Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90933.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90933
Upstream
Published
2026-06-17T20:17:28Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-55199 affecting package libssh2 for versions less than 1.11.1-4
Details

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSHMSGEXTINFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nrextensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from libssh2get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

References

Affected packages

Azure Linux:3 / libssh2

Package

Name
libssh2
Purl
pkg:rpm/azure-linux/libssh2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.11.1-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90933.json"