{"id":"SUSE-SU-2026:21396-1","summary":"Security update for libssh","details":"This update for libssh fixes the following issues:\n\n- Update to version 0.11.4:\n- CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() (bsc#1258049)\n- CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files (bsc#1258045)\n- CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054)\n- CVE-2026-0967: Specially crafted patterns could cause DoS (bsc#1258081)\n- CVE-2026-0968: OOB Read in sftp_parse_longname() (bsc#1258080)\n- CVE-2025-8114: Fix NULL pointer dereference after allocation failure (bsc#1246974)\n- CVE-2025-8277: Fix memory leak of ephemeral key pair during repeated wrong KEX (bsc#1249375)\n","modified":"2026-05-01T18:32:38.521996Z","published":"2026-04-30T09:40:57Z","related":["CVE-2025-8114","CVE-2025-8277","CVE-2026-0964","CVE-2026-0965","CVE-2026-0966","CVE-2026-0967","CVE-2026-0968"],"upstream":["CVE-2025-8114","CVE-2025-8277","CVE-2026-0964","CVE-2026-0965","CVE-2026-0966","CVE-2026-0967","CVE-2026-0968"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621396-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246974"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249375"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258045"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258049"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258054"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258080"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258081"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-8114"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-8277"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0964"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0965"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0966"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0968"}],"schema_version":"1.7.5"}