Zurück zur CVE-Übersicht
CVE-2026-7598
HIGH(7.3)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Risk Signal Score18/100 — NIEDRIG
- CVSS 7.3 — Hoch
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.5%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.3
Technische Schwere
Beschreibung
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.
Betroffene Produkte
- cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*
Referenzen
- https://github.com/libssh2/libssh2/
- https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744...
- https://github.com/libssh2/libssh2/pull/1858
- https://vuldb.com/submit/805564
- https://vuldb.com/vuln/360555
- https://vuldb.com/vuln/360555/cti
- https://access.redhat.com/errata/RHSA-2026:16736
- https://access.redhat.com/errata/RHSA-2026:61752
- https://access.redhat.com/errata/RHSA-2026:7021
- https://access.redhat.com/security/cve/CVE-2026-7598