Known vulnerabilities in libssh (Red Hat package)
Vendor:
Red Hat Inc.
Software:
libssh (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:libssh_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
24
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.10.4-19.el9_8
0.12.0-3.el10_2
0.9.6-4.el8_6.2
0.9.4-2.el8_4.2
0.10.4-18.el9
0.10.4-9.el9_2.2
0.10.4-17.el9_7
0.11.1-5.el10_1
0.9.6-3.el9_0.2
0.9.6-16.el8_10
0.10.4-15.el9_7
0.10.4-13.el9_4.1
0.9.6-3.el9_0.1
0.10.4-9.el9_2.1
0.9.4-2.el8_4.1
0.9.0-4.el8_2.1
0.9.6-13.el8_8.1
0.9.6-4.el8_6.1
0.9.6-15.el8_10
0.10.4-15.el9_6
0.11.1-4.el10_0
0.9.6-14.el8
0.10.4-13.el9
0.9.6-13.el8_9
0.9.6-13.el8_8
0.9.6-4.el8_6
0.10.4-9.el9_2
0.10.4-11.el9
0.9.6-10.el8_8
0.9.4-3.el8
0.9.6-3.el8
0.9.4-2.el8
0.7.1-7.el7
0.7.1-3.el7
0.7.1-2.el7
Vulnerabilities (24)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139533 - Use After Free CVE-2026-59850 |
CWE-416 | Low | 0.10.4-19.el9_8, 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260728153 SB2026080402 and 9 more |
||
| #VU139532 - Always-Incorrect Control Flow Implementation CVE-2026-59849 |
CWE-670 | Low | 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260817115 SB20260831114 |
||
| #VU139531 - Resource exhaustion CVE-2026-59848 |
CWE-400 | Low | 0.10.4-19.el9_8, 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260728153 SB2026080402 and 3 more |
||
| #VU139530 - Improper Validation of Integrity Check Value CVE-2026-59847 |
CWE-354 | Medium | 0.10.4-19.el9_8, 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260728153 SB2026080402 and 9 more |
||
| #VU139529 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-59846 |
CWE-78 | Low | 0.10.4-19.el9_8, 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260728153 SB2026080402 and 3 more |
||
| #VU139528 - Out-of-bounds read CVE-2026-59842 |
CWE-125 | Low | 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260817115 |
||
| #VU139527 - Improper input validation CVE-2026-59844 |
CWE-20 | Low | 0.10.4-19.el9_8, 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260728153 SB2026080402 and 8 more |
||
| #VU139526 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2026-59843 |
CWE-835 | Low | 0.10.4-19.el9_8, 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260728153 SB2026080402 and 8 more |
||
| #VU139525 - Stack-based buffer overflow CVE-2026-15370 |
CWE-121 | Medium | 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260817115 SB20260831114 |
||
| #VU139524 - Improper Check or Handling of Exceptional Conditions CVE-2026-59845 |
CWE-703 | Low | 0.10.4-19.el9_8, 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260728129 SB20260728153 and 9 more |
||
| #VU139523 - Improper Access Control CVE-2026-59851 |
CWE-284 | Medium | 0.12.0-3.el10_2 | 27.07.2026 |
SB20260727145 SB20260817115 |
||
| #VU115172 - Return of Wrong Status Code CVE-2025-5987 |
CWE-393 | Low | 0.10.4-9.el9_2.2, 0.10.4-17.el9_7, 0.11.1-5.el10_1 | 12.09.2025 |
SB2025091207 SB2025091215 SB2025091222 and 17 more |
||
| #VU114093 - Incorrect Calculation CVE-2025-5372 |
CWE-682 | Low | 0.9.4-2.el8_4.2, 0.9.6-3.el9_0.2, 0.9.6-4.el8_6.2, 0.9.6-16.el8_10 | 14.08.2025 |
SB2025081494 SB2025081495 SB2025081532 and 21 more |
||
| #VU111900 - Out-of-bounds read CVE-2025-5318 |
CWE-125 | Medium | 0.9.0-4.el8_2.1, 0.9.4-2.el8_4.1, 0.9.6-3.el9_0.1, 0.9.6-4.el8_6.1, 0.9.6-13.el8_8.1, 0.9.6-15.el8_10, 0.10.4-9.el9_2.1, 0.10.4-13.el9_4.1, 0.10.4-15.el9_6, 0.11.1-4.el10_0 | 24.06.2025 |
SB2025062451 SB2025062454 SB20250704157 and 61 more |
||
| #VU84540 - Unchecked Return Value CVE-2023-6918 |
CWE-252 | Low | 0.9.6-14.el8, 0.10.4-13.el9 | 19.12.2023 |
SB2023121906 SB2023121910 SB2023121911 and 63 more |
||
| #VU84538 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-6004 |
CWE-78 | Medium | 0.9.6-14.el8, 0.10.4-13.el9 | 19.12.2023 |
SB2023121905 SB2023121906 SB2023121910 and 58 more |
||
| #VU84537 - Inadequate Encryption Strength CVE-2023-48795 |
CWE-326 | Low | 0.9.6-4.el8_6, 0.9.6-13.el8_8, 0.9.6-13.el8_9, 0.10.4-9.el9_2 | 19.12.2023 |
SB2023121903 SB2023121905 SB2023121906 and 343 more |
||
| #VU75741 - Improper input validation CVE-2023-1667 |
CWE-20 | Medium | 0.9.6-4.el8_6, 0.9.6-10.el8_8, 0.10.4-11.el9 | 04.05.2023 |
SB2023050456 SB2023050501 SB2023052441 and 75 more |
||
| #VU75740 - Improper Authentication CVE-2023-2283 |
CWE-287 | High | 0.9.6-4.el8_6, 0.9.6-10.el8_8, 0.10.4-11.el9 | 04.05.2023 |
SB2023050456 SB2023050501 SB2023052441 and 84 more |
||
| #VU56217 - Memory corruption CVE-2021-3634 |
CWE-119 | High | 0.9.6-3.el8 | 31.08.2021 |
SB2021083135 SB2021083136 SB2022011903 and 46 more |
Showing elements 1 - 20 out of 24