Bug 2506860 (CVE-2026-66034) - CVE-2026-66034 libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read
Summary: CVE-2026-66034 libssh2: libssh2: Information disclosure and potential arbitra...
Keywords:
Status: NEW
Alias: CVE-2026-66034
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2507310 2507311 2507312
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-24 17:04 UTC by OSIDB Bzimport
Modified: 2026-07-25 15:01 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-24 17:04:09 UTC
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.


Note You need to log in before you can comment on or make changes to this bug.