- What: Security update for libssh2
- Impact: Systems using Red Hat Enterprise Linux 7 may be affected
Red Hat Product Errata RHSA-2026:61752 - Security Advisory Issued: 2026-08-31 Updated: 2026-08-31 RHSA-2026:61752 - Security Advisory Overview Updated Packages Synopsis Important: libssh2 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libssh2 is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libssh2 packages provide a library that implements the SSH2 protocol. Security Fix(es): libssh2: integer overflow via large username or password arguments (CVE-2026-7598) libssh2: libssh2: Heap buffer overflow via integer overflow in publickey attribute allocation (CVE-2026-58050) libssh2: libssh2: Arbitrary code execution via double-free in SFTP session (CVE-2026-66032) libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read (CVE-2026-66034) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le Fixes BZ - 2464597 - CVE-2026-7598 libssh2: integer overflow via large username or password arguments BZ - 2493955 - CVE-2026-58050 libssh2: libssh2: Heap buffer overflow via integer overflow in publickey attribute allocation BZ - 2506857 - CVE-2026-66032 libssh2: libssh2: Arbitrary code execution via double-free in SFTP session BZ - 2506860 - CVE-2026-66034 libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read CVEs CVE-2026-7598 CVE-2026-58050 CVE-2026-66032 CVE-2026-66034 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 SRPM libssh2-1.8.0-4.el7_9.2.src.rpm SHA-256: e1e61bcc2c79b646875b5452b528b6b6351250af4e2a3c896a624dc594837216 x86_64 libssh2-1.8.0-4.el7_9.2.i686.rpm SHA-256: 59cd1e5cd26151417587f948c6be7c1420021687298a947b8b4894b4a8090cb4 libssh2-1.8.0-4.el7_9.2.x86_64.rpm SHA-256: 46c6afefcf79e0692161750267e2e8f2084b732f7b520ea5fec2efd0d2264909 libssh2-debuginfo-1.8.0-4.el7_9.2.i686.rpm SHA-256: 7b85fb0460c63ce7d8c6725716dab26695b7989a2d59f583c9ec534db3e20d25 libssh2-debuginfo-1.8.0-4.el7_9.2.i686.rpm SHA-256: 7b85fb0460c63ce7d8c6725716dab26695b7989a2d59f583c9ec534db3e20d25 libssh2-debuginfo-1.8.0-4.el7_9.2.x86_64.rpm SHA-256: b94db91c82081a03be47d2dda51e8e50a89013c1cc9ef1cc65d70e56d6bed890 libssh2-debuginfo-1.8.0-4.el7_9.2.x86_64.rpm SHA-256: b94db91c82081a03be47d2dda51e8e50a89013c1cc9ef1cc65d70e56d6bed890 libssh2-devel-1.8.0-4.el7_9.2.i686.rpm SHA-256: d1217167130217c2247a1b225a6d9ad9233aae03337af2414ee37eb9cd98e53a libssh2-devel-1.8.0-4.el7_9.2.x86_64.rpm SHA-256: ef5f40e093cd50e2ec54cc56ed19ca625c70eb74ada9a661a2ec6f70ef66da87 libssh2-docs-1.8.0-4.el7_9.2.noarch.rpm SHA-256: ef792e49d34b08227b521fc8ff762281fb88a6f54cb48d5335c53c8ccf44142e Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 SRPM libssh2-1.8.0-4.el7_9.2.src.rpm SHA-256: e1e61bcc2c79b646875b5452b528b6b6351250af4e2a3c896a624dc594837216 s390x libssh2-1.8.0-4.el7_9.2.s390.rpm SHA-256: e3c3e96ca7a76af8e99df34db660ad32fe9063e4644a1b7def3345ef5e718f0b libssh2-1.8.0-4.el7_9.2.s390x.rpm SHA-256: 4588370a32afd0fbc887c7fa9d71e56d0fb63d55c904b56ac4775f475445b412 libssh2-debuginfo-1.8.0-4.el7_9.2.s390.rpm SHA-256: c1659e4441af49372b9469c70911ee56b389eedd3b4b7cc99c075f382ed0a193 libssh2-debuginfo-1.8.0-4.el7_9.2.s390.rpm SHA-256: c1659e4441af49372b9469c70911ee56b389eedd3b4b7cc99c075f382ed0a193 libssh2-debuginfo-1.8.0-4.el7_9.2.s390x.rpm SHA-256: 97a1e631caa0c9cebf1e344d9620ab955e00bfb3ec39cda0b1063fd4488f4dbb libssh2-debuginfo-1.8.0-4.el7_9.2.s390x.rpm SHA-256: 97a1e631caa0c9cebf1e344d9620ab955e00bfb3ec39cda0b1063fd4488f4dbb libssh2-devel-1.8.0-4.el7_9.2.s390.rpm SHA-256: 015ceaab0ea934dbdef196fc7c85f14f937b74163f1846da167d8ca924e278fe libssh2-devel-1.8.0-4.el7_9.2.s390x.rpm SHA-256: 74c8755fdf9f4b05365b6a34de4a6d6af5b620c0efe675fb14cac131d6638670 libssh2-docs-1.8.0-4.el7_9.2.noarch.rpm SHA-256: ef792e49d34b08227b521fc8ff762281fb88a6f54cb48d5335c53c8ccf44142e Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 SRPM libssh2-1.8.0-4.el7_9.2.src.rpm SHA-256: e1e61bcc2c79b646875b5452b528b6b6351250af4e2a3c896a624dc594837216 ppc64 libssh2-1.8.0-4.el7_9.2.ppc.rpm SHA-256: c6580a063a81d2dd30d48eb0923b2a8aba762ee281c2105a9f619cfabc8573c7 libssh2-1.8.0-4.el7_9.2.ppc64.rpm SHA-256: b57b0191c4d0a37056de119a129432e1f4d636c753271d7ca6e289e15acb9d08 libssh2-debuginfo-1.8.0-4.el7_9.2.ppc.rpm SHA-256: 824eb603734d4c798e558bc963b2e6a27a2ca40a9833020d1b77ee8997b9628c libssh2-debuginfo-1.8.0-4.el7_9.2.ppc.rpm SHA-256: 824eb603734d4c798e558bc963b2e6a27a2ca40a9833020d1b77ee8997b9628c libssh2-debuginfo-1.8.0-4.el7_9.2.ppc64.rpm SHA-256: 078d03027e93c38c0aab8fb2b3c2f7abf8b6f198ea7cc7545753f0ac55b27278 libssh2-debuginfo-1.8.0-4.el7_9.2.ppc64.rpm SHA-256: 078d03027e93c38c0aab8fb2b3c2f7abf8b6f198ea7cc7545753f0ac55b27278 libssh2-devel-1.8.0-4.el7_9.2.ppc.rpm SHA-256: 5408a2bb650b80e8a07c64e69c847b5f02f28dd4b6a307ed12f65dbca80e7533 libssh2-devel-1.8.0-4.el7_9.2.ppc64.rpm SHA-256: 3140d7fe06fad926f49eaa08feebabfd124fae033719cda1dd9980226b30eba0 libssh2-docs-1.8.0-4.el7_9.2.noarch.rpm SHA-256: ef792e49d34b08227b521fc8ff762281fb88a6f54cb48d5335c53c8ccf44142e Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 SRPM libssh2-1.8.0-4.el7_9.2.src.rpm SHA-256: e1e61bcc2c79b646875b5452b528b6b6351250af4e2a3c896a624dc594837216 ppc64le libssh2-1.8.0-4.el7_9.2.ppc64le.rpm SHA-256: 4a6bd0d6b938636e115d20444dd2fb4f3bf1fda3e00c0b00d03750d78627bea9 libssh2-debuginfo-1.8.0-4.el7_9.2.ppc64le.rpm SHA-256: 028f37fed340ee9a32d7d93805b760996b589c05ace1c723bbe5c955c1186015 libssh2-debuginfo-1.8.0-4.el7_9.2.ppc64le.rpm SHA-256: 028f37fed340ee9a32d7d93805b760996b589c05ace1c723bbe5c955c1186015 libssh2-devel-1.8.0-4.el7_9.2.ppc64le.rpm SHA-256: 6fa292b92d43191f29d8a9d1411a34b38135fab4adcb0e63f26f7157ba24491d libssh2-docs-1.8.0-4.el7_9.2.noarch.rpm SHA-256: ef792e49d34b08227b521fc8ff762281fb88a6f54cb48d5335c53c8ccf44142e The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .