REDHAT-BUG-2436982
Published Feb 4, 2026
·Updated
A malicious SFTP server can send malformed longname field of the `SSH_FXP_NAME` message (file listing). Due to the missing NULL check, the libssh could read beyond the buffer bounds on heap, causing unexpected behavior or crashes.
Affected Software
1 affected component
libssh libssh
Event History
Feb 4, 2026
Data Sourced
via Red Hat·11:48 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2436982?
The severity of REDHAT-BUG-2436982 is considered critical due to potential remote code execution or crashes.
2
How do I fix REDHAT-BUG-2436982?
To fix REDHAT-BUG-2436982, update your libssh library to the latest patched version.
3
What causes the vulnerability REDHAT-BUG-2436982?
REDHAT-BUG-2436982 is caused by a malformed longname field from a malicious SFTP server leading to buffer over-read.
4
Who is affected by REDHAT-BUG-2436982?
Users of the libssh library are affected by REDHAT-BUG-2436982.
5
Is there a workaround for REDHAT-BUG-2436982?
There is no official workaround for REDHAT-BUG-2436982; applying the update is the recommended action.