A malicious SFTP server can send malformed longname field of the `SSH_FXP_NAME` message (file listing). Due to the missing NULL check, the libssh could read beyond the buffer bounds on heap, causing unexpected behavior or crashes.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:18160 https://access.redhat.com/errata/RHSA-2026:18160