Skip to content
Ubuntu 26.04 libssh2 Important Remote Exec DoS Issues USN-8722

Ubuntu 26.04 libssh2 Important Remote Exec DoS Issues USN-8722

Linuxsecurity LinuxSecurity Advisories September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

Several security issues were fixed in libssh2. Software Description: - libssh2: Client-side C library implementing the SSH2 protocol Details: It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66032) It was discovered that libssh2 incorrectly handled AES-GCM cipher negotiation. A remote attacker controlling an SSH server could possibly use this issue to cause libssh2 to crash, resulting in a denial of service. (CVE-2026-66033) It was discovered that libssh2 incorrectly handled Encrypt-then-MAC cipher negotiation. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66035)

Several security issues were fixed in libssh2.

Software Description:

- libssh2: Client-side C library implementing the SSH2 protocol

It was discovered that libssh2 incorrectly handled certain SFTP server

responses. A remote attacker controlling an SSH server could use this issue

to cause libssh2 to crash or possibly execute arbitrary code.

It was discovered that libssh2 incorrectly handled AES-GCM cipher

negotiation. A remote attacker controlling an SSH server could possibly use

this issue to cause libssh2 to crash, resulting in a denial of service.

It was discovered that libssh2 incorrectly handled Encrypt-then-MAC cipher

negotiation. A remote attacker controlling an SSH server could use this

issue to cause libssh2 to crash or possibly execute arbitrary code.

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssh2-1t64 1.11.1-1ubuntu0.26.04.4 Ubuntu 24.04 LTS libssh2-1t64 1.11.0-4.1ubuntu0.24.04.4 In general, a standard system update will make all the necessary changes.

CVE-2026-66032, CVE-2026-66033, CVE-2026-66035

Ubuntu Security Notice USN-8722-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)