[ GLSA 202608-17 ] libssh2: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178718855663.1.9052676101148070053@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-17
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: libssh2: Multiple Vulnerabilities
     Date: August 20, 2026
     Bugs: #977961
       ID: 202608-17

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in libssh2, the worst of which
could result in remote code execution.

Background
==========

libssh2 is a library implementing the SSH2 protocol.

Affected packages
=================

Package           Vulnerable    Unaffected
----------------  ------------  ------------
net-libs/libssh2  < 1.11.1-r2   >= 1.11.1-r2

Description
===========

Multiple vulnerabilities have been discovered in libssh2. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All libssh2 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=net-libs/libssh2-1.11.1-r2"

References
==========

[ 1 ] CVE-2025-15661
      https://nvd.nist.gov/vuln/detail/CVE-2025-15661
[ 2 ] CVE-2026-7598
      https://nvd.nist.gov/vuln/detail/CVE-2026-7598
[ 3 ] CVE-2026-55199
      https://nvd.nist.gov/vuln/detail/CVE-2026-55199
[ 4 ] CVE-2026-55200
      https://nvd.nist.gov/vuln/detail/CVE-2026-55200

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-17

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqGVUwbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZFWAP/0ZGzpH33oBHpz+FDsFW
RPQOAEfvFbyuMtdOEoxa9ynXMf8mdVbwKEfHJNEaa2QSR0QrCbt5LzN/9u2ZkFKQ
VXxhkr9yiiToc9uTGUvzWEk+hjLdAnjB6rdjrRhRVpHax36E6QLtbmPnNXZjYhvJ
6ws2XmgsECw33AF7AtRn8rtO8tWKqmpUJ/Op3eY2seMIfiAMIPjoPHz3oATEYMN4
Jg1O3D4Nk2dXuyBzaQmEKfhy2J0dw6aGJPuw6Jfx/wifu+p55Uq17WFBm/eOBzZl
jwXXp6nt6lfhYaIhOkyX8gNqYIWhVOxJX5WQJZWHxRYVnthSxLm4QYwrdG/0IMTG
6Jko/3ECW2lnGtmLFqiwke5t/RvH/AL+tAqyV56zZdGkbdmkD0R3wPMTQG+2UyHk
aWy7GhpRcCSBbr3qHW8GFre+GQf2X0HFVLF6U2FITjxsE01uHDvcSBWw16BN6E2z
68kKwVq4Ymrl5hQbeNf0tUDJ9Bvr3G4KJW1PqCcR0ijGpmlV03JZ1zUAeIR3x6Ga
63PhqM3y9RtxMHOLXT7v48h14YPdve+NN8h6R0e9KL2wec1nZRvxUlOMxX71YJJ4
HVCw/WLeeG9pOxmlgSn2yEE0lNtfx0me+R5ux1xM7TsRgP5V9eW9MWOwgU/Caohc
o2cDuD9zdvx/V6OG7bJTFp2l
=934k
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.