Back Linuxsecurity Ubuntu 26.04 libssh2 Important Remote Exec DoS Issues USN-8722
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
Several security issues were fixed in libssh2. Software Description: - libssh2: Client-side C library implementing the SSH2 protocol Details: It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66032) It was discovered that libssh2 incorrectly handled AES-GCM cipher negotiation. A remote attacker controlling an SSH server could possibly use this issue to cause libssh2 to crash, resulting in a denial of service. (CVE-2026-66033) It was discovered that libssh2 incorrectly handled Encrypt-then-MAC cipher negotiation. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66035)
Several security issues were fixed in libssh2.
Software Description:
- libssh2: Client-side C library implementing the SSH2 protocol
It was discovered that libssh2 incorrectly handled certain SFTP server
responses. A remote attacker controlling an SSH server could use this issue
to cause libssh2 to crash or possibly execute arbitrary code.
It was discovered that libssh2 incorrectly handled AES-GCM cipher
negotiation. A remote attacker controlling an SSH server could possibly use
this issue to cause libssh2 to crash, resulting in a denial of service.
It was discovered that libssh2 incorrectly handled Encrypt-then-MAC cipher
negotiation. A remote attacker controlling an SSH server could use this
issue to cause libssh2 to crash or possibly execute arbitrary code.
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssh2-1t64 1.11.1-1ubuntu0.26.04.4 Ubuntu 24.04 LTS libssh2-1t64 1.11.0-4.1ubuntu0.24.04.4 In general, a standard system update will make all the necessary changes.
CVE-2026-66032, CVE-2026-66033, CVE-2026-66035
Ubuntu Security Notice USN-8722-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
