> USN-8799-1: libssh2 vulnerabilities
[DATE: 22/09/2026 03:58]
[LANGUAGE: EN]
It was discovered that libssh2 incorrectly handled certain publickey
subsystem attributes. A remote attacker controlling a malicious SSH server
could use this issue to cause a denial of service or possibly execute
arbitrary code.
(CVE-2026-58050)
It was discovered that libssh2 did not properly initialize publickey list
entries before parsing. A remote attacker controlling a malicious SSH
server could use this issue to cause a denial of service or possibly
execute arbitrary code. (CVE-2026-58051)
It was discovered that libssh2 incorrectly handled certain SFTP server
responses. A remote attacker controlling an SSH server could use this issue
to cause libssh2 to crash or possibly execute arbitrary code.
(CVE-2026-66032)
It was discovered that libssh2 did not properly check bounds in certain
publickey subsystem responses. A remote attacker controlling a malicious
SSH server could use this issue to cause a denial of service or possibly
execute arbitrary code.. (CVE-2026-66034)