#1144415 libssh2: CVE-2026-58050 CVE-2026-58051

Package:
src:libssh2
Source:
src:libssh2
Submitter:
Salvatore Bonaccorso
Date:
2026-08-20 15:31:01 UTC
Severity:
normal
Tags:
#1144415#5
Date:
2026-08-14 18:51:41 UTC
From:
To:
Hi,

The following vulnerabilities were published for libssh2.

CVE-2026-58050[0]:
| libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute
| count from a publickey-subsystem response and uses it in the
| allocation num_attrs * sizeof(libssh2_publickey_attribute) without
| bounds checking, so on 32-bit platforms the multiplication overflows
| to an undersized buffer. A malicious SSH server can then drive the
| attribute-parsing loop to write past the allocation, causing a heap
| buffer overflow in a connecting libssh2 client.


CVE-2026-58051[1]:
| libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC
| but does not zero-initialize new entries before parsing populates
| them, so a parse failure reaching the cleanup path leaves
| libssh2_publickey_list_free operating on an uninitialized entry. A
| malicious SSH server offering the publickey subsystem can use a
| malformed response to make cleanup free an uninitialized, attacker-
| influenceable attrs pointer in a connecting libssh2 client.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-58050
https://www.cve.org/CVERecord?id=CVE-2026-58050
https://github.com/libssh2/libssh2/pull/2128
https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12
[1] https://security-tracker.debian.org/tracker/CVE-2026-58051
https://www.cve.org/CVERecord?id=CVE-2026-58051
https://github.com/libssh2/libssh2/pull/2127
https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144415#10
Date:
2026-08-16 18:19:13 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libssh2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144415@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Nicolas Mora <babelouest@debian.org> (supplier of updated libssh2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 15 Aug 2026 09:17:51 -0400
Source: libssh2
Architecture: source
Version: 1.11.1-6
Distribution: unstable
Urgency: medium
Maintainer: Nicolas Mora <babelouest@debian.org>
Changed-By: Nicolas Mora <babelouest@debian.org>
Closes: 1144415
Changes:
 libssh2 (1.11.1-6) unstable; urgency=medium
 .
   * d/patches: Fix CVEs CVE-2026-58050 CVE-2026-58051 (Closes: #1144415)
Checksums-Sha1:
 5d799566af1813d193108f0d9e32d5ec8ef90521 2329 libssh2_1.11.1-6.dsc
 61c721696f08bf91d23dd59b766bac65e9a78b04 1093012 libssh2_1.11.1.orig.tar.gz
 d1d810ea2c4807fe71b0b66c784bd874ad5b9c67 488 libssh2_1.11.1.orig.tar.gz.asc
 86d5ca0c36c3a5de6167834bf9741926499c34bb 21116 libssh2_1.11.1-6.debian.tar.xz
 8c6be2dc3915cb40104110552a592442a12ff941 6129 libssh2_1.11.1-6_amd64.buildinfo
Checksums-Sha256:
 74a21ac2c6fd1ad234f8c9f7313649ceb7edd3e9ea8e35bcec9aa71f04e44d23 2329 libssh2_1.11.1-6.dsc
 d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7 1093012 libssh2_1.11.1.orig.tar.gz
 f5618c9356a1d5a8059d6cf64015d86547f06b2b8b1f542fbbaf381a736c8075 488 libssh2_1.11.1.orig.tar.gz.asc
 458237338c295ff7679bc76b00a82ae2c2501e647d107166f9e3fafbb6dd388a 21116 libssh2_1.11.1-6.debian.tar.xz
 f844119a13e25ac5042843aa484bb76ddddade9eaa187e78ad04233f7df32d32 6129 libssh2_1.11.1-6_amd64.buildinfo
Files:
 1ddba9f9e41cda1540aca828f3a80127 2329 libs optional libssh2_1.11.1-6.dsc
 38857d10b5c5deb198d6989dacace2e6 1093012 libs optional libssh2_1.11.1.orig.tar.gz
 5ecd37626fbb7ca0850a56a05a37a4c2 488 libs optional libssh2_1.11.1.orig.tar.gz.asc
 35cf933c00bb0980a587e8208e6ad99a 21116 libs optional libssh2_1.11.1-6.debian.tar.xz
 e5e2737e542520c5bc2bb9289de97845 6129 libs optional libssh2_1.11.1-6_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEhAWwL8wo75dEyPJT/oITlEC9IrkFAmqB+1cACgkQ/oITlEC9
Irn4hhAAqQJPNfvogDmRz8ZBCywe9s9Q1DtJlwk7+80cf4EVlG4/y98we27IsTXf
NF4FdEzefeNloOkymOwYjGvzyllfz/xAHd9ZJklb1tmuVZrIXMWe65IG6/V2DZbv
8c8c4ujedduQZiH+iCgVrdlrWf+dIj1e8Jg82PYo+L07V+wIckMf5J+MF9V/qW/2
2yPB9A/HGL6mIfmOsS/dQBb9d50YDwHfARSHfpdd44vSvZRTQlO14t0rymOLV3jd
C8swETqMl3Hw1/8tDDeyuM5bB9O7+rEsG5E7Rm3WFF6khQUSAGLMpS5APxgY7Tud
l0EM92rwLH7gqzd1PDwi1VVlfKCJcz/NkhT1qFGBzKXUjbaMsrEnv/Eh/GpLakol
AugtVpCeSNdWAgqwTI6uXOflXJnj4ByqNpAdM31Fib/MwbZ1V+Z6AarJlyk6qn6P
4ZN29MywO7Jio9DEWPOh5cONoPpPhv/UlES+wTzxzIX9f/B3V5UC2E+ZvLWb4Mf+
iLN1cGDkH6462EApZ6QImsMdMSK1wP/5BlUMPnoIZlUEpG/Peu1HWOsF6uquiwRt
gNuCqlA6hM2kDpQu0tMDMdUoaLS9DIif3fQ+Zplpk3VfOAUt76p/QxllfPSgyM1b
8xcyQ/UPwCqOU4B3Plcuh6+me3o+vEOpym0aP8l7UQgQwE2gkBE=
=ySeA
-----END PGP SIGNATURE-----

#1144415#15
Date:
2026-08-19 19:41:58 UTC
From:
To:
Hello,

The fix for these two CVEs is in unstable as 1.11.1-6, but the security tracker still lists trixie as vulnerable at 1.11.1-1+deb13u1.

Is an update for trixie planned, via a security update or the next point release? Knowing the likely route would help me decide whether to wait for it or work around the package.

Thanks for your work on Debian.

Regards,
Ejas Ali

#1144415#20
Date:
2026-08-20 15:28:42 UTC
From:
To:
Hi,

Thanks for you mail.

I'm working on that, currently. I hope send a patch soon.