#1127693 libssh: CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731

Package:
src:libssh
Source:
src:libssh
Submitter:
Salvatore Bonaccorso
Date:
2026-08-03 15:49:01 UTC
Severity:
normal
Tags:
#1127693#5
Date:
2026-02-11 19:35:55 UTC
From:
To:
Hi,

The following vulnerabilities were published for libssh.

CVE-2026-0964[0]:
| Improper sanitation of paths received from SCP servers


CVE-2026-0965[1]:
| Denial of Service via improper configuration file handling


CVE-2026-0966[2]:
| Buffer underflow in ssh_get_hexa() on invalid input


CVE-2026-0967[3]:
| Denial of Service via inefficient regular expression processing


CVE-2026-0968[4]:
| Denial of Service due to malformed SFTP message


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-0964
https://www.cve.org/CVERecord?id=CVE-2026-0964
[1] https://security-tracker.debian.org/tracker/CVE-2026-0965
https://www.cve.org/CVERecord?id=CVE-2026-0965
[2] https://security-tracker.debian.org/tracker/CVE-2026-0966
https://www.cve.org/CVERecord?id=CVE-2026-0966
[3] https://security-tracker.debian.org/tracker/CVE-2026-0967
https://www.cve.org/CVERecord?id=CVE-2026-0967
[4] https://security-tracker.debian.org/tracker/CVE-2026-0968
https://www.cve.org/CVERecord?id=CVE-2026-0968

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1127693#12
Date:
2026-03-09 19:22:40 UTC
From:
To:
#1127693#19
Date:
2026-03-15 09:19:16 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libssh, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1127693@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Martin Pitt <mpitt@debian.org> (supplier of updated libssh package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 15 Mar 2026 08:56:59 +0000
Source: libssh
Architecture: source
Version: 0.12.0-1
Distribution: unstable
Urgency: medium
Maintainer: Laurent Bigonville <bigon@debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Closes: 1127693
Changes:
 libssh (0.12.0-1) unstable; urgency=medium
 .
   * New upstream security/feature release:
     - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request()
     - CVE-2026-0965: Possible Denial of Service when parsing unexpected
       configuration files
     - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input
     - CVE-2026-0967: Specially crafted patterns could cause DoS
     - CVE-2026-0968: OOB Read in sftp_parse_longname()
     - CVE-2026-3731: Read buffer overrun when handling SFTP extensions
     - Note: CVE-2025-14821 is Windows specific, does not apply to Linux
     (Closes: #1127693)
   * Enable new FIDO/U2F support. Build-depend on libfido2-dev.
   * Drop "Priority: optional" field.  Debian Policy 4.7.3 made this obsolete.
     Bump Standards-Version accordingly.
Checksums-Sha1:
 820beaf979645ec3a76cc80bd1123da3ad42dd0e 2615 libssh_0.12.0-1.dsc
 468fc33daa7822fb5f90cb599a62242607f3e425 751928 libssh_0.12.0.orig.tar.xz
 e6d2bec8530cda5779e9e0b9058dc4d89be2c2b9 833 libssh_0.12.0.orig.tar.xz.asc
 be8be65311179f7e2d9732d9ea9d360fcc40108d 31932 libssh_0.12.0-1.debian.tar.xz
 b035d073a2d1c7d83fe43f6e765107d4d4c1c55d 7663 libssh_0.12.0-1_source.buildinfo
Checksums-Sha256:
 72aba33c68ba6b89d2c72c095f9e10d0252f31138feaf24086d72a3798ad8c27 2615 libssh_0.12.0-1.dsc
 1a6af424d8327e5eedef4e5fe7f5b924226dd617ac9f3de80f217d82a36a7121 751928 libssh_0.12.0.orig.tar.xz
 8eaf061c358ffc7ead729d6cd93da9286d831224e97b6fc6535669a2955d1be5 833 libssh_0.12.0.orig.tar.xz.asc
 8f76de597989f3e4e0090467a244c2c57fd96f9ef5027218f67b26c744a3be36 31932 libssh_0.12.0-1.debian.tar.xz
 88dc61c89cd1489c36c8b12d7476d183d0607a0ab38b481053cf1189199e6cba 7663 libssh_0.12.0-1_source.buildinfo
Files:
 7f16589a71ef85e166aa3b11d344e4bf 2615 libs optional libssh_0.12.0-1.dsc
 244ff82e0902ba4bcd89e27f8cc2590c 751928 libs optional libssh_0.12.0.orig.tar.xz
 3fe0c5318468835f0d89328d357ba261 833 libs optional libssh_0.12.0.orig.tar.xz.asc
 602ebab4a69a485990ff559210fecdf8 31932 libs optional libssh_0.12.0-1.debian.tar.xz
 9b34f8539914c8ebf38f704e91d21c35 7663 libs optional libssh_0.12.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmm2dH8ACgkQ7nvd5Lhr
VxM+FA//X4I8gdTiQedAQWTZUWcrl7PYjwC87w6C8dai1h0F6dYpyykbZyW+i+UZ
UmPo45SIpnDOhgzRvv0N+V8Hjbzibp3CTIxjRvgMmeELsMSnNed0bP+/1Rssg3QJ
75aWqvA6ggX8QX6/e2OZi8JZoexPnlwEmipX+xhaYtTIgKm8J8TCngXkvnJgSQoe
W8CLXgwufshPzlkeiENpPuse1cjTtMcgGj7yoEWn6VPu5aGIAowddXPbxel7Utw/
ryUsRjRvYbYaNcSFKCwQYsaV3kfH0+qVLdGAH2q83qKfZwQcqVI34u8AkHRZUZld
ti2hTOLrCkGNKgF1pzv9kPJOvFcwTLhmQslJi6EAa/DEbrx+g+bym5uUIHL2lebt
pYDz3TvAZF2+CwvpwgmhUPUHV2dgTkk1SItxSR3ELoVJQsvfU1Rg73QWOIDvsenw
dpn8TZtWh19eNdOmf/bWPmxhef3EJHwovKgQ+m6GGQyQ1JJs8KzUjk8PecZGbyNc
MlJA9q8HsgpHXY7QYJw++ut5IhP/LyRjN8hw/QX99WXnT8t07CQYjELQWEmx9E/y
l7GaAyvaHGRrJ4BsG5644o0GquyN3SfhCAO0ty3MYNp/20Xz83AG61Oc3hZL/wck
r+m1s/gcZ2l5OTY558xsV9bCa3yl0UwiZv/xUorv4RySpvihTEs=
=X94n
-----END PGP SIGNATURE-----

#1127693#24
Date:
2026-03-15 09:31:47 UTC
From:
To:
Hello Salvatore and security team,

I finally got around to uploading the new 0.12.0 upstream release to Debian
unstable. For trixie I'd recomment to uploading the upstream point release
0.11.4 [2] as we did in the past -- beyond the security updates there are only
some ProxyJump bug fixes which IMHO are worth having.

The previous security update only backported the two security fixes instead of
updating to 0.11.3. Similarly, 0.11.3 [4] also only has these two plus three
bug fixes which are worth having.

I prepared a 0.11.4 update in https://people.debian.org/~mpitt/tmp/ , including
a full debdiff [5].

I have not uploaded yet, waiting for your review/ACK.

Thanks!

Pitti

[1] https://tracker.debian.org/news/1730502/accepted-libssh-0120-1-source-into-unstable/
[2] https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
[3] https://tracker.debian.org/news/1687440/accepted-libssh-0112-1deb13u1-source-into-proposed-updates/
[4] https://www.libssh.org/2025/09/09/libssh-0-11-3-security-and-bugfix-release/
[5] https://people.debian.org/~mpitt/tmp/libssh_0.11.2-1+deb13u1-0.11.4-0+deb13u1.debdiff
[6] https://salsa.debian.org/debian/libssh/-/commits/trixie?ref_type=heads

#1127693#29
Date:
2026-03-18 06:55:26 UTC
From:
To:
Hi Martin,

Sorry for the late reply, I missed your response.

We have marked all corresponding CVEs as no-dsa earlier, so can you
please make an upload through the stable updates process to get fixes
in the 13.5 point release?

Regards,
Salvatore

#1127693#40
Date:
2026-08-03 15:48:16 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libssh, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1127693@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Martin Pitt <mpitt@debian.org> (supplier of updated libssh package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 01 Aug 2026 13:42:11 +0200
Source: libssh
Architecture: source
Version: 0.11.5-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Laurent Bigonville <bigon@debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Closes: 1127693 1142537
Changes:
 libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium
 .
   * New upstream security/bug fix release 0.11.4:
     - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request()
     - CVE-2026-0965: Possible Denial of Service when parsing unexpected
       configuration files
     - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input
     - CVE-2026-0967: Specially crafted patterns could cause DoS
     - CVE-2026-0968: OOB Read in sftp_parse_longname()
     - CVE-2026-3731: Read buffer overrun when handling SFTP extensions
     - Note: CVE-2025-14821 is Windows specific, does not apply to Linux
https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
     (Closes: #1127693)
   * New upstream security/bug fix release 0.11.5:
     - CVE-2026-15370: Stack buffer overflow in SFTP server longname
       construction
     - CVE-2026-59843: Denial of service via zero advertised channel packet
       size
     - CVE-2026-59844: Denial of service via oversized SFTP read length
     - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork()
       failure
     - CVE-2026-59846: Information disclosure via ProxyCommand %r username
       expansion
     - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification
     - CVE-2026-59848: Denial of service via SFTP responses with unknown
       request IDs
     - CVE-2026-59849: Denial of service via automatic certificate
       authentication loop
     - CVE-2026-59850: Use-after-free via data callbacks on closed channels
     - Zero-initialize every ssh_string
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
     (Closes: #1142537)
Checksums-Sha1:
 2087dc4964630a8390271bf4168f8091174e0573 2371 libssh_0.11.5-0+deb13u1.dsc
 004929095e3d23cfb3d999bec7779362afea9e73 629716 libssh_0.11.5.orig.tar.xz
 30146aedb82f2b3790a117c21bebdea05b063e04 31932 libssh_0.11.5-0+deb13u1.debian.tar.xz
 7533bd519a94a351f5601b9babbf9d82f5acf448 8085 libssh_0.11.5-0+deb13u1_source.buildinfo
Checksums-Sha256:
 8aeaec786998691f4a2a320ae66943d3fa324882465d2a91f62658a13cd7bcff 2371 libssh_0.11.5-0+deb13u1.dsc
 6898ba9dd836d618b71dc7a4bb786a502c173cef5cafbf20fe5e0567ba4ea30c 629716 libssh_0.11.5.orig.tar.xz
 00576a30d068e87813f96b1b8405d249d7fdaf75b9e61c5af775910dc15022fd 31932 libssh_0.11.5-0+deb13u1.debian.tar.xz
 5bc098fe907fae7fd6a6cf9d1dc7d94a5ef4c348cbb73e5c1fc489da4dfac847 8085 libssh_0.11.5-0+deb13u1_source.buildinfo
Files:
 6d954a139c57a013b8c955c7f576cb58 2371 libs optional libssh_0.11.5-0+deb13u1.dsc
 73aaa09a07041c6ec85b154cbcf604c3 629716 libs optional libssh_0.11.5.orig.tar.xz
 7388f83349450388d6cae899b1059c92 31932 libs optional libssh_0.11.5-0+deb13u1.debian.tar.xz
 270d452d8e4fe75f9f3a7b74904394ab 8085 libs optional libssh_0.11.5-0+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmpuSoYACgkQ7nvd5Lhr
VxM1TA//ZzzSSGg3N+ZXXGyE6NXDuo8QYJu6FtQz+wg5EGIOGojrpZzPorlzQns9
xmj7xidBx8T1M2fnJf+PA4i8iT/P1ZzfXqOOZJYBHeUR4euW1TaxOcrgPjeaTEeo
jByYWX86FIIfGStutlAUIJUz77Lvf03rup2hY0ew3Cxj7z8/wFEnQ7zBxp6HbRlE
4v6ZFld8r/Bj7a/9O+YuCL0cA1E2QcUIoMqtibEatLKbmHD/guhNs1V9cfvcSEBh
+mkU1cTyKNFB8wlG+HC4VGrFpow01stdu/1Vl6fYd6nXhcmjd//gosvK0PNa/e0+
gAY12pdlxioSaOoJe3lpnIl0AjC7X8cCXOv+9eZIkJ1fRpikV4eX068Y+Y92TdWC
hGbgUxTSFSx0plvGhkkjLMq6p+f4ArQBqLc7TKSZpP3lfeCr4YmMSKkxs+hKzQCb
Wm5Or26CCqW/uAyDL2c/duWaLpLtb0R9LL5E08gNLqYrgN3HfSFkcN4w3eVPfjq4
JdKdVR22QaWlJAaKcAMyzLfsSi/kC2QR3Td3XbCZTW6mqZ3kZ21FJ3B6GLwy6ku5
tpynFbuupiRGCZMNRfRaH+6otfOftec0So9DAmaann8Yln8DzxDRL5xAvcGPkza3
8ppL0RzYX/j5onShhwpFonPlPWwFvnBt6vdLQg2BgFyz7A0R/E4=
=CuaC
-----END PGP SIGNATURE-----