VDB
GCVE-110-MAGEIA-2026-273
GCVE-110-MAGEIA-2026-273
Advisory Published
The updated packages fix security vulnerabilities:
Heap Buffer Over-read via sftp_symlink() in sftp.c. (CVE-2025-15661)
libssh2 userauth.c userauth_password integer overflow. (CVE-2026-7598)
Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler. (CVE-2026-55199)
Out-of-Bounds Write via Unchecked packet_length in transport.c.
(CVE-2026-55200)
Integer Overflow in publickey Subsystem Attribute Allocation.
(CVE-2026-58050)
Free of Uninitialized Pointer in publickey List Cleanup.
(CVE-2026-58051)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | libssh2 | 0 (affected), 1.11.1-2.1.mga10 (unaffected) | — |
| Mageia | libssh2 | 0 (affected), 1.11.0-1.1.mga9 (unaffected) | — |
References
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.