Security News

Cybersecurity news aggregator

🔄
MEDIUM Updates Red Hat Errata

RHSA-2026:62217: Moderate: libssh security update

  • What: libssh security update
  • Impact: Red Hat Enterprise Linux 9 users need to apply patch
Read Full Article →

Red Hat Product Errata RHSA-2026:62217 - Security Advisory Issued: 2026-09-01 Updated: 2026-09-01 RHSA-2026:62217 - Security Advisory Overview Updated Packages Synopsis Moderate: libssh security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libssh is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description libssh is a library which implements the SSH protocol. It can be used to implement client and server applications. Security Fix(es): libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843) libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844) libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845) libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846) libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847) libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848) libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2498176 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size BZ - 2498177 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length BZ - 2498178 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure BZ - 2498179 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion BZ - 2498180 - CVE-2026-59847 libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification BZ - 2498181 - CVE-2026-59848 libssh: libssh: denial of service via SFTP responses with unknown request IDs BZ - 2498183 - CVE-2026-59850 libssh: libssh: use-after-free via data callbacks on closed channels CVEs CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM libssh-0.10.4-19.el9_8.src.rpm SHA-256: 83663aff05b77225cded03c63955736eddc0d6ecf6072cb4355563094a2a3250 x86_64 libssh-0.10.4-19.el9_8.i686.rpm SHA-256: 384c442100e56eca5edd391c5c32de21db2833b04e8cfd053b8fb91a62182863 libssh-0.10.4-19.el9_8.x86_64.rpm SHA-256: 10d0ecb7cef182f8d11eb4bc772943a60c48b8171f602ffd83bb79b9edf5eb44 libssh-config-0.10.4-19.el9_8.noarch.rpm SHA-256: ce06b99793b9e5abc50a58ebc3ef11037f2efbdb5f819a25f8de4994613194d4 libssh-debuginfo-0.10.4-19.el9_8.i686.rpm SHA-256: 9887122b281f2cd3001386dd55c62505a28e01b4ac5e7467cc7cf4d857a35331 libssh-debuginfo-0.10.4-19.el9_8.i686.rpm SHA-256: 9887122b281f2cd3001386dd55c62505a28e01b4ac5e7467cc7cf4d857a35331 libssh-debuginfo-0.10.4-19.el9_8.x86_64.rpm SHA-256: 6dbfe85e6e435f060b681fc735143a4a613fea127098eb0bcb9f3ee442ec21a9 libssh-debuginfo-0.10.4-19.el9_8.x86_64.rpm SHA-256: 6dbfe85e6e435f060b681fc735143a4a613fea127098eb0bcb9f3ee442ec21a9 libssh-debugsource-0.10.4-19.el9_8.i686.rpm SHA-256: 6ee888283dca6aa7d940fc53de97cad48cd2260beb6b0f513f5602866c2e7dfd libssh-debugsource-0.10.4-19.el9_8.i686.rpm SHA-256: 6ee888283dca6aa7d940fc53de97cad48cd2260beb6b0f513f5602866c2e7dfd libssh-debugsource-0.10.4-19.el9_8.x86_64.rpm SHA-256: 2963c197c0da421749d447aa107d9a7fd70c59a5b4902e4c26b828a0156f5ea3 libssh-debugsource-0.10.4-19.el9_8.x86_64.rpm SHA-256: 2963c197c0da421749d447aa107d9a7fd70c59a5b4902e4c26b828a0156f5ea3 libssh-devel-0.10.4-19.el9_8.i686.rpm SHA-256: ad1aa2897e76ffb196d2b7c60ce0b253875cda8390abf6069d7ca1c0548d46a1 libssh-devel-0.10.4-19.el9_8.x86_64.rpm SHA-256: 93e5cd35a2cee2d6b370ab7111534103234413dfdc4b63dcc0961630f5b9b288 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM libssh-0.10.4-19.el9_8.src.rpm SHA-256: 83663aff05b77225cded03c63955736eddc0d6ecf6072cb4355563094a2a3250 x86_64 libssh-0.10.4-19.el9_8.i686.rpm SHA-256: 384c442100e56eca5edd391c5c32de21db2833b04e8cfd053b8fb91a62182863 libssh-0.10.4-19.el9_8.x86_64.rpm SHA-256: 10d0ecb7cef182f8d11eb4bc772943a60c48b8171f602ffd83bb79b9edf5eb44 libssh-config-0.10.4-19.el9_8.noarch.rpm SHA-256: ce06b99793b9e5abc50a58ebc3ef11037f2efbdb5f819a25f8de4994613194d4 libssh-debuginfo-0.10.4-19.el9_8.i686.rpm SHA-256: 9887122b281f2cd3001386dd55c62505a28e01b4ac5e7467cc7cf4d857a35331 libssh-debuginfo-0.10.4-19.el9_8.i686.rpm SHA-256: 9887122b281f2cd3001386dd55c62505a28e01b4ac5e7467cc7cf4d857a35331 libssh-debuginfo-0.10.4-19.el9_8.x86_64.rpm SHA-256: 6dbfe85e6e435f060b681fc735143a4a613fea127098eb0bcb9f3ee442ec21a9 libssh-debuginfo-0.10.4-19.el9_8.x86_64.rpm SHA-256: 6dbfe85e6e435f060b681fc735143a4a613fea127098eb0bcb9f3ee442ec21a9 libssh-debugsource-0.10.4-19.el9_8.i686.rpm SHA-256: 6ee888283dca6aa7d940fc53de97cad48cd2260beb6b0f513f5602866c2e7dfd libssh-debugsource-0.10.4-19.el9_8.i686.rpm SHA-256: 6ee888283dca6aa7d940fc53de97cad48cd2260beb6b0f513f5602866c2e7dfd libssh-debugsource-0.10.4-19.el9_8.x86_64.rpm SHA-256: 2963c197c0da421749d447aa107d9a7fd70c59a5b4902e4c26b828a0156f5ea3 libssh-debugsource-0.10.4-19.el9_8.x86_64.rpm SHA-256: 2963c197c0da421749d447aa107d9a7fd70c59a5b4902e4c26b828a0156f5ea3 libssh-devel-0.10.4-19.el9_8.i686.rpm SHA-256: ad1aa2897e76ffb196d2b7c60ce0b253875cda8390abf6069d7ca1c0548d46a1 libssh-devel-0.10.4-19.el9_8.x86_64.rpm SHA-256: 93e5cd35a2cee2d6b370ab7111534103234413dfdc4b63dcc0961630f5b9b288 Red Hat Enterprise Linux for IBM z Systems 9 SRPM libssh-0.10.4-19.el9_8.src.rpm SHA-256: 83663aff05b77225cded03c63955736eddc0d6ecf6072cb4355563094a2a3250 s390x libssh-0.10.4-19.el9_8.s390x.rpm SHA-256: d8f81f77d6fa830d001ea0336b7b4dfa955bd94e885205f8eb62b21e9439b264 libssh-config-0.10.4-19.el9_8.noarch.rpm SHA-256: ce06b99793b9e5abc50a58ebc3ef11037f2efbdb5f819a25f8de4994613194d4 libssh-debuginfo-0.10.4-19.el9_8.s390x.rpm SHA-256: 61d364ca00fa5ccf102404bb8a774575f9ae4e69397554bbf9ff2f82d9ef6924 libssh-debuginfo-0.10.4-19.el9_8.s390x.rpm SHA-256: 61d364ca00fa5ccf102404bb8a774575f9ae4e69397554bbf9ff2f82d9ef6924 libssh-debugsource-0.10.4-19.el9_8.s390x.rpm SHA-256: 2b751c250f41f7db73265d9932f88c5996a5528c2f249918f67f56d47d26610d libssh-debugsource-0.10.4-19.el9_8.s390x.rpm SHA-256: 2b751c250f41f7db73265d9932f88c5996a5528c2f249918f67f56d47d26610d libssh-devel-0.10.4-19.el9_8.s390x.rpm SHA-256: 8db538efb806f75c1718651c2edf11b13473edf9d274ebbe23f683fbc8f232cc Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM libssh-0.10.4-19.el9_8.src.rpm SHA-256: 83663aff05b77225cded03c63955736eddc0d6ecf6072cb4355563094a2a3250 s390x libssh-0.10.4-19.el9_8.s390x.rpm SHA-256: d8f81f77d6fa830d001ea0336b7b4dfa955bd94e885205f8eb62b21e9439b264 libssh-config-0.10.4-19.el9_8.noarch.rpm SHA-256: ce06b99793b9e5abc50a58ebc3ef11037f2efbdb5f819a25f8de4994613194d4 libssh-debuginfo-0.10.4-19.el9_8.s390x.rpm SHA-256: 61d364ca00fa5ccf102404bb8a774575f9ae4e69397554bbf9ff2f82d9ef6924 libssh-debuginfo-0.10.4-19.el9_8.s390x.rpm SHA-256: 61d364ca00fa5ccf102404bb8a774575f9ae4e69397554bbf9ff2f82d9ef6924 libssh-debugsource-0.10.4-19.el9_8.s390x.rpm SHA-256: 2b751c250f41f7db73265d9932f88c5996a5528c2f249918f67f56d47d26610d libssh-debugsource-0.10.4-19.el9_8.s390x.rpm SHA-256: 2b751c250f41f7db73265d9932f88c5996a5528c2f249918f67f56d47d26610d libssh-devel-0.10.4-19.el9_8.s390x.rpm SHA-256: 8db538efb806f75c1718651c2edf11b13473edf9d274ebbe23f683fbc8f232cc Red Hat Enterprise Linux for Power, little endian 9 SRPM libssh-0.10.4-19.el9_8.src.rpm SHA-256: 83663aff05b77225cded03c63955736eddc0d6ecf6072cb4355563094a2a3250 ppc64le libssh-0.10.4-19.el9_8.ppc64le.rpm SHA-256: 44d3d65ac69d08e4ce6053e477b236772065f48c4be8162370976d3bd0f3e82f libssh-config-0.10.4-19.el9_8.noarch.rpm SHA-256: ce06b99793b9e5abc50a58ebc3ef11037f2efbdb5f819a25f8de4994613194d4 libssh-debuginfo-0.10.4-19.el9_8.ppc64le.rpm SHA-256: aafabd2608e48473494275f32409f674c3164e3af320caab81fc75c46abec640 libssh-debuginfo-0.10.4-19.el9_8.ppc64le.rpm SHA-256: aafabd2608e48473494275f32409f674c3164e3af320caab81fc75c46abec640 libssh-debugsource-0.10.4-19.el9_8.ppc64le.rpm SHA-256: d5ccfaf050ea9c81

Share this article