[CLSA-2026:1787740667] Fix CVE(s): CVE-2026-66032
Type:
security
Severity:
Important
Release date:
2026-08-26 10:38:04 UTC
Description:
* SECURITY UPDATE: double free in sftp_open() lets a malicious SSH server corrupt the heap of an authenticated client opening an SFTP session - debian/patches/CVE-2026-66032.patch: set data to NULL after freeing the SSH_FXP_STATUS response buffer on the FX_OK path, so the if(badness) arm cannot free the same pointer a second time when the follow-up sftp_packet_require() for SSH_FXP_HANDLE fails, in sftp_open() in src/sftp.c - CVE-2026-66032
CVEs fixed:
Updated packages:
  • libssh2-1_1.8.0-2.1+deb10u1+tuxcare.els3_amd64.deb
    sha:db2b9d030ab9a8fc2163855c61f90b51d3b9c5f9
  • libssh2-1-dev_1.8.0-2.1+deb10u1+tuxcare.els3_amd64.deb
    sha:8061f7ee27a3cdc48ca69a21b1c0a97ddb92aef9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.