Impact
A stack buffer overflow occurs during SFTP directory listing when libssh constructs the longname field with unsafe concatenation into a fixed-size stack buffer. When a client forces the server to list attacker-controlled filenames that are sufficiently long, the buffer can overflow, leading to server crashes or potential execution of arbitrary code on the host.
Affected Systems
Red Hat Enterprise Linux 8, 9, 10 and Red Hat Hardened Images, all of which ship the vulnerable libssh component. Any system running the SFTP server on these platforms is affected.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, and the EPSS score of less than 1% reflects a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote SFTP client that supplies oversized filenames during a directory listing. Exploitation would require network access to the SFTP service and could result in a crash or, in the worst case, remote code execution on the server.
OpenCVE Enrichment
Debian DSA