Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90927.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90927
Upstream
Published
2026-06-17T20:17:28Z
Modified
2026-09-04T05:27:10Z
Summary
CVE-2026-55200 affecting package libssh2 for versions less than 1.11.1-3
Details

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2transportread() that fails to enforce upper bounds on packetlength field. Remote attackers can send crafted SSH packets with excessively large packetlength values to corrupt heap memory and achieve remote code execution.

References

Affected packages

Azure Linux:3 / libssh2

Package

Name
libssh2
Purl
pkg:rpm/azure-linux/libssh2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.11.1-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90927.json"