Multiple vulnerabilities have been found in libssh2, the worst of which could result in remote code execution. Affected packages Package net-libs/libssh2 on all architectures Affected versions < 1.11.1-r2 Unaffected versions >= 1.11.1-r2 Background libssh2 is a library implementing the SSH2 protocol. Description Multiple vulnerabilities have been discovered in libssh2. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All libssh2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-libs/libssh2-1.11.1-r2" References CVE-2025-15661 CVE-2026-7598 CVE-2026-55199 CVE-2026-55200 Release date August 20, 2026 Latest revision August 20, 2026: 1 Severity high Exploitable remote Bugzilla entries 977961
Multiple vulnerabilities in libssh2, including at least one high-severity remote code execution flaw (CVE-2026-7598, CVSS 7.3), affect all versions up to and including 1.11.1. The authoritative NVD data confirms the affected version range as libssh2 <= 1.11.1, and the GLSA advisory specifies the fixed version as >= 1.11.1-r2. No workaround is available, requiring an immediate upgrade to the patched release.