Junglewise Threat Intelligence

CVE-2026-0966: libssh denial of service in ssh_get_hexa function

CVE-2026-0966 · Severity: high · CVSS 8.2 · Published 2026-03-26

Technologies: Red Hat Enterprise Linux, Libssh, Red Hat OpenShift Container Platform. Vendors: Red Hat, Libssh.

Executive brief

A vulnerability has been identified in libssh, a library used by many applications to implement secure communications. An attacker can remotely crash the specific process handling their connection by sending specially crafted data during the authentication phase. This occurs only if the server has high-level debug logging enabled, potentially leading to a denial of service for that specific user session.

Technical details

A buffer underflow vulnerability (CWE-124) exists in the libssh API function `ssh_get_hexa()` when it receives zero-length input. This function is utilized internally by `ssh_get_fingerprint_hash()` and within the GSSAPI code for logging Object Identifiers (OIDs) received by the server. An unauthenticated remote attacker can trigger this flaw during GSSAPI authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation results in a denial of service (DoS) of the per-connection daemon process. The issue is fixed in libssh versions 0.11.4 and 0.12.0.

Affected products

  • libssh libssh up to (excluding) 0.11.4, up to (excluding) 0.12.0
  • Red Hat Enterprise Linux 8.0, 9.0, 10.0
  • Red Hat OpenShift Container Platform 4.0

Timeline

  • 2026-01-26: other: Reported to Red Hat Bugzilla
  • 2026-02-10: patched: libssh versions 0.12.0 and 0.11.4 released
  • 2026-03-26: disclosed: CVE published
  • 2026-05-19: advisory: Red Hat security advisory RHSA-2026:18160 issued

References

Related threats