Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81098.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-81098
Upstream
Published
2026-03-26T21:17:00Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-0964 affecting package libssh for versions less than 0.10.6-7
Details

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences.

This is the same issue as in OpenSSH, tracked as CVE-2019-6111.

References

Affected packages

Azure Linux:3 / libssh

Package

Name
libssh
Purl
pkg:rpm/azure-linux/libssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.6-7

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81098.json"