Description

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.

INFO

Published Date :

2026-03-26T20:06:29.554Z

Last Modified :

2026-05-01T16:01:05.494Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-0968 vulnerability.

Vendors Products
Libssh
  • Libssh
Redhat
  • Enterprise Linux
  • Hummingbird
  • Openshift

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact