Source: libssh2
Version: 1.11.1-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/libssh2/libssh2/pull/1858
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for libssh2.

CVE-2026-7598[0]:
| A security vulnerability has been detected in libssh2 up to 1.11.1.
| The impacted element is the function userauth_password of the file
| src/userauth.c. Such manipulation of the argument
| username_len/password_len leads to integer overflow. The attack may
| be launched remotely. The name of the patch is
| 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied
| to remediate this issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-7598
    https://www.cve.org/CVERecord?id=CVE-2026-7598
[1] https://github.com/libssh2/libssh2/pull/1858
[2] 
https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to