CVE Vulnerabilities

CVE-2026-59845

Detection of Error Condition Without Action

Published: Jul 21, 2026 | Modified: Jul 30, 2026
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the callers accessible process tree, leading to local denial of service.

Weakness

The product detects a specific error, but takes no actions to handle the error.

Affected Software

NameVendorStart VersionEnd Version
LibsshLibssh- (including)- (including)
Hardened_imagesRedhat- (including)- (including)
Enterprise_linuxRedhat8.0 (including)8.0 (including)
Enterprise_linuxRedhat9.0 (including)9.0 (including)
Enterprise_linuxRedhat10.0 (including)10.0 (including)
Red Hat Hardened ImagesRedHatlibssh-main-0.12.1-4.hum1*

Potential Mitigations

References