[CLSA-2026:1776705065] libssh: Fix of CVE-2026-0968
Type:
security
Severity:
Low
Release date:
2026-04-20 17:11:10 UTC
Description:
- CVE-2026-0968: sanitize input handling in sftp_parse_longname() to prevent OOB read when processing malformed SFTP longname fields, add unit tests
Updated packages:
  • libssh-0.9.6-14.el8.tuxcare.els4.i686.rpm
    sha:2262d1827fb66481d03ae591089b03a5da0559494b6d075c94bf4d768f7cc6d2
  • libssh-0.9.6-14.el8.tuxcare.els4.x86_64.rpm
    sha:447c9f94ada2ac84a7df2b7f54d63cff3bfa4fb7969f4ff6caabefbcd6d7dcbb
  • libssh-config-0.9.6-14.el8.tuxcare.els4.noarch.rpm
    sha:056083aa3bce430bbc2801bbe22765a16d282b5b77868c2742639765f254172d
  • libssh-devel-0.9.6-14.el8.tuxcare.els4.i686.rpm
    sha:18046992ca710be986f2cae56d7d4a54f7ac5bd252d3368e9dd079ac7547996c
  • libssh-devel-0.9.6-14.el8.tuxcare.els4.x86_64.rpm
    sha:0e1948f8010aaaed95f3acadd9970c7b6ceb7b2fd52f6554c1c80eccd1a06e37
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.