{"id":"CVE-2026-55200","summary":"libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c","details":"libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.","modified":"2026-09-19T08:08:55.635447Z","published":"2026-06-17T19:03:15.183Z","related":["SUSE-SU-2026:22284-1","SUSE-SU-2026:22364-1","openSUSE-SU-2026:11109-1","openSUSE-SU-2026:21057-1"],"database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-680"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55200.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55200.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55200"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c"},{"type":"REPORT","url":"https://github.com/libssh2/libssh2/pull/2052"},{"type":"FIX","url":"https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8"},{"type":"PACKAGE","url":"https://github.com/libssh2/libssh2"},{"type":"EVIDENCE","url":"https://web.archive.org/web/20260623211210/https://github.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-poc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libssh2/libssh2","events":[{"introduced":"a312b43325e3383c865a87bb1d26cb52e3292641"},{"fixed":"97acf3dfda80c91c3a8c9f2372546301d4a1a7a8"}],"database_specific":{"cpe":"cpe:2.3:a:libssh2:libssh2:1.11.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.11.1"},{"last_affected":"1.11.1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.11.1","libssh2-1.11.1"],"database_specific":{"vanir_signatures_modified":"2026-09-19T08:08:55Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["141284426602951877244048188813499579259","143473284225173970337868642692660082915","239476351730145920916386564352533292186","186841941824073284665751444935760647525","231959736810542483406341454873690778984"],"threshold":0.9},"id":"CVE-2026-55200-959b9c2e","signature_type":"Line","signature_version":"v1","source":"https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8","target":{"file":"src/transport.c"}},{"source":"https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8","target":{"file":"src/transport.c","function":"ssh2_transport_read"},"deprecated":false,"digest":{"function_hash":"199057862071948971514444742776006168965","length":7507},"id":"CVE-2026-55200-a735b935","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55200.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}