{"id":"MGASA-2026-0189","summary":"Updated libssh packages fix security vulnerabilities","details":"CVE-2025-4877  Write beyond bounds in binary to base64 conversion\nfunctions\nCVE-2025-4878  Use of uninitialized variable in privatekey_from_file()\nCVE-2025-5318  Likely read beyond bounds in sftp server handle\nmanagement\nCVE-2025-5351  Double free in functions exporting keys\nCVE-2025-5372  ssh_kdf() returns a success code on certain failures\nCVE-2025-5449  Likely read beyond bounds in sftp server message decoding\nCVE-2025-5987  Invalid return code for chacha20 poly1305 with OpenSSL\nbackend\n","modified":"2026-06-10T05:15:04.434517705Z","published":"2026-06-10T05:07:06Z","upstream":["CVE-2025-4877","CVE-2025-4878","CVE-2025-5318","CVE-2025-5351","CVE-2025-5372","CVE-2025-5449","CVE-2025-5987"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0189.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=34405"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2025/06/27/2"}],"affected":[{"package":{"name":"libssh","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/libssh?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.6-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0189.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}