- What: libssh vulnerability fixed in Ubuntu
- Impact: Potential denial of service or unexpected behavior
Ubuntu Security Notices USN-8093-2 USN-8093-2: libssh vulnerability Publication date 19 August 2026 Overview libssh could be made to crash or behave unexpectedly. Releases 26.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages libssh - A tiny C SSH library Details USN-8093-1 fixed a vulnerability in libssh. This update provides the corresponsing fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that libssh incorrectly performed bounds checking when processing SFTP extensions. If a client application queried extension data out of bounds, it could cause the application to crash, resulting in a denial of service, or exhibit unintended behavior. USN-8093-1 fixed a vulnerability in libssh. This update provides the corresponsing fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that libssh incorrectly performed bounds checking when processing SFTP extensions. If a client application queried extension data out of bounds, it could cause the application to crash, resulting in a denial of service, or exhibit unintended behavior. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute libssh-4 – 0.11.3-1ubuntu2 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-3731 CVE-2026-3731 Related notices USN-8093-1 USN-8093-1