cbcvebase.
CVE-2026-0968
published 2026-03-26

CVE-2026-0968: A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an…

low3.1CVSS 3.1
AVNACHPRNUIRSUCNINAL
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlibssh< libssh 0.12.0-1 (forky)libssh 0.12.0-1 (forky)
libsshlibssh<= 0.11.3
libsshlibssh>= 0 < 0.12.0-10.12.0-1
libsshlibssh>= 0 < 0.9.6-2ubuntu0.22.04.60.9.6-2ubuntu0.22.04.6
libsshlibssh>= 0 < 0.10.6-2ubuntu0.30.10.6-2ubuntu0.3
libsshlibssh>= 0 < 0.11.2-1ubuntu0.20.11.2-1ubuntu0.2
libsshlibssh>= 0 < 0.6.3-4.3ubuntu0.6+esm40.6.3-4.3ubuntu0.6+esm4
libsshlibssh>= 0 < 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm60.8.0~20170825.94fa1e38-1ubuntu0.7+esm6
libsshlibssh>= 0 < 0.9.3-2ubuntu2.5+esm30.9.3-2ubuntu2.5+esm3
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
osv3.1LOW