Libssh Vulnerability in SFTP Servers Leading to Heap Memory Issues
CVE-2026-0968
3.1LOW
What is CVE-2026-0968?
A vulnerability exists in libssh that allows a malicious SFTP server to exploit a flaw by sending a malformed 'longname' field in an SSH_FXP_NAME message during file listing operations. This oversight in checking for null values can trigger memory access violations, resulting in unexpected application behavior, crashes, or service interruptions due to potential denial of service (DoS). Attackers could leverage this weakness to execute specific payloads, heightening security risks for users engaged in secure file transfer.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.0
Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jakub Jelen (libssh) and nevv (CTyun Red-Shield Security Lab) for reporting this issue.