{"id":"OESA-2026-3017","summary":"libssh2 security update","details":"libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10).\r\n\r\nSecurity Fix(es):\n\nlibssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.(CVE-2025-15661)","modified":"2026-07-19T04:00:14.275738499Z","published":"2026-07-19T03:47:50Z","upstream":["CVE-2025-15661"],"database_specific":{"severity":"Medium"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3017"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15661"}],"affected":[{"package":{"name":"libssh2","ecosystem":"openEuler:20.03-LTS-SP4","purl":"pkg:rpm/openEuler/libssh2&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.0-12.oe2003sp4"}]}],"ecosystem_specific":{"src":["libssh2-1.9.0-12.oe2003sp4.src.rpm"],"x86_64":["libssh2-1.9.0-12.oe2003sp4.x86_64.rpm","libssh2-debuginfo-1.9.0-12.oe2003sp4.x86_64.rpm","libssh2-debugsource-1.9.0-12.oe2003sp4.x86_64.rpm","libssh2-devel-1.9.0-12.oe2003sp4.x86_64.rpm"],"aarch64":["libssh2-1.9.0-12.oe2003sp4.aarch64.rpm","libssh2-debuginfo-1.9.0-12.oe2003sp4.aarch64.rpm","libssh2-debugsource-1.9.0-12.oe2003sp4.aarch64.rpm","libssh2-devel-1.9.0-12.oe2003sp4.aarch64.rpm"],"noarch":["libssh2-help-1.9.0-12.oe2003sp4.noarch.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3017.json"}}],"schema_version":"1.7.5"}