{"id":"AZL-90933","summary":"CVE-2026-55199 affecting package libssh2 for versions less than 1.11.1-4","details":"libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.","modified":"2026-08-30T05:26:50Z","published":"2026-06-17T20:17:28Z","upstream":["CVE-2026-55199"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55199"}],"affected":[{"package":{"name":"libssh2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libssh2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.1-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90933.json"}}],"schema_version":"1.9.0"}