Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
No workaround available.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6410-1 | libssh security update |
Ubuntu USN |
USN-8699-1 | libssh vulnerabilities |
Tue, 22 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat enterprise Linux For Els
Redhat enterprise Linux For Eus Redhat enterprise Linux For Ibm Z Systems Redhat enterprise Linux For Ibm Z Systems Els Redhat enterprise Linux For Ibm Z Systems Eus Redhat enterprise Linux For Power Little Endian Redhat enterprise Linux For Power Little Endian Els Redhat enterprise Linux For Power Little Endian Eus |
|
| CPEs | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* cpe:2.3:a:libssh:libssh:0.12.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_els:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux_for_els:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_eus:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux_for_eus:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_els:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_els:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:10.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Redhat enterprise Linux For Els
Redhat enterprise Linux For Eus Redhat enterprise Linux For Ibm Z Systems Redhat enterprise Linux For Ibm Z Systems Els Redhat enterprise Linux For Ibm Z Systems Eus Redhat enterprise Linux For Power Little Endian Redhat enterprise Linux For Power Little Endian Els Redhat enterprise Linux For Power Little Endian Eus |
Mon, 17 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:10.2 | |
| References |
|
Thu, 30 Jul 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libssh
Libssh libssh Redhat hardened Images |
|
| Vendors & Products |
Libssh
Libssh libssh Redhat hardened Images |
Wed, 22 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 21 Jul 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server. | |
| Title | Libssh: libssh: stack buffer overflow in sftp server longname construction | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-17T21:54:00.734Z
Reserved: 2026-07-10T08:14:26.583Z
Link: CVE-2026-15370
Updated: 2026-07-22T17:49:21.197Z
Status : Analyzed
Published: 2026-07-21T09:16:53.683
Modified: 2026-09-22T19:47:33.437
Link: CVE-2026-15370
OpenCVE Enrichment
Updated: 2026-07-30T18:00:15Z
-
CWE-121
Stack-based Buffer Overflow
Debian DSA
Ubuntu USN