|
jeffv via plug on 22 Jun 2026 06:14:14 -0700
|
[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]
|
[PLUG] flaw discovered in popular SSH library libssh2
|
- From: jeffv via plug <plug@lists.phillylinux.org>
- To: Philadelphia Linux User's Group Discussion List <plug@lists.phillylinux.org>
- Subject: [PLUG] flaw discovered in popular SSH library libssh2
- Date: Mon, 22 Jun 2026 09:14:07 -0400
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comcastmailservice.net; s=20211018a; t=1782134049; bh=ZBA4QW2bQM9kjAV12JJVBZClhBAInlcRA9ouumoDo3M=; h=Received:Received:Message-ID:Date:MIME-Version:To:From:Subject: Content-Type:Xfinity-Spam-Result; b=o7om4WxmDAkZv0+Ha1X0VhNoxbfhjdYZN6yncUQrBq4+NNevXpGz54DW19y0QGG8K SAohYg5D0xvmWnei3gz7sWseM+ki6FdYQ4SX+nnlh//D6v3hvIRNRwJ/XFPNUH/ZIA 7jmh4elyYbf0TSjYGaKn4DjAtzmJtt+AtvvI2uisj2+ZhPFNlqy5Tk5Kh+9nrVilye M5U8G7S4CxNCy4Cn0NfgNnzfr1TXxrxEBNobWE6P0L0gXuH4s0dBE6NfkF0qeHJjuG 66WN0AbEgDuBvegF7QOf+2d8wVUDmlZn0jWvAx4XdUlkNcT/BdeiJkHIjYGI/fheev cGUQDeCq9xv8g==
- Reply-to: jeffv <jeffv@op.net>
- Sender: "plug" <plug-bounces@lists.phillylinux.org>
- User-agent: Mozilla Thunderbird
- Xfinity-graffiti: 65104330690
- Xfinity-qid: beTXw01J47NcPbeTYwzpWp
Massive security flaw discovered in popular SSH library libssh2
https://cybernews.com/security/libssh2-critical-vulnerability-enables-rce/
The first is an out-of-bounds write vulnerability with a critical
severity score of 9.2 out of 10, tracked as CVE-2026-55200.
The maintainers have already fixed the bugs via 2 GitHub commits:
97acf3d and 1762685, respectively. However, they haven’t yet released a
new official libssh2 version. Linux distributions and other projects are
scrambling to backport the fixes into their own packages.
___________________________________________________________________________
Philadelphia Linux Users Group -- http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug