulnerability.Patch CVE-2026-66032 - Upgrade
Upgrade
libssh2to a version that resolves this vulnerability.Patch CVE-2026-58050 - Upgrade
Upgrade
libssh2to a version that resolves this vulnerability.Patch CVE-2026-66034 - Upgrade
Upgrade
libssh2to a version that resolves this vulnerability.Patch CVE-2026-7598