Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

libssh2: Malicious SSH servers can crash or take control

USN-8532-1
Summary

Libssh2, a library used by some applications for secure connections, contains vulnerabilities that could allow a malicious SSH server to crash the application or take control of it. This is a concern for applications that use libssh2 for secure connections. Affected applications should update to the latest version of libssh2 to fix these issues.

What to do
  • Update canonical libssh2 to version 1.11.0-4.1ubuntu0.24.04.3.
  • Update canonical libssh2 to version 1.11.1-1ubuntu0.26.04.3.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:24.04:LTS canonical libssh2 < 1.11.0-4.1ubuntu0.24.04.3
Fix: upgrade to 1.11.0-4.1ubuntu0.24.04.3
Ubuntu:26.04:LTS canonical libssh2 < 1.11.1-1ubuntu0.26.04.3
Fix: upgrade to 1.11.1-1ubuntu0.26.04.3
Original title
libssh2 vulnerabilities
Original description
It was discovered that libssh2 incorrectly handled certain publickey
subsystem attributes. A remote attacker controlling a malicious SSH server
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2026-58050)

It was discovered that libssh2 did not properly initialize publickey list
entries before parsing. A remote attacker controlling a malicious SSH
server could use this issue to cause a denial of service or possibly
execute arbitrary code. (CVE-2026-58051)
Published: 13 Jul 2026 · Updated: 13 Jul 2026 · First seen: 13 Jul 2026