CVE-2026-15370

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libssh:libssh:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-21 09:16

Updated : 2026-08-17 22:16


NVD link : CVE-2026-15370

Mitre link : CVE-2026-15370

CVE.ORG link : CVE-2026-15370


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • hardened_images

libssh

  • libssh
CWE
CWE-121

Stack-based Buffer Overflow