A malicious SFTP server can send malformed longname field of the `SSH_FXP_NAME` message (file listing). Due to the missing NULL check, the libssh could read beyond the buffer bounds on heap, causing unexpected behavior or crashes.