Executive brief
A security flaw was identified in libssh, a library used by many applications to provide secure communication over the SSH protocol. Due to a coding error in how the library verifies data integrity when using specific encryption settings, a sophisticated attacker positioned between two communicating parties could modify data in transit without being detected. This could lead to the corruption of sensitive information or the injection of malicious commands into a secure session.
Technical details
A vulnerability exists in libssh within the `src/libcrypto.c` component when compiled with the OpenSSL backend. The root cause is an incorrect check of the return value from the `EVP_DecryptFinal()` function during AES-GCM decryption. Because authentication tag verification failures are not properly handled as integrity failures, the library fails to detect if the ciphertext has been tampered with. An in-path (man-in-the-middle) attacker can exploit this to modify plaintext on the wire. This requires the session to be using AES-GCM and the library to be linked against OpenSSL.
Affected products
- libssh libssh All versions using OpenSSL backend for AES-GCM
- Red Hat Red Hat Enterprise Linux 8 affected status
- Red Hat Red Hat Enterprise Linux 9 affected status
- Red Hat Red Hat Enterprise Linux 10 affected status
Timeline
- 2026-07-08: disclosed: Reported via Red Hat Bugzilla
- 2026-07-21: advisory: NVD and Red Hat published advisory details