Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Ubuntu Security

USN-8532-1: libssh2 vulnerabilities

Two vulnerabilities in libssh2 (CVE-2026-58050, CVSS 7.0 HIGH, and CVE-2026-58051, CVSS 6.5 MEDIUM) allow a malicious SSH server to cause denial of service or potentially execute arbitrary code by exploiting improper handling of publickey subsystem attributes and uninitialized list entries. Affected versions include libssh2 up to and including version 1.11.1.
Read Full Article →

It was discovered that libssh2 incorrectly handled certain publickey subsystem attributes. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58050) It was discovered that libssh2 did not properly initialize publickey list entries before parsing. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58051)

Share this article