SUSE-SU-2026:23245-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202623245-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23245-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:23245-1
Upstream
CVE (8)
Related
Published
2026-08-19T10:47:36Z
Modified
2026-08-27T18:23:27Z
Summary
Security update for libssh2_org
Details

This update for libssh2_org fixes the following issues:

Security issues fixed:

  • CVE-2025-15661: out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c (bsc#1268546).
  • CVE-2026-7598: integer overflow in function userauth_password of file src/userauth.c (bsc#1263890).
  • CVE-2026-58050: heap buffer overflow due to missing bounds check in attribute count of publickey-subsystem response (bsc#1269568).
  • CVE-2026-58051: uninitialized pointer freed when malformed responses are sent by an SSH server (bsc#1269567).
  • CVE-2026-66032: arbitrary code execution via double-free in SFTP session (bsc#1272737).
  • CVE-2026-66033: denial of service via integer underflow in AES-GCM cipher negotiation (bsc#1272736).
  • CVE-2026-66034: information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735).
  • CVE-2026-66035: arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734).

Other updates and bugfixes:

  • Fix an issue with Encrypt-then-MAC family (bsc#1221622).
    • Test the ETM feature in the remote end's configuration when receiving data. Upstream issue: #1331.
  • Always add the KEX pseudo-methods ext-info-c and kex-strict-c-v00@openssh.com when configuring custom method list (bsc#1218971).
    • The strict-kex extension is announced in the list of available KEX methods. However, when the default KEX method list is modified or replaced, the extension is not added back automatically.
References

Affected packages

SUSE:Linux Micro 6.0 / libssh2_org

Package

Name
libssh2_org
Purl
pkg:rpm/suse/libssh2_org&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.11.0-4.1

Ecosystem specific

{
    "binaries":  [
        {
            "libssh2-1":  "1.11.0-4.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23245-1.json"