CVE-2026-15370
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.
Weakness
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.
Affected products
- libssh libssh
- redhat hardened_images
- redhat enterprise_linux
- redhat enterprise_linux_for_els
- redhat enterprise_linux_for_eus
- redhat enterprise_linux_for_ibm_z_systems
- redhat enterprise_linux_for_ibm_z_systems_els
- redhat enterprise_linux_for_ibm_z_systems_eus
References
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.