CVE Vulnerabilities

CVE-2026-59844

Memory Allocation with Excessive Size Value

Published: Jul 21, 2026 | Modified: Sep 01, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

Weakness

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Affected Software

NameVendorStart VersionEnd Version
LibsshLibssh- (including)- (including)
Hardened_imagesRedhat- (including)- (including)
Enterprise_linuxRedhat8.0 (including)8.0 (including)
Enterprise_linuxRedhat9.0 (including)9.0 (including)
Enterprise_linuxRedhat10.0 (including)10.0 (including)
Red Hat Enterprise Linux 10RedHatlibssh-0:0.12.0-3.el10_2*
Red Hat Enterprise Linux 8RedHatlibssh-0:0.9.6-17.el8_10*
Red Hat Enterprise Linux 8RedHatlibssh-0:0.9.6-17.el8_10*
Red Hat Enterprise Linux 9RedHatlibssh-0:0.10.4-19.el9_8*
Red Hat Enterprise Linux 9RedHatlibssh-0:0.10.4-19.el9_8*
Red Hat Hardened ImagesRedHatlibssh-main-0.12.1-4.hum1*
LibsshUbunturesolute*
LibsshUbuntuupstream*

Potential Mitigations

References