Flaw in libssh Affects OpenSSL Backend Integrity Protection
CVE-2026-59847

5.9MEDIUM

What is CVE-2026-59847?

An issue has been identified in libssh where incorrect finalization checks in AES-GCM mode, particularly for builds utilizing the OpenSSL backend, could disable integrity protection. This vulnerability allows an in-path attacker to intercept and alter plaintext data transmitted over the network without raising any alarms. The flaw poses serious security risks for users relying on secure communication channels, enabling potential data manipulation without detection.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Ben Smyth for reporting this issue.
.