Denial of Service Vulnerability in libssh Affects Multiple Clients
CVE-2026-59848

5.3MEDIUM

What is CVE-2026-59848?

A vulnerability exists in libssh, where a malicious SFTP server can exploit queued responses for unknown request IDs, leading to unbounded memory consumption. This can result in a denial of service for clients as their memory usage grows without limit, potentially causing crashes or inaccessibility. Mitigation of this issue requires users to ensure they are running an updated version of libssh.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Aisle Research for reporting this issue.
.