CVE-2026-0965

CWE-7310 documents8 sources
Severity
3.3LOW
EPSS
0.0%
top 96.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 26

Description

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

Debianlibssh< 0.12.0-1
NVDlibssh/libssh0.11.3

Also affects: Enterprise Linux 10.0, 9.0

🔴Vulnerability Details

4
GHSA
GHSA-q35q-xwh9-8pgw: A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing2026-03-26
OSV
CVE-2026-0965: A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing2026-03-26
CVEList
Libssh: libssh: denial of service via improper configuration file handling2026-03-26
OSV
libssh vulnerabilities2026-02-18

📋Vendor Advisories

4
Ubuntu
libssh vulnerabilities2026-02-23
Ubuntu
libssh vulnerabilities2026-02-18
Red Hat
libssh: libssh: Denial of Service via improper configuration file handling2026-02-10
Debian
CVE-2026-0965: libssh - A flaw was found in libssh where it can attempt to open arbitrary files during c...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-0965 Impact, Exploitability, and Mitigation Steps | Wiz