Skip to content
Fedora 43 libssh Critical Denial of Service Buffer Overflow 2026

Fedora 43 libssh Critical Denial of Service Buffer Overflow 2026

Linuxsecurity LinuxSecurity Advisories July 23, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

The ssh library was designed to be used by programmers needing a working SSH

implementation by the mean of a library. The complete control of the client is

made by the programmer. With libssh, you can remotely execute programs, transfer

files, use a secure and transparent tunnel for your remote programs. With its

Secure FTP implementation, you can play with remote files easily, without

third-party programs others than libcrypto (from openssl).

New upstream security release (#2503148)

* Tue Jul 21 2026 Jakub Jelen - 0.11.5-1 - New upstream security release (#2503148)

* Tue Jul 21 2026 Jakub Jelen - 0.11.5-1 - New upstream security release (#2503148)

[ 1 ] Bug #2503148 - libssh-0.12.1 is available [ 2 ] Bug #2503651 - CVE-2026-15370 libssh: libssh: stack buffer overflow in SFTP server longname construction [fedora-all] [ 3 ] Bug #2503657 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size [fedora-all] [ 4 ] Bug #2503658 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length [fedora-all] [ 5 ] Bug #2503668 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure [fedora-all] [ 6 ] Bug #2503669 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all] https...

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-063caa9112' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.