[CLSA-2026:1778745959] libssh2: Fix of CVE-2026-7598
Type:
security
Severity:
Critical
Release date:
2026-05-14 19:22:04 UTC
Description:
- CVE-2026-7598: add username_len/password_len bounds checks in userauth_list() and userauth_password() to prevent integer overflow when allocating the SSH USERAUTH_REQUEST packet buffer
Updated packages:
  • libssh2-1.4.2-3.0.1.el6_10.1.tuxcare.els4.i686.rpm
    sha:84ce44486e41d460c77bbf0162d9de00308faa960b20d5655c883ae4e0e348b0
  • libssh2-1.4.2-3.0.1.el6_10.1.tuxcare.els4.x86_64.rpm
    sha:ff070a4376c915e72ccaeefe534e9fcd2b62c6c630d79032bf0ad8a591e59a30
  • libssh2-devel-1.4.2-3.0.1.el6_10.1.tuxcare.els4.i686.rpm
    sha:a4df5ee315ece7022ff69982c73ba552dfc6b9ddb48d8c2aafcb96ed3da6a3e8
  • libssh2-devel-1.4.2-3.0.1.el6_10.1.tuxcare.els4.x86_64.rpm
    sha:d59e38df35ee542741f23c27704a2a7c2731da63f6907f8009ce297633fe7311
  • libssh2-docs-1.4.2-3.0.1.el6_10.1.tuxcare.els4.x86_64.rpm
    sha:7f91dde44829df80cf5e20edd25cbf8625c8842808d36d0045329c902e6c6ffa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.