{"id":"AZL-93396","summary":"CVE-2026-66032 affecting package libssh2 for versions less than 1.11.1-5","details":"libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.","modified":"2026-08-30T05:26:50Z","published":"2026-07-24T17:17:35Z","upstream":["CVE-2026-66032"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66032"}],"affected":[{"package":{"name":"libssh2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libssh2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.1-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93396.json"}}],"schema_version":"1.9.0"}