{"id":"ECHO-dafd-2ec3-4df0","summary":"Multiplication overflow in libssh2_publickey_list_fetch(): an\nattacker-controlled 32-bit num_attrs is multiplied by\nsizeof(libssh2_publickey_attribute) in the allocation without bounds checking.\nPer the CVE description and Debian tracker, the multiplication only overflows\n\"on 32-bit platforms\". Echo builds libssh2 exclusively for amd64/arm64, where\nsize_t is 64-bit and the product of a 32-bit count cannot overflow, so the\nvulnerable code path is not reachable on any shipped architecture.\nDebian status: undetermined (no fixed version). Upstream fix 344975259 caps\nnum_attrs at 1024; not backported — it does not apply to 1.11.1 (macro-namespace\nrefactor) and is unnecessary on the 64-bit architectures we ship.\nhttps://security-tracker.debian.org/tracker/CVE-2026-58050\n","modified":"2026-07-29T18:23:45.605744413Z","published":"2026-07-15T08:15:03.677Z","withdrawn":"2026-07-15T08:15:03.677Z","upstream":["CVE-2026-58050"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-58050"}],"affected":[{"package":{"name":"libssh2","ecosystem":"Echo","purl":"pkg:deb/echo/libssh2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.1-1+e4"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-dafd-2ec3-4df0.json"}}],"schema_version":"1.9.0"}