{"id":"AZL-81849","summary":"CVE-2026-0968 affecting package libssh for versions less than 0.10.6-8","details":"A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.","modified":"2026-08-30T05:26:50Z","published":"2026-03-26T21:17:01Z","upstream":["CVE-2026-0968"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0968"}],"affected":[{"package":{"name":"libssh","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.6-8"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81849.json"}}],"schema_version":"1.9.0"}