VDB
RHSA-2026%3A0996
RHSA-2026%3A0996
PUBLISHED
CVSS 8.100000381469727 HIGH
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhcos-ppc64le-414.92.202601191325-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-ppc64le-414.92.202601191325-0, rhcos-ppc64le-414.92.202601191325-0, rhcos-ppc64le-414.92.202601191325-0 |
| Red Hat | rhcos-aarch64-414.92.202601191325-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-aarch64-414.92.202601191325-0 |
| Red Hat | rhcos-x86_64-414.92.202601191325-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-x86_64-414.92.202601191325-0, rhcos-x86_64-414.92.202601191325-0, * |
| Red Hat | rhcos-s390x-414.92.202601191325-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-s390x-414.92.202601191325-0, rhcos-s390x-414.92.202601191325-0, rhcos-s390x-414.92.202601191325-0 |
| Red Hat | rhcos-x86_64-414.92.202601191325-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-x86_64-414.92.202601191325-0 |
| Red Hat | rhcos-s390x-414.92.202601191325-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-s390x-414.92.202601191325-0 |
| Red Hat | rhcos-ppc64le-414.92.202601191325-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-ppc64le-414.92.202601191325-0 |
| Red Hat | rhcos-aarch64-414.92.202601191325-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-aarch64-414.92.202601191325-0, rhcos-aarch64-414.92.202601191325-0, rhcos-aarch64-414.92.202601191325-0 |
Timeline
- Jan 30, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 11, 2026 CVE Updated
- May 11, 2026 Security Advisory
- May 11, 2026 Security Advisory
- May 11, 2026 Security Advisory
- May 11, 2026 Security Advisory
- May 11, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:0996 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2376219 issue
- https://www.libssh.org/security/advisories/CVE-2025-5987.txt advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-8677 advisory
- https://access.redhat.com/security/cve/CVE-2025-40778 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-40778 advisory
- https://access.redhat.com/security/cve/CVE-2025-40780 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-40780 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2392605 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2405827 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2405830 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0996.json advisory
- https://www.cve.org/CVERecord?id=CVE-2025-5987 advisory
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/677a42645ef22b5a50741bad5facf9d8a8bc6d21 advisory
- https://www.mozilla.org/security/advisories/mfsa2026-22/#CVE-2025-59375 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2405829 issue
- https://access.redhat.com/security/cve/CVE-2025-5987 advisory
- https://access.redhat.com/security/cve/CVE-2025-8677 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-8677 advisory
…and 12 more