Executive brief
libssh2 is a widely used library that allows applications to communicate securely using the SSH protocol. A vulnerability in how the library handles incoming data packets could allow a remote attacker to crash the application or potentially take control of the system. This could lead to unauthorized access to sensitive data or a complete disruption of services relying on this library.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the ssh2_transport_read() function within transport.c of libssh2. The root cause is a failure to enforce upper bounds on the packet_length field received from the network, leading to an integer overflow or buffer overflow (CWE-680) when processing excessively large values. A remote, unauthenticated attacker can exploit this by sending specially crafted SSH packets to corrupt heap memory. This memory corruption can result in a denial of service or remote code execution (RCE). The issue is fixed in commit 97acf3df (often referenced as 7acf3df) by adding boundary checks against LIBSSH2_PACKET_MAXPAYLOAD.
Affected products
- libssh2 libssh2 through 1.11.1
Timeline
- 2026-06-12: patched: Fix merged into master branch via pull request 2052
- 2026-06-17: disclosed: CVE published and advisory released by VulnCheck