Information on source package libssh

Available versions

ReleaseVersion
bullseye0.9.8-0+deb11u1
bullseye (security)0.9.8-0+deb11u2
bookworm0.10.6-0+deb12u2
bookworm (security)0.10.6-0+deb12u1
trixie0.11.2-1+deb13u1
forky0.11.3-1
sid0.11.3-1

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-0968vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableDenial of Service due to malformed SFTP message
CVE-2026-0967vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableDenial of Service via inefficient regular expression processing
CVE-2026-0966vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableBuffer underflow in ssh_get_hexa() on invalid input
CVE-2026-0965vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableDenial of Service via improper configuration file handling
CVE-2026-0964vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableImproper sanitation of paths received from SCP servers

Resolved issues

BugDescription
CVE-2025-14821Insecure default configuration leads to local man-in-the-middle attacks on Windows
CVE-2025-8277A flaw was found in libssh's handling of key exchange (KEX) processes ...
CVE-2025-8114A flaw was found in libssh, a library that implements the SSH protocol ...
CVE-2025-5987A flaw was found in libssh when using the ChaCha20 cipher with the Ope ...
CVE-2025-5449A flaw was found in the SFTP server message decoding logic of libssh. ...
CVE-2025-5372A flaw was found in libssh versions built with OpenSSL versions older ...
CVE-2025-5351A flaw was found in the key export functionality of libssh. The issue ...
CVE-2025-5318A flaw was found in the libssh library in versions less than 0.11.2. A ...
CVE-2025-4878A vulnerability was found in libssh, where an uninitialized variable e ...
CVE-2025-4877There's a vulnerability in the libssh package where when a libssh cons ...
CVE-2023-48795The SSH transport protocol with certain OpenSSH extensions, found in O ...
CVE-2023-6918A flaw was found in the libssh implements abstract layer for message d ...
CVE-2023-6004A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump ...
CVE-2023-3603A missing allocation check in sftp server processing read requests may ...
CVE-2023-2283A vulnerability was found in libssh, where the authentication check of ...
CVE-2023-1667A NULL pointer dereference was found In libssh during re-keying with a ...
CVE-2021-3634A flaw has been found in libssh in versions prior to 0.9.6. The SSH pr ...
CVE-2020-16135libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buf ...
CVE-2020-1730A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in t ...
CVE-2019-14889A flaw was found with the libssh API function ssh_scp_new() in version ...
CVE-2018-10933A vulnerability was found in libssh's server-side state machine before ...
CVE-2016-0739libssh before 0.7.3 improperly truncates ephemeral secrets generated f ...
CVE-2015-3146The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in ...
CVE-2014-8132Double free vulnerability in the ssh_packet_kexinit function in kex.c ...
CVE-2014-0017The RAND_bytes function in libssh before 0.6.3, when forking is enable ...
CVE-2013-0176The publickey_from_privatekey function in libssh before 0.5.4, when no ...
CVE-2012-6063Double free vulnerability in the sftp_mkdir function in sftp.c in libs ...
CVE-2012-4562Multiple integer overflows in libssh before 0.5.3 allow remote attacke ...
CVE-2012-4561The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from ...
CVE-2012-4560Multiple buffer overflows in libssh before 0.5.3 allow remote attacker ...
CVE-2012-4559Multiple double free vulnerabilities in the (1) agent_sign_data functi ...

Security announcements

DSA / DLADescription
DLA-4385-1libssh - security update
DSA-5591-1libssh - security update
DLA-3437-1libssh - security update
DSA-5409-1libssh - security update
DSA-4965-1libssh - security update
DLA-2303-1libssh - security update
DLA-2038-1libssh - security update
DLA-1548-1libssh - security update
DSA-4322-1libssh - security update
DSA-3488-1libssh - security update
DLA-425-1libssh - security update
DSA-2879-1libssh - security update
DSA-2577-1libssh - several

Search for package or bug name: Reporting problems