A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:18160 | |
| https://access.redhat.com/errata/RHSA-2026:18683 | |
| https://access.redhat.com/errata/RHSA-2026:7067 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-0966 | Mitigation Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2433121 | Issue Tracking Vendor Advisory |
| https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ | Release Notes |
Configurations
Configuration 1 (hide)
|
History
19 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
11 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process. |
30 Apr 2026, 16:29
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
|
| First Time |
Redhat
Redhat enterprise Linux Libssh Libssh libssh Redhat hardened Images Redhat openshift Container Platform |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
| References | () https://access.redhat.com/errata/RHSA-2026:7067 - Vendor Advisory | |
| References | () https://access.redhat.com/security/cve/CVE-2026-0966 - Mitigation, Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2433121 - Issue Tracking, Vendor Advisory | |
| References | () https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ - Release Notes |
24 Apr 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Mar 2026, 13:26
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
26 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
26 Mar 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-26 21:17
Updated : 2026-05-19 14:16
NVD link : CVE-2026-0966
Mitre link : CVE-2026-0966
CVE.ORG link : CVE-2026-0966
JSON object : View
Products Affected
redhat
- hardened_images
- openshift_container_platform
- enterprise_linux
libssh
- libssh
CWE
CWE-124
Buffer Underwrite ('Buffer Underflow')
