{"id":"CLSA-2026-1776855642","summary":"Fix CVE(s): CVE-2019-17498, CVE-2019-3857","details":"   * SECURITY UPDATE: Integer overflow leading to out-of-bounds write when\n     SSH_MSG_CHANNEL_REQUEST packets with exit signal messages are parsed.\n     - debian/patches/CVE-2019-3857.patch: check namelen + 1 does not\n       overflow before allocation in exit-signal handling.\n     - CVE-2019-3857\n   * SECURITY UPDATE: Integer overflow in bounds check in SSH_MSG_DISCONNECT\n     packet parsing enabling out-of-bounds read.\n     - debian/patches/CVE-2019-17498.patch: harden bounds checking in\n       SSH_MSG_DISCONNECT, SSH_MSG_DEBUG, and SSH_MSG_GLOBAL_REQUEST\n       handlers to prevent unsigned integer underflow and overflow.\n     - CVE-2019-17498","modified":"2026-06-04T09:47:10.751040090Z","published":"2026-04-22T11:00:47Z","upstream":["CVE-2019-17498","CVE-2019-3857"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2026-1776855642.html"}],"affected":[{"package":{"name":"libssh2-1","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libssh2-1?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0-2ubuntu0.1+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1776855642.json"}},{"package":{"name":"libssh2-1-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libssh2-1-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0-2ubuntu0.1+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1776855642.json"}}],"schema_version":"1.7.5"}