{"id":"CLSA-2026-1779467653","summary":"libssh: Fix of 4 CVEs","details":"- CVE-2025-4877: prevent base64 integer overflow and potential OOB write\n- CVE-2025-4878: initialize stack pointers to mitigate use of uninitialized\n  values in legacy privatekey_from_file() path\n- CVE-2025-8277: fix DH-GEX packet filter and free unused ephemeral / ECDH\n  keys to prevent memory exhaustion\n- CVE-2026-0965: skip non-regular and oversized configuration / known_hosts\n  files to avoid local DoS","modified":"2026-05-27T11:18:14.849208507Z","published":"2026-05-22T16:34:17Z","upstream":["CVE-2025-4877","CVE-2025-4878","CVE-2025-8277","CVE-2026-0965"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/tuxcare9.6esu/CLSA-2026-1779467653.html"}],"affected":[{"package":{"name":"libssh","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/libssh?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.4-15.el9_6.tuxcare.els8"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1779467653.json"}},{"package":{"name":"libssh-config","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/libssh-config?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.4-15.el9_6.tuxcare.els8"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1779467653.json"}},{"package":{"name":"libssh-devel","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/libssh-devel?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.4-15.el9_6.tuxcare.els8"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1779467653.json"}}],"schema_version":"1.7.5"}