CVE-2026-15370

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libssh:libssh:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

30 Jul 2026, 13:13

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:libssh:libssh:-:*:*:*:*:*:*:*
First Time Libssh libssh
Redhat enterprise Linux
Redhat hardened Images
Redhat
Libssh
References () https://access.redhat.com/errata/RHSA-2026:47768 - () https://access.redhat.com/errata/RHSA-2026:47768 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2026-15370 - () https://access.redhat.com/security/cve/CVE-2026-15370 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2499049 - () https://bugzilla.redhat.com/show_bug.cgi?id=2499049 - Issue Tracking, Vendor Advisory

30 Jul 2026, 09:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:47768 -

21 Jul 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 09:16

Updated : 2026-07-30 13:13


NVD link : CVE-2026-15370

Mitre link : CVE-2026-15370

CVE.ORG link : CVE-2026-15370


JSON object : View

Products Affected

redhat

  • hardened_images
  • enterprise_linux

libssh

  • libssh
CWE
CWE-121

Stack-based Buffer Overflow