CVE-2019-3863: Debian Linux
High severity, CVSS 8.8. EPSS: 3.4% chance of exploitation in the next 30 days.
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
Affected products
- Debian Debian Linux: version 8.0 only
- LIBSSH2 LIBSSH2: before 1.8.1 (fixed in 1.8.1)
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Opensuse Leap: version 15.0 only; version 42.3 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Server Tus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2019-03-25. Last modified 2026-06-17.