Back Linuxsecurity Mageia 9 libssh Security Flaw in SCP Causes Resource Exhaustion Issues
Description: CVE-2026-0964 Improper sanitation of paths received from SCP servers CVE-2026-0965 The libssh can attempt to read non-regular files when misconfigured, which could cause resource exhaustion or blocking. CVE-2026-0966 Providing 0-length input for the ssh_get_hexa() causes 1-byte buffer underflow on heap, possibly causing memory corruption. CVE-2026-0967 Pattern matching at various places in libssh could lead to complex backtracking causing timeouts. CVE-2026-0968 Possible read behind bounds of longname
Description: CVE-2026-0964 Improper sanitation of paths received from SCP servers CVE-2026-0965 The libssh can attempt to read non-regular files when misconfigured, which could cause resource exhaustion or blocking. CVE-2026-0966 Providing 0-length input for the ssh_get_hexa() causes 1-byte buffer underflow on heap, possibly causing memory corruption. CVE-2026-0967 Pattern matching at various places in libssh could lead to complex backtracking causing timeouts. CVE-2026-0968 Possible read behind bounds of longname
- - - - - - - - - - - -
-
-
-
-
-
-
-
-
-
-
-
-
- 9/core/libssh-0.10.6-1.2.mga9
- 9/core/libssh-0.10.6-1.2.mga9
Publication date: 12 Jun 2026 URL: https: //advisories.mageia.org/MGASA-2026-0202.html Type: security CVE: CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
