CVE Vulnerabilities

CVE-2026-0966

Buffer Underwrite ('Buffer Underflow')

Published: Mar 26, 2026 | Modified: May 19, 2026
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A flaw was found in libssh. The API function ssh_get_hexa() is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the servers logging verbosity is set to SSH_LOG_PACKET (3) or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.

Weakness

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Affected Software

NameVendorStart VersionEnd Version
LibsshLibssh*0.11.4 (excluding)
Hardened_imagesRedhat- (including)- (including)
Openshift_container_platformRedhat4.0 (including)4.0 (including)
Enterprise_linuxRedhat8.0 (including)8.0 (including)
Enterprise_linuxRedhat9.0 (including)9.0 (including)
Enterprise_linuxRedhat10.0 (including)10.0 (including)
Red Hat Enterprise Linux 10RedHatlibssh-0:0.12.0-2.el10*
Red Hat Enterprise Linux 9RedHatlibssh-0:0.10.4-18.el9*
Red Hat Enterprise Linux 9RedHatlibssh-0:0.10.4-18.el9*
Red Hat Hardened ImagesRedHatlibssh-main-0.12.0-1.1.hum1*
LibsshUbuntudevel*
LibsshUbuntuesm-infra-legacy/xenial*
LibsshUbuntuesm-infra/bionic*
LibsshUbuntuesm-infra/focal*
LibsshUbuntuesm-infra/xenial*
LibsshUbuntujammy*
LibsshUbuntunoble*
LibsshUbuntuquesting*
LibsshUbuntuupstream*

Potential Mitigations

References