Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
libssh2: Malicious SSH servers can crash or take control
USN-8532-1
Summary
Libssh2, a library used by some applications for secure connections, contains vulnerabilities that could allow a malicious SSH server to crash the application or take control of it. This is a concern for applications that use libssh2 for secure connections. Affected applications should update to the latest version of libssh2 to fix these issues.
What to do
- Update canonical libssh2 to version 1.11.0-4.1ubuntu0.24.04.3.
- Update canonical libssh2 to version 1.11.1-1ubuntu0.26.04.3.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:24.04:LTS | canonical | libssh2 |
< 1.11.0-4.1ubuntu0.24.04.3 Fix: upgrade to 1.11.0-4.1ubuntu0.24.04.3
|
| Ubuntu:26.04:LTS | canonical | libssh2 |
< 1.11.1-1ubuntu0.26.04.3 Fix: upgrade to 1.11.1-1ubuntu0.26.04.3
|
Original title
libssh2 vulnerabilities
Original description
It was discovered that libssh2 incorrectly handled certain publickey
subsystem attributes. A remote attacker controlling a malicious SSH server
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2026-58050)
It was discovered that libssh2 did not properly initialize publickey list
entries before parsing. A remote attacker controlling a malicious SSH
server could use this issue to cause a denial of service or possibly
execute arbitrary code. (CVE-2026-58051)
subsystem attributes. A remote attacker controlling a malicious SSH server
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2026-58050)
It was discovered that libssh2 did not properly initialize publickey list
entries before parsing. A remote attacker controlling a malicious SSH
server could use this issue to cause a denial of service or possibly
execute arbitrary code. (CVE-2026-58051)
- https://ubuntu.com/security/notices/USN-8532-1 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-58050 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-58051 Third Party Advisory
Published: 13 Jul 2026 · Updated: 13 Jul 2026 · First seen: 13 Jul 2026