Out-of-bounds read in libssh - CVE-2026-0968

 

Out-of-bounds read in libssh - CVE-2026-0968

Published: February 24, 2026


Vulnerability identifier: #VU123156
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0968
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the sftp_parse_longname() function. A malicious SFTP server can send a specially crafted SSH_FXP_NAME message to trigger an out-of-bounds read and crash the application or read parts of system memory on the client system. 


Affected software

libssh
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
SUSE Linux Micro
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
LANTIME Operating System Firmware (LTOS)
libssh (Ubuntu package)
libssh
libssh-debuginfo
libssh-debugsource
libssh-devel
libssh-help
libssh-config
libssh4-32bit
libssh4-debuginfo-32bit
libssh4-debuginfo
libssh4
libssh4-64bit
libssh4-32bit-debuginfo
libssh4-64bit-debuginfo
libssh-doc

How to mitigate CVE-2026-0968

Install updates from vendor's website.

libssh - update to 0.11.4
LANTIME Operating System Firmware (LTOS) - update to 7.10.009
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.6+esm4, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6, 0.9.3-2ubuntu2.5+esm3
libssh - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-debuginfo - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-debugsource - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-devel - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-help - addressed in versions 0.9.4-15, 0.9.6-15, 0.10.5-9
libssh-config - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh4-32bit - addressed in versions 0.9.8-3.21.1, 0.9.8-150600.11.9.1
libssh4-debuginfo-32bit - update to 0.9.8-3.21.1
libssh4-debuginfo - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh4 - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh-debugsource - addressed in versions 0.9.8-3.21.1, 0.9.8-150200.13.15.1, 0.9.8-150600.11.9.1, 0.11.4-160000.1.1
libssh-devel - addressed in versions 0.9.8-3.21.1, 0.9.8-150600.11.9.1
libssh4-64bit - update to 0.9.8-150600.11.9.1
libssh4-32bit-debuginfo - update to 0.9.8-150600.11.9.1
libssh4-64bit-debuginfo - update to 0.9.8-150600.11.9.1
libssh-doc - update to 0.10.5-13
libssh-config - update to 0.10.5-13
libssh-devel - update to 0.10.5-13
libssh - update to 0.10.5-13

External References

Related Security Bulletins