CVE-2026-59842

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libssh:libssh:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-21 12:18

Updated : 2026-08-19 05:17


NVD link : CVE-2026-59842

Mitre link : CVE-2026-59842

CVE.ORG link : CVE-2026-59842


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • hardened_images

libssh

  • libssh
CWE
CWE-125

Out-of-bounds Read