CVE-2026-59842

⚪ Do wiadomości

Błąd w libssh umożliwia zdalnemu atakującemu ujawnienie fragmentów pamięci serwera.

CVSS
3.7
EPSS
0.4%
Exploit
none
Vendor
redhat
Opis źródłowy (NVD)

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-07-21 12:18:57 UTC
Ostatnia modyfikacja (NVD)2026-08-19 05:17:04 UTC
Referencje