- What: libssh security update released
- Impact: Red Hat Enterprise Linux 8 users may be affected
Red Hat Product Errata RHSA-2026:62218 - Security Advisory Issued: 2026-09-01 Updated: 2026-09-01 RHSA-2026:62218 - Security Advisory Overview Updated Packages Synopsis Moderate: libssh security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libssh is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description libssh is a library which implements the SSH protocol. It can be used to implement client and server applications. Security Fix(es): libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843) libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844) libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845) libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846) libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847) libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848) libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2498176 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size BZ - 2498177 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length BZ - 2498178 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure BZ - 2498179 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion BZ - 2498180 - CVE-2026-59847 libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification BZ - 2498181 - CVE-2026-59848 libssh: libssh: denial of service via SFTP responses with unknown request IDs BZ - 2498183 - CVE-2026-59850 libssh: libssh: use-after-free via data callbacks on closed channels CVEs CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b x86_64 libssh-0.9.6-17.el8_10.i686.rpm SHA-256: 1e8870229bc1c60428e3e760e516b123ca8545d67f864ca11c7ae6313ed2031b libssh-0.9.6-17.el8_10.x86_64.rpm SHA-256: 6b63ff7d5535f6b2e0c59c721346bccc27aa8c69e91c1f91aa5164841d25fe6c libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e libssh-debuginfo-0.9.6-17.el8_10.i686.rpm SHA-256: 6c35bfc67ac4da8a774438533093f4f7cca9715bc0dd89a2f48604179786b7f1 libssh-debuginfo-0.9.6-17.el8_10.i686.rpm SHA-256: 6c35bfc67ac4da8a774438533093f4f7cca9715bc0dd89a2f48604179786b7f1 libssh-debuginfo-0.9.6-17.el8_10.x86_64.rpm SHA-256: 126cad613e54b435f9c9af9b0c01657acc25eca20e4e2ef0e41bf402aeff0819 libssh-debuginfo-0.9.6-17.el8_10.x86_64.rpm SHA-256: 126cad613e54b435f9c9af9b0c01657acc25eca20e4e2ef0e41bf402aeff0819 libssh-debugsource-0.9.6-17.el8_10.i686.rpm SHA-256: 33c749839225fbafb2e873894731da3c1ddcd58e0857f7f8ad1425cf9243916d libssh-debugsource-0.9.6-17.el8_10.i686.rpm SHA-256: 33c749839225fbafb2e873894731da3c1ddcd58e0857f7f8ad1425cf9243916d libssh-debugsource-0.9.6-17.el8_10.x86_64.rpm SHA-256: 90ee6393194e7798e74317676e162ff7e0e5678b8c4bd866487c266cf7141439 libssh-debugsource-0.9.6-17.el8_10.x86_64.rpm SHA-256: 90ee6393194e7798e74317676e162ff7e0e5678b8c4bd866487c266cf7141439 libssh-devel-0.9.6-17.el8_10.i686.rpm SHA-256: ebb1c09208865f3dad62c6e2b5166a1a1bc52b6b2004fb8063145dcc03d69729 libssh-devel-0.9.6-17.el8_10.x86_64.rpm SHA-256: 289409df706a04ce80cc55e4ad40a3c9494063a8a871392a0b8f359689cc5bd1 Red Hat Enterprise Linux for IBM z Systems 8 SRPM libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b s390x libssh-0.9.6-17.el8_10.s390x.rpm SHA-256: 24ada9a39b08317ebd00b79919556ac0251a7729afc5a56583654ebace8e0d84 libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e libssh-debuginfo-0.9.6-17.el8_10.s390x.rpm SHA-256: 2741a093e57718e9a9676da553bfebe15789233099cc72070e0b7d419c81ef9b libssh-debuginfo-0.9.6-17.el8_10.s390x.rpm SHA-256: 2741a093e57718e9a9676da553bfebe15789233099cc72070e0b7d419c81ef9b libssh-debugsource-0.9.6-17.el8_10.s390x.rpm SHA-256: 8d8b6f4d244eeb3fc844e4f6706002c07d0c840764f9a3f5729a735a81fd44df libssh-debugsource-0.9.6-17.el8_10.s390x.rpm SHA-256: 8d8b6f4d244eeb3fc844e4f6706002c07d0c840764f9a3f5729a735a81fd44df libssh-devel-0.9.6-17.el8_10.s390x.rpm SHA-256: 2cdd3b6f62cf43aa1ee09b882bf08a040bf0cefcd6b721ac550bcfbfde846d33 Red Hat Enterprise Linux for Power, little endian 8 SRPM libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b ppc64le libssh-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 7d6796427509bb5f850df20f26cb8670abf9836afef1201bd431c73d95e2747e libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e libssh-debuginfo-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 5e7ee6231a11ac7fe00ffb303018eca5855aededcf78c4a2df7bcfa54b602114 libssh-debuginfo-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 5e7ee6231a11ac7fe00ffb303018eca5855aededcf78c4a2df7bcfa54b602114 libssh-debugsource-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 20a046b29dc5f0cfc8dd91105f4fe5088c8208533e4258caa6e7c35590d2e0de libssh-debugsource-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 20a046b29dc5f0cfc8dd91105f4fe5088c8208533e4258caa6e7c35590d2e0de libssh-devel-0.9.6-17.el8_10.ppc64le.rpm SHA-256: f367d42f1cb411e72f3f86e8bdd23bfac9088f6a9ea280cc34b9cd67b157da18 Red Hat Enterprise Linux for ARM 64 8 SRPM libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b aarch64 libssh-0.9.6-17.el8_10.aarch64.rpm SHA-256: ffba69fdbd592b3576ecf5a69723b49e07dba5364e1c78161ff6374c35dde6da libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e libssh-debuginfo-0.9.6-17.el8_10.aarch64.rpm SHA-256: fa2d168d45ceaf1145b92cb90cdbfe5cac408521e0b5aa1437143958f0392483 libssh-debuginfo-0.9.6-17.el8_10.aarch64.rpm SHA-256: fa2d168d45ceaf1145b92cb90cdbfe5cac408521e0b5aa1437143958f0392483 libssh-debugsource-0.9.6-17.el8_10.aarch64.rpm SHA-256: 7968a9d01f01cc8c06a57aba5657423bd018f0909795ab0bdef799fb9859f8eb libssh-debugsource-0.9.6-17.el8_10.aarch64.rpm SHA-256: 7968a9d01f01cc8c06a57aba5657423bd018f0909795ab0bdef799fb9859f8eb libssh-devel-0.9.6-17.el8_10.aarch64.rpm SHA-256: 69063d6ea75f1066fee58f7b2f66450205da6234da346adeb048edcdc2746137 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b x86_64 libssh-0.9.6-17.el8_10.i686.rpm SHA-256: 1e8870229bc1c60428e3e760e516b123ca8545d67f864ca11c7ae6313ed2031b libssh-0.9.6-17.el8_10.x86_64.rpm SHA-256: 6b63ff7d5535f6b2e0c59c721346bccc27aa8c69e91c1f91aa5164841d25fe6c libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e libssh-debuginfo-0.9.6-17.el8_10.i686.rpm SHA-256: 6c35bfc67ac4da8a774438533093f4f7cca9715bc0dd89a2f48604179786b7f1 libssh-debuginfo-0.9.6-17.el8_10.i686.rpm SHA-256: 6c35bfc67ac4da8a774438533093f4f7cca9715bc0dd89a2f48604179786b7f1 libssh-debuginfo-0.9.6-17.el8_10.x86_64.rpm SHA-256: 126cad613e54b435f9c9af9b0c01657acc25eca20e4e2ef0e41bf402aeff0819 libssh-debuginfo-0.9.6-17.el8_10.x86_64.rpm SHA-256: 126cad613e54b435f9c9af9b0c01657acc25eca20e4e2ef0e41bf402aeff0819 libssh-debugsource-0.9.6-17.el8_10.i686.rpm SHA-256: 33c749839225fbafb2e873894731da3c1ddcd58e0857f7f8ad1425cf9243916d libssh-debugsource-0.9.6-17.el8_10.i686.rpm SHA-256: 33c749839225fbafb2e873894731da3c1ddcd58e0857f7f8ad1425cf9243916d libssh-debugsource-0.9.6-17.el8_10.x86_64.rpm SHA-256: 90ee6393194e7798e74317676e162ff7e0e5678b8c4bd866487c266cf7141439 libssh-debugsource-0.9.6-17.el8_10.x86_64.rpm SHA-256: 90ee6393194e7798e74317676e162ff7e0e5678b8c4bd866487c266cf7141439 libssh-devel-0.9.6-17.el8_10.i686.rpm SHA-256: ebb1c09208865f3dad62c6e2b5166a1a1bc52b6b2004fb8063145dcc03d69729 libssh-devel-0.9.6-17.el8_10.x86_64.rpm SHA-256: 289409df706a04ce80cc55e4ad40a3c9494063a8a871392a0b8f359689cc5bd1 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b aarch64 libssh-0.9.6-17.el8_10.aarch64.rpm SHA-256: ffba69fdbd592b3576ecf5a69723b49e07dba5364e1c78161ff6374c35dde6da libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3