Release date:
2026-08-26 10:38:04 UTC
Description:
* SECURITY UPDATE: double free in sftp_open() lets a malicious SSH server
corrupt the heap of an authenticated client opening an SFTP session
- debian/patches/CVE-2026-66032.patch: set data to NULL after freeing the
SSH_FXP_STATUS response buffer on the FX_OK path, so the if(badness)
arm cannot free the same pointer a second time when the follow-up
sftp_packet_require() for SSH_FXP_HANDLE fails, in sftp_open() in
src/sftp.c
- CVE-2026-66032
Updated packages:
-
libssh2-1_1.8.0-2.1+deb10u1+tuxcare.els3_amd64.deb
sha:db2b9d030ab9a8fc2163855c61f90b51d3b9c5f9
-
libssh2-1-dev_1.8.0-2.1+deb10u1+tuxcare.els3_amd64.deb
sha:8061f7ee27a3cdc48ca69a21b1c0a97ddb92aef9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.