Path traversal in libssh - CVE-2026-0964
Published: February 24, 2026
Vulnerability identifier: #VU123151
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0964
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim into connecting to a malicious SCP server and overwrite arbitrary files on the user's system.
Affected software
libssh
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
SUSE Linux Micro
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
LANTIME Operating System Firmware (LTOS)
libssh (Ubuntu package)
libssh-debugsource
libssh-debuginfo
libssh
libssh-help
libssh-devel
libssh-config
libssh4-debuginfo-32bit
libssh4-32bit
libssh4-debuginfo
libssh4
libssh4-64bit-debuginfo
libssh4-64bit
libssh4-32bit-debuginfo
libssh-doc
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
SUSE Linux Micro
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
LANTIME Operating System Firmware (LTOS)
libssh (Ubuntu package)
libssh-debugsource
libssh-debuginfo
libssh
libssh-help
libssh-devel
libssh-config
libssh4-debuginfo-32bit
libssh4-32bit
libssh4-debuginfo
libssh4
libssh4-64bit-debuginfo
libssh4-64bit
libssh4-32bit-debuginfo
libssh-doc
How to mitigate CVE-2026-0964
Install updates from vendor's website.
libssh - update to 0.11.4
LANTIME Operating System Firmware (LTOS) - update to 7.10.009
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.6+esm4, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6, 0.9.3-2ubuntu2.5+esm3
libssh-debugsource - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-debuginfo - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-help - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-devel - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-config - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh4-debuginfo-32bit - update to 0.9.8-3.21.1
libssh4-32bit - addressed in versions 0.9.8-3.21.1, 0.9.8-150600.11.9.1
libssh4-debuginfo - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh4 - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh-debugsource - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh-devel - addressed in versions 0.9.8-3.21.1, 0.9.8-150600.11.9.1
libssh4-64bit-debuginfo - update to 0.9.8-150600.11.9.1
libssh4-64bit - update to 0.9.8-150600.11.9.1
libssh4-32bit-debuginfo - update to 0.9.8-150600.11.9.1
libssh - update to 0.10.5-13
libssh-doc - update to 0.10.5-13
libssh-config - update to 0.10.5-13
libssh-devel - update to 0.10.5-13
LANTIME Operating System Firmware (LTOS) - update to 7.10.009
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.6+esm4, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6, 0.9.3-2ubuntu2.5+esm3
libssh-debugsource - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-debuginfo - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-help - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-devel - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-config - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh4-debuginfo-32bit - update to 0.9.8-3.21.1
libssh4-32bit - addressed in versions 0.9.8-3.21.1, 0.9.8-150600.11.9.1
libssh4-debuginfo - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh4 - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh-debugsource - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh-devel - addressed in versions 0.9.8-3.21.1, 0.9.8-150600.11.9.1
libssh4-64bit-debuginfo - update to 0.9.8-150600.11.9.1
libssh4-64bit - update to 0.9.8-150600.11.9.1
libssh4-32bit-debuginfo - update to 0.9.8-150600.11.9.1
libssh - update to 0.10.5-13
libssh-doc - update to 0.10.5-13
libssh-config - update to 0.10.5-13
libssh-devel - update to 0.10.5-13
External References
Related Security Bulletins
- Multiple vulnerabilities in libssh
- SUSE update for libssh
- Ubuntu update for libssh
- SUSE update for libssh
- SUSE update for libssh
- openEuler 24.03 LTS update for libssh
- Anolis OS update for libssh
- openEuler 22.03 LTS SP4 update for libssh
- openEuler 20.03 LTS SP4 update for libssh
- openEuler 24.03 LTS SP2 update for libssh
- openEuler 24.03 LTS SP1 update for libssh
- Meinberg LANTIME firmware update for third-party components
- SUSE update for libssh