jeffv via plug on 22 Jun 2026 06:14:14 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[PLUG] flaw discovered in popular SSH library libssh2


Massive security flaw discovered in popular SSH library libssh2

https://cybernews.com/security/libssh2-critical-vulnerability-enables-rce/


The first is an out-of-bounds write vulnerability with a critical severity score of 9.2 out of 10, tracked as CVE-2026-55200.

The maintainers have already fixed the bugs via 2 GitHub commits: 97acf3d and 1762685, respectively. However, they haven’t yet released a new official libssh2 version. Linux distributions and other projects are scrambling to backport the fixes into their own packages.
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug