{"id":"RHSA-2026:61752","summary":"Red Hat Security Advisory: libssh2 security update","modified":"2026-09-01T10:56:27.075433843Z","published":"2026-09-01T10:28:36Z","upstream":["CVE-2026-58050","CVE-2026-66032","CVE-2026-66034","CVE-2026-7598"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:61752"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464597"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493955"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2506857"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2506860"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_61752.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-7598"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-7598"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7598"},{"type":"ARTICLE","url":"https://github.com/libssh2/libssh2/"},{"type":"ARTICLE","url":"https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1"},{"type":"ARTICLE","url":"https://github.com/libssh2/libssh2/pull/1858"},{"type":"ARTICLE","url":"https://vuldb.com/submit/805564"},{"type":"ARTICLE","url":"https://vuldb.com/vuln/360555"},{"type":"ARTICLE","url":"https://vuldb.com/vuln/360555/cti"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-58050"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-58050"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58050"},{"type":"ARTICLE","url":"https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc"},{"type":"ARTICLE","url":"https://github.com/libssh2/libssh2/blob/master/src/publickey.c"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/libssh2-integer-overflow-in-publickey-subsystem-attribute-allocation"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-66032"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-66032"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66032"},{"type":"ARTICLE","url":"https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0"},{"type":"ARTICLE","url":"https://github.com/libssh2/libssh2/pull/2180"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-open"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-66034"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-66034"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66034"},{"type":"ARTICLE","url":"https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9"},{"type":"ARTICLE","url":"https://github.com/libssh2/libssh2/pull/2202"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem"}],"affected":[{"package":{"name":"libssh2","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/libssh2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.8.0-4.el7_9.2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:61752.json"}},{"package":{"name":"libssh2-devel","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/libssh2-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.8.0-4.el7_9.2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:61752.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}