VDB

GCVE-110-MAGEIA-2026-273

GCVE-110-MAGEIA-2026-273
Advisory Published
Vulnetix · Advisory published July 20, 2026
The updated packages fix security vulnerabilities: Heap Buffer Over-read via sftp_symlink() in sftp.c. (CVE-2025-15661) libssh2 userauth.c userauth_password integer overflow. (CVE-2026-7598) Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler. (CVE-2026-55199) Out-of-Bounds Write via Unchecked packet_length in transport.c. (CVE-2026-55200) Integer Overflow in publickey Subsystem Attribute Allocation. (CVE-2026-58050) Free of Uninitialized Pointer in publickey List Cleanup. (CVE-2026-58051)

Affected Products

VendorProductVersionsPlatforms
Mageialibssh20 (affected), 1.11.1-2.1.mga10 (unaffected)
Mageialibssh20 (affected), 1.11.0-1.1.mga9 (unaffected)

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›