{"id":"MGASA-2026-0425","summary":"Updated libssh packages fix security vulnerabilities","details":"Stack buffer overflow in SFTP server longname construction.\n(CVE-2026-15370)\nDenial of service via zero advertised channel packet size.\n(CVE-2026-59843)\nDenial of service via oversized SFTP read length. (CVE-2026-59844)\nDenial of service via unchecked ProxyCommand fork() failure.\n(CVE-2026-59845)\nInformation disclosure via ProxyCommand %r username expansion.\n(CVE-2026-59846)\nIntegrity downgrade via OpenSSL AES-GCM tag verification.\n(CVE-2026-59847)\nDenial of service via SFTP responses with unknown request IDs.\n(CVE-2026-59848)\nDenial of service via automatic certificate authentication loop.\n(CVE-2026-59849)\nUse-after-free via data callbacks on closed channels. (CVE-2026-59850)\n","modified":"2026-09-20T04:30:03.288305532Z","published":"2026-09-20T04:25:32Z","upstream":["CVE-2026-15370","CVE-2026-59843","CVE-2026-59844","CVE-2026-59845","CVE-2026-59846","CVE-2026-59847","CVE-2026-59848","CVE-2026-59849","CVE-2026-59850"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0425.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35983"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/07/21/7"},{"type":"WEB","url":"https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIVTLBAG4MPX3WGPMVYDO2UPZB6G3ESR/"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YZ324UUCGQ4JEC4ZOJMJODWYVPSFBWUU/"},{"type":"WEB","url":"https://lists.debian.org/debian-security-announce/2026/msg00321.html"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8699-1"}],"affected":[{"package":{"name":"libssh","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/libssh?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.5-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0425.json"}},{"package":{"name":"libssh","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/libssh?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.6-1.3.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0425.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}