#1127693 libssh: CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 #1127693
- Package:
- src:libssh
- Source:
- src:libssh
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-03 15:49:01 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for libssh. CVE-2026-0964[0]: | Improper sanitation of paths received from SCP servers CVE-2026-0965[1]: | Denial of Service via improper configuration file handling CVE-2026-0966[2]: | Buffer underflow in ssh_get_hexa() on invalid input CVE-2026-0967[3]: | Denial of Service via inefficient regular expression processing CVE-2026-0968[4]: | Denial of Service due to malformed SFTP message If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-0964 https://www.cve.org/CVERecord?id=CVE-2026-0964 [1] https://security-tracker.debian.org/tracker/CVE-2026-0965 https://www.cve.org/CVERecord?id=CVE-2026-0965 [2] https://security-tracker.debian.org/tracker/CVE-2026-0966 https://www.cve.org/CVERecord?id=CVE-2026-0966 [3] https://security-tracker.debian.org/tracker/CVE-2026-0967 https://www.cve.org/CVERecord?id=CVE-2026-0967 [4] https://security-tracker.debian.org/tracker/CVE-2026-0968 https://www.cve.org/CVERecord?id=CVE-2026-0968 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hi, One more CVE was assigned, CVE-2026-3731. This was for https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt and fixed by https://git.libssh.org/projects/libssh.git/commit/?id=f80670a7aba86cbb442c9b115c9eaf4ca04601b8 in 11.4 as well. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libssh, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1127693@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Martin Pitt <mpitt@debian.org> (supplier of updated libssh package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 15 Mar 2026 08:56:59 +0000
Source: libssh
Architecture: source
Version: 0.12.0-1
Distribution: unstable
Urgency: medium
Maintainer: Laurent Bigonville <bigon@debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Closes: 1127693
Changes:
libssh (0.12.0-1) unstable; urgency=medium
.
* New upstream security/feature release:
- CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request()
- CVE-2026-0965: Possible Denial of Service when parsing unexpected
configuration files
- CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input
- CVE-2026-0967: Specially crafted patterns could cause DoS
- CVE-2026-0968: OOB Read in sftp_parse_longname()
- CVE-2026-3731: Read buffer overrun when handling SFTP extensions
- Note: CVE-2025-14821 is Windows specific, does not apply to Linux
(Closes: #1127693)
* Enable new FIDO/U2F support. Build-depend on libfido2-dev.
* Drop "Priority: optional" field. Debian Policy 4.7.3 made this obsolete.
Bump Standards-Version accordingly.
Checksums-Sha1:
820beaf979645ec3a76cc80bd1123da3ad42dd0e 2615 libssh_0.12.0-1.dsc
468fc33daa7822fb5f90cb599a62242607f3e425 751928 libssh_0.12.0.orig.tar.xz
e6d2bec8530cda5779e9e0b9058dc4d89be2c2b9 833 libssh_0.12.0.orig.tar.xz.asc
be8be65311179f7e2d9732d9ea9d360fcc40108d 31932 libssh_0.12.0-1.debian.tar.xz
b035d073a2d1c7d83fe43f6e765107d4d4c1c55d 7663 libssh_0.12.0-1_source.buildinfo
Checksums-Sha256:
72aba33c68ba6b89d2c72c095f9e10d0252f31138feaf24086d72a3798ad8c27 2615 libssh_0.12.0-1.dsc
1a6af424d8327e5eedef4e5fe7f5b924226dd617ac9f3de80f217d82a36a7121 751928 libssh_0.12.0.orig.tar.xz
8eaf061c358ffc7ead729d6cd93da9286d831224e97b6fc6535669a2955d1be5 833 libssh_0.12.0.orig.tar.xz.asc
8f76de597989f3e4e0090467a244c2c57fd96f9ef5027218f67b26c744a3be36 31932 libssh_0.12.0-1.debian.tar.xz
88dc61c89cd1489c36c8b12d7476d183d0607a0ab38b481053cf1189199e6cba 7663 libssh_0.12.0-1_source.buildinfo
Files:
7f16589a71ef85e166aa3b11d344e4bf 2615 libs optional libssh_0.12.0-1.dsc
244ff82e0902ba4bcd89e27f8cc2590c 751928 libs optional libssh_0.12.0.orig.tar.xz
3fe0c5318468835f0d89328d357ba261 833 libs optional libssh_0.12.0.orig.tar.xz.asc
602ebab4a69a485990ff559210fecdf8 31932 libs optional libssh_0.12.0-1.debian.tar.xz
9b34f8539914c8ebf38f704e91d21c35 7663 libs optional libssh_0.12.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmm2dH8ACgkQ7nvd5Lhr
VxM+FA//X4I8gdTiQedAQWTZUWcrl7PYjwC87w6C8dai1h0F6dYpyykbZyW+i+UZ
UmPo45SIpnDOhgzRvv0N+V8Hjbzibp3CTIxjRvgMmeELsMSnNed0bP+/1Rssg3QJ
75aWqvA6ggX8QX6/e2OZi8JZoexPnlwEmipX+xhaYtTIgKm8J8TCngXkvnJgSQoe
W8CLXgwufshPzlkeiENpPuse1cjTtMcgGj7yoEWn6VPu5aGIAowddXPbxel7Utw/
ryUsRjRvYbYaNcSFKCwQYsaV3kfH0+qVLdGAH2q83qKfZwQcqVI34u8AkHRZUZld
ti2hTOLrCkGNKgF1pzv9kPJOvFcwTLhmQslJi6EAa/DEbrx+g+bym5uUIHL2lebt
pYDz3TvAZF2+CwvpwgmhUPUHV2dgTkk1SItxSR3ELoVJQsvfU1Rg73QWOIDvsenw
dpn8TZtWh19eNdOmf/bWPmxhef3EJHwovKgQ+m6GGQyQ1JJs8KzUjk8PecZGbyNc
MlJA9q8HsgpHXY7QYJw++ut5IhP/LyRjN8hw/QX99WXnT8t07CQYjELQWEmx9E/y
l7GaAyvaHGRrJ4BsG5644o0GquyN3SfhCAO0ty3MYNp/20Xz83AG61Oc3hZL/wck
r+m1s/gcZ2l5OTY558xsV9bCa3yl0UwiZv/xUorv4RySpvihTEs=
=X94n
-----END PGP SIGNATURE-----
Hello Salvatore and security team, I finally got around to uploading the new 0.12.0 upstream release to Debian unstable. For trixie I'd recomment to uploading the upstream point release 0.11.4 [2] as we did in the past -- beyond the security updates there are only some ProxyJump bug fixes which IMHO are worth having. The previous security update only backported the two security fixes instead of updating to 0.11.3. Similarly, 0.11.3 [4] also only has these two plus three bug fixes which are worth having. I prepared a 0.11.4 update in https://people.debian.org/~mpitt/tmp/ , including a full debdiff [5]. I have not uploaded yet, waiting for your review/ACK. Thanks! Pitti [1] https://tracker.debian.org/news/1730502/accepted-libssh-0120-1-source-into-unstable/ [2] https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ [3] https://tracker.debian.org/news/1687440/accepted-libssh-0112-1deb13u1-source-into-proposed-updates/ [4] https://www.libssh.org/2025/09/09/libssh-0-11-3-security-and-bugfix-release/ [5] https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1-0.11.4-0+deb13u1.debdiff [6] https://salsa.debian.org/debian/libssh/-/commits/trixie?ref_type=heads
Hi Martin, Sorry for the late reply, I missed your response. We have marked all corresponding CVEs as no-dsa earlier, so can you please make an upload through the stable updates process to get fixes in the 13.5 point release? Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libssh, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1127693@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Martin Pitt <mpitt@debian.org> (supplier of updated libssh package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 01 Aug 2026 13:42:11 +0200
Source: libssh
Architecture: source
Version: 0.11.5-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Laurent Bigonville <bigon@debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Closes: 1127693 1142537
Changes:
libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium
.
* New upstream security/bug fix release 0.11.4:
- CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request()
- CVE-2026-0965: Possible Denial of Service when parsing unexpected
configuration files
- CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input
- CVE-2026-0967: Specially crafted patterns could cause DoS
- CVE-2026-0968: OOB Read in sftp_parse_longname()
- CVE-2026-3731: Read buffer overrun when handling SFTP extensions
- Note: CVE-2025-14821 is Windows specific, does not apply to Linux
https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
(Closes: #1127693)
* New upstream security/bug fix release 0.11.5:
- CVE-2026-15370: Stack buffer overflow in SFTP server longname
construction
- CVE-2026-59843: Denial of service via zero advertised channel packet
size
- CVE-2026-59844: Denial of service via oversized SFTP read length
- CVE-2026-59845: Denial of service via unchecked ProxyCommand fork()
failure
- CVE-2026-59846: Information disclosure via ProxyCommand %r username
expansion
- CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification
- CVE-2026-59848: Denial of service via SFTP responses with unknown
request IDs
- CVE-2026-59849: Denial of service via automatic certificate
authentication loop
- CVE-2026-59850: Use-after-free via data callbacks on closed channels
- Zero-initialize every ssh_string
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
(Closes: #1142537)
Checksums-Sha1:
2087dc4964630a8390271bf4168f8091174e0573 2371 libssh_0.11.5-0+deb13u1.dsc
004929095e3d23cfb3d999bec7779362afea9e73 629716 libssh_0.11.5.orig.tar.xz
30146aedb82f2b3790a117c21bebdea05b063e04 31932 libssh_0.11.5-0+deb13u1.debian.tar.xz
7533bd519a94a351f5601b9babbf9d82f5acf448 8085 libssh_0.11.5-0+deb13u1_source.buildinfo
Checksums-Sha256:
8aeaec786998691f4a2a320ae66943d3fa324882465d2a91f62658a13cd7bcff 2371 libssh_0.11.5-0+deb13u1.dsc
6898ba9dd836d618b71dc7a4bb786a502c173cef5cafbf20fe5e0567ba4ea30c 629716 libssh_0.11.5.orig.tar.xz
00576a30d068e87813f96b1b8405d249d7fdaf75b9e61c5af775910dc15022fd 31932 libssh_0.11.5-0+deb13u1.debian.tar.xz
5bc098fe907fae7fd6a6cf9d1dc7d94a5ef4c348cbb73e5c1fc489da4dfac847 8085 libssh_0.11.5-0+deb13u1_source.buildinfo
Files:
6d954a139c57a013b8c955c7f576cb58 2371 libs optional libssh_0.11.5-0+deb13u1.dsc
73aaa09a07041c6ec85b154cbcf604c3 629716 libs optional libssh_0.11.5.orig.tar.xz
7388f83349450388d6cae899b1059c92 31932 libs optional libssh_0.11.5-0+deb13u1.debian.tar.xz
270d452d8e4fe75f9f3a7b74904394ab 8085 libs optional libssh_0.11.5-0+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmpuSoYACgkQ7nvd5Lhr
VxM1TA//ZzzSSGg3N+ZXXGyE6NXDuo8QYJu6FtQz+wg5EGIOGojrpZzPorlzQns9
xmj7xidBx8T1M2fnJf+PA4i8iT/P1ZzfXqOOZJYBHeUR4euW1TaxOcrgPjeaTEeo
jByYWX86FIIfGStutlAUIJUz77Lvf03rup2hY0ew3Cxj7z8/wFEnQ7zBxp6HbRlE
4v6ZFld8r/Bj7a/9O+YuCL0cA1E2QcUIoMqtibEatLKbmHD/guhNs1V9cfvcSEBh
+mkU1cTyKNFB8wlG+HC4VGrFpow01stdu/1Vl6fYd6nXhcmjd//gosvK0PNa/e0+
gAY12pdlxioSaOoJe3lpnIl0AjC7X8cCXOv+9eZIkJ1fRpikV4eX068Y+Y92TdWC
hGbgUxTSFSx0plvGhkkjLMq6p+f4ArQBqLc7TKSZpP3lfeCr4YmMSKkxs+hKzQCb
Wm5Or26CCqW/uAyDL2c/duWaLpLtb0R9LL5E08gNLqYrgN3HfSFkcN4w3eVPfjq4
JdKdVR22QaWlJAaKcAMyzLfsSi/kC2QR3Td3XbCZTW6mqZ3kZ21FJ3B6GLwy6ku5
tpynFbuupiRGCZMNRfRaH+6otfOftec0So9DAmaann8Yln8DzxDRL5xAvcGPkza3
8ppL0RzYX/j5onShhwpFonPlPWwFvnBt6vdLQg2BgFyz7A0R/E4=
=CuaC
-----END PGP SIGNATURE-----