CVE-2026-0968

Source
https://cve.org/CVERecord?id=CVE-2026-0968
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0968.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-0968
Downstream
AZL (1)
BELL (1)
CLSA (8)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (1)
MINI (1)
OESA (6)
openSUSE (2)
RHSA (2)
RLSA (2)
SUSE (9)
UBUNTU (1)
Related
Published
2026-03-26T20:06:29Z
Modified
2026-09-03T03:30:33Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Libssh: libssh: denial of service due to malformed sftp message
Details

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an SSH_FXP_NAME message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-476"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0968.json"
}
References

Affected packages

Git / gitlab.com/libssh/libssh-mirror

Affected ranges

Type
GIT
Repo
https://gitlab.com/libssh/libssh-mirror
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "0.11.3"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

libssh-0.*
libssh-0.11.0
libssh-0.11.1
libssh-0.11.2
libssh-0.11.3
libssh-0.8.0
Other
release-0-3-0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0968.json"