{"id":"CLSA-2026-1776864708","summary":"Fix CVE(s): CVE-2019-13115, CVE-2019-3855, CVE-2019-3856, CVE-2019-3863","details":"   * SECURITY UPDATE: integer overflow in transport read allowing\n     out-of-bounds write via crafted SSH packet\n     - debian/patches/CVE-2019-3855.patch: add packet_length bounds\n       check against LIBSSH2_PACKET_MAXPAYLOAD in transport read\n     - CVE-2019-3855\n   * SECURITY UPDATE: integer overflow in keyboard-interactive handling\n     allowing out-of-bounds write via crafted num-prompts value\n     - debian/patches/CVE-2019-3856.patch: cap num_prompts at 100 to\n       prevent excessive allocation in keyboard-interactive auth\n     - CVE-2019-3856\n   * SECURITY UPDATE: integer overflow in keyboard-interactive response\n     allowing out-of-bounds write via crafted response lengths\n     - debian/patches/CVE-2019-3863.patch: add SIZE_MAX overflow check\n       in keyboard-interactive response packet length calculation\n     - CVE-2019-3863\n   * SECURITY UPDATE: out-of-bounds memory access in kex exchange when\n     reading malformed data in diffie_hellman_sha1/sha256\n     - debian/patches/CVE-2019-13115.patch: add _libssh2_copy_string()\n       bounds-checked helper and use it in kex DH group exchange\n     - CVE-2019-13115","modified":"2026-06-04T09:45:49.783942431Z","published":"2026-04-22T13:31:52Z","upstream":["CVE-2019-13115","CVE-2019-3855","CVE-2019-3856","CVE-2019-3863"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2026-1776864708.html"}],"affected":[{"package":{"name":"libssh2-1","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libssh2-1?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0-2ubuntu0.1+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1776864708.json"}},{"package":{"name":"libssh2-1-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libssh2-1-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0-2ubuntu0.1+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1776864708.json"}}],"schema_version":"1.7.5"}