Description
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected products
- libssh / libssh
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / hardened_images
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:42922
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:55855
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:62217
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:62218
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-59850
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2498183
Updated 11m ago · 8 sources