The updated packages fix security vulnerabilities: Heap Buffer Over-read via sftpsymlink() in sftp.c. (CVE-2025-15661) libssh2 userauth.c userauthpassword integer overflow. (CVE-2026-7598) Pre-Authentication DoS via SSHMSGEXTINFO Handler. (CVE-2026-55199) Out-of-Bounds Write via Unchecked packetlength in transport.c. (CVE-2026-55200) Integer Overflow in publickey Subsystem Attribute Allocation. (CVE-2026-58050) Free of Uninitialized Pointer in publickey List Cleanup. (CVE-2026-58051)