Bug#1142856: libssh: CVE-2026-66032 CVE-2026-66033 CVE-2026-66034 CVE-2026-66035

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: libssh
Version: 1.11.1-4
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for libssh.

CVE-2026-66032[0]:
| libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-
| free vulnerability in the sftp_open() function in src/sftp.c that
| allows a malicious SSH server to corrupt the heap of any
| authenticated client opening an SFTP session. When a server responds
| to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response
| data buffer is freed, and if a subsequent sftp_packet_require() call
| returns a specific error such as
| LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a
| second time, enabling tcache dup conditions on glibc systems that
| allow overlapping allocations and function pointer overwrites.


CVE-2026-66033[1]:
| libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-
| authentication integer underflow vulnerability in the
| ssh2_cipher_crypt() function in src/openssl.c that allows a
| malicious SSH server to crash any connecting client by negotiating
| AES-GCM ciphers during handshake. Attackers can exploit the
| underflow in the expression computing blocksize minus aadlen minus
| authentication tag length to trigger an out-of-bounds read and a
| memcpy call with a near-SIZE_MAX length argument, causing immediate
| process crash before any authentication occurs.


CVE-2026-66034[2]:
| libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing
| bounds check vulnerability that allows a malicious SSH server to
| trigger an arbitrary-length heap out-of-bounds read and a free of an
| uninitialized pointer via the publickey subsystem. In
| libssh2_publickey_list_fetch(), the version 1 response parser reads
| a server-controlled comment_len value and advances the parse pointer
| without verifying sufficient bytes remain in the buffer, causing the
| out-of-bounds read to leak heap pointers from adjacent allocations
| defeating ASLR, followed by heap allocator state corruption when the
| error cleanup path frees an uninitialized pointer from a non-zeroed
| realloc() region.


CVE-2026-66035[3]:
| libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-
| authentication heap buffer overflow vulnerability that allows a
| malicious SSH server to corrupt heap metadata in any connecting
| client by sending a packet with a packet_length smaller than the
| cipher's block size during Encrypt-then-MAC cipher negotiation. In
| the fullpacket() function in src/transport.c, the ETM path allocates
| a buffer of packet_length bytes but copies blocksize minus one bytes
| via memcpy, causing an overflow that on 32-bit glibc writes
| attacker-controlled bytes into an adjacent chunk's SIZE field,
| enabling tcache bin confusion, overlapping live objects, and
| function pointer overwrite during the session handshake before
| authentication.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66032
    https://www.cve.org/CVERecord?id=CVE-2026-66032
[1] https://security-tracker.debian.org/tracker/CVE-2026-66033
    https://www.cve.org/CVERecord?id=CVE-2026-66033
[2] https://security-tracker.debian.org/tracker/CVE-2026-66034
    https://www.cve.org/CVERecord?id=CVE-2026-66034
[3] https://security-tracker.debian.org/tracker/CVE-2026-66035
    https://www.cve.org/CVERecord?id=CVE-2026-66035

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.