CVE-2026-59842: Libssh
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.
Affected products
- Libssh Libssh: version 0.12.0 only
- Red Hat Enterprise Linux: version 10.0 only; version 10.2 only
- Red Hat Enterprise Linux For Els: version 10.2 only
- Red Hat Enterprise Linux For Eus: version 10.2 only
- Red Hat Enterprise Linux For IBM Z Systems: version 10.0 only; version 10.2 only
- Red Hat Enterprise Linux For IBM Z Systems Els: version 10.2 only
- Red Hat Enterprise Linux For IBM Z Systems Eus: version 10.2 only
- Red Hat Enterprise Linux For Power Little Endian: version 10.0 only; version 10.2 only
- Red Hat Enterprise Linux For Power Little Endian Els: version 10.2 only
- Red Hat Enterprise Linux For Power Little Endian Eus: version 10.2 only
- Red Hat Hardened Images: affected versions not specified
Published 2026-07-21. Last modified 2026-09-22.