UBUNTU-CVE-2026-0964

Source
https://ubuntu.com/security/CVE-2026-0964
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-0964.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-0964
Upstream
  • CVE-2026-0964
Downstream
Related
Published
2026-02-13T00:00:00Z
Modified
2026-04-02T21:07:04.938148Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.

References

Affected packages

Ubuntu:22.04:LTS
libssh

Package

Name
libssh
Purl
pkg:deb/ubuntu/libssh@0.9.6-2ubuntu0.22.04.6?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.6-2ubuntu0.22.04.6

Affected versions

0.*
0.9.6-1
0.9.6-1build1
0.9.6-2
0.9.6-2build1
0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.4
0.9.6-2ubuntu0.22.04.5

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libssh-4",
            "binary_version": "0.9.6-2ubuntu0.22.04.6"
        },
        {
            "binary_name": "libssh-dev",
            "binary_version": "0.9.6-2ubuntu0.22.04.6"
        },
        {
            "binary_name": "libssh-gcrypt-4",
            "binary_version": "0.9.6-2ubuntu0.22.04.6"
        },
        {
            "binary_name": "libssh-gcrypt-dev",
            "binary_version": "0.9.6-2ubuntu0.22.04.6"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-0964.json"
Ubuntu:24.04:LTS
libssh

Package

Name
libssh
Purl
pkg:deb/ubuntu/libssh@0.10.6-2ubuntu0.3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.6-2ubuntu0.3

Affected versions

0.*
0.10.5-3ubuntu1
0.10.5-3ubuntu2
0.10.6-2
0.10.6-2build1
0.10.6-2build2
0.10.6-2ubuntu0.1
0.10.6-2ubuntu0.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libssh-4",
            "binary_version": "0.10.6-2ubuntu0.3"
        },
        {
            "binary_name": "libssh-dev",
            "binary_version": "0.10.6-2ubuntu0.3"
        },
        {
            "binary_name": "libssh-gcrypt-4",
            "binary_version": "0.10.6-2ubuntu0.3"
        },
        {
            "binary_name": "libssh-gcrypt-dev",
            "binary_version": "0.10.6-2ubuntu0.3"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-0964.json"
Ubuntu:25.10
libssh

Package

Name
libssh
Purl
pkg:deb/ubuntu/libssh@0.11.2-1ubuntu0.2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.11.2-1ubuntu0.2

Affected versions

0.*
0.11.1-1
0.11.1-2
0.11.2-1
0.11.2-1build1
0.11.2-1ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libssh-4",
            "binary_version": "0.11.2-1ubuntu0.2"
        },
        {
            "binary_name": "libssh-dev",
            "binary_version": "0.11.2-1ubuntu0.2"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-0964.json"
Ubuntu:Pro:16.04:LTS
libssh

Package

Name
libssh
Purl
pkg:deb/ubuntu/libssh@0.6.3-4.3ubuntu0.6+esm4?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.3-4.3ubuntu0.6+esm4

Affected versions

0.*
0.6.3-3ubuntu3
0.6.3-4.1
0.6.3-4.2
0.6.3-4.2ubuntu1
0.6.3-4.3
0.6.3-4.3ubuntu0.1
0.6.3-4.3ubuntu0.2
0.6.3-4.3ubuntu0.5
0.6.3-4.3ubuntu0.6
0.6.3-4.3ubuntu0.6+esm1
0.6.3-4.3ubuntu0.6+esm2
0.6.3-4.3ubuntu0.6+esm3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libssh-4",
            "binary_version": "0.6.3-4.3ubuntu0.6+esm4"
        },
        {
            "binary_name": "libssh-dev",
            "binary_version": "0.6.3-4.3ubuntu0.6+esm4"
        },
        {
            "binary_name": "libssh-gcrypt-4",
            "binary_version": "0.6.3-4.3ubuntu0.6+esm4"
        },
        {
            "binary_name": "libssh-gcrypt-dev",
            "binary_version": "0.6.3-4.3ubuntu0.6+esm4"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-0964.json"
Ubuntu:Pro:18.04:LTS
libssh

Package

Name
libssh
Purl
pkg:deb/ubuntu/libssh@0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6

Affected versions

0.*
0.7.5-1
0.8.0~20170825.94fa1e38-1
0.8.0~20170825.94fa1e38-1build1
0.8.0~20170825.94fa1e38-1ubuntu0.1
0.8.0~20170825.94fa1e38-1ubuntu0.2
0.8.0~20170825.94fa1e38-1ubuntu0.5
0.8.0~20170825.94fa1e38-1ubuntu0.6
0.8.0~20170825.94fa1e38-1ubuntu0.7
0.8.0~20170825.94fa1e38-1ubuntu0.7+esm3
0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4
0.8.0~20170825.94fa1e38-1ubuntu0.7+esm5

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libssh-4",
            "binary_version": "0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6"
        },
        {
            "binary_name": "libssh-dev",
            "binary_version": "0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6"
        },
        {
            "binary_name": "libssh-gcrypt-4",
            "binary_version": "0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6"
        },
        {
            "binary_name": "libssh-gcrypt-dev",
            "binary_version": "0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-0964.json"
Ubuntu:Pro:20.04:LTS
libssh

Package

Name
libssh
Purl
pkg:deb/ubuntu/libssh@0.9.3-2ubuntu2.5+esm3?arch=source&distro=esm-infra/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.3-2ubuntu2.5+esm3

Affected versions

0.*
0.9.0-1ubuntu1
0.9.0-1ubuntu4
0.9.0-1ubuntu5
0.9.3-2ubuntu1
0.9.3-2ubuntu2
0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.4
0.9.3-2ubuntu2.5
0.9.3-2ubuntu2.5+esm1
0.9.3-2ubuntu2.5+esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libssh-4",
            "binary_version": "0.9.3-2ubuntu2.5+esm3"
        },
        {
            "binary_name": "libssh-dev",
            "binary_version": "0.9.3-2ubuntu2.5+esm3"
        },
        {
            "binary_name": "libssh-gcrypt-4",
            "binary_version": "0.9.3-2ubuntu2.5+esm3"
        },
        {
            "binary_name": "libssh-gcrypt-dev",
            "binary_version": "0.9.3-2ubuntu2.5+esm3"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-0964.json"