Critical Vulnerabilities in Fedora's OpenSSH and libssh Libraries

Critical Vulnerabilities in Fedora's OpenSSH and libssh Libraries

First seen 23 Jul 2026, 12:05 UTC Linuxsecurity 84% similarity 74.0

Article Content

Browse articles
ThreatCluster

Recent updates for Fedora's OpenSSH and libssh libraries address critical vulnerabilities. CVE-2026-59996 and CVE-2026-60002, published on July 8, 2026, involve file misplacement and use-after-free issues in OpenSSH. Additionally, multiple vulnerabilities in libssh, including CVE-2026-15370, published on July 21, 2026, pertain to buffer overflows and denial of service risks. Affected systems include Fedora 43 and 44, with potential impacts on remote file transfers and server stability. Users are urged to apply patches immediately to mitigate risks. The vulnerabilities could allow attackers to exploit permissions and escalate privileges if not addressed.

Key Points: • Critical vulnerabilities in OpenSSH and libssh require immediate patching. • CVE-2026-59996 and CVE-2026-60002 involve file misplacement and use-after-free issues. • Libssh vulnerabilities include buffer overflows and denial of service risks.

ThreatCluster AI

Timeline

2026-07-08
CVE-2026-59996 published
OpenSSH vulnerability allows files to be misplaced during remote transfers, affecting security.
Linuxsecurity
2026-07-08
CVE-2026-60002 published
OpenSSH vulnerability involves a use-after-free issue during key re-exchange, posing security risks.
Linuxsecurity
2026-07-21
CVE-2026-15370 published
Libssh vulnerability identified as a buffer overflow in SFTP server longname construction.
Linuxsecurity
2026-07-21
Multiple libssh vulnerabilities published
Several denial of service vulnerabilities in libssh were disclosed, affecting server stability.
Linuxsecurity
2026-07-21
Fedora updates released
Fedora released critical updates for OpenSSH and libssh to address identified vulnerabilities.
Linuxsecurity
2026-07-21
CVE-2026-59843 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-59845 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-59846 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-59842 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-59844 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →