CVE-2020-1730: Canonical Ubuntu Linux
Medium severity, CVSS 5.3. EPSS: 3.1% chance of exploitation in the next 30 days.
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 19.10 only
- Fedoraproject Fedora: version 31 only; version 32 only
- Libssh Libssh: from 0.8.0, before 0.8.9 (fixed in 0.8.9); from 0.9.0, before 0.9.4 (fixed in 0.9.4)
- Netapp Cloud Backup: affected versions not specified
- Oracle MySQL Workbench: up to and including 8.0.21
- Red Hat Enterprise Linux: version 8.0 only
Published 2020-04-13. Last modified 2026-06-17.