CVE-2026-55200

NameCVE-2026-55200
Descriptionlibssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6365-1
Debian Bugs1140401

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libssh2 (PTS)bullseye1.9.0-2+deb11u1vulnerable
bookworm1.10.0-3vulnerable
trixie1.11.1-1vulnerable
trixie (security)1.11.1-1+deb13u1fixed
forky1.11.1-3vulnerable
sid1.11.1-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libssh2sourcetrixie1.11.1-1+deb13u1DSA-6365-1
libssh2source(unstable)1.11.1-41140401

Notes

https://github.com/libssh2/libssh2/pull/2052
Fixed by: https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8

Search for package or bug name: Reporting problems