Description
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the libssh library allows an authenticated remote peer to advertise a zero maximum packet size during an SSH channel open request. The server subsequently enters an infinite loop when writing to that channel, consuming CPU resources until the process is terminated. This results in a denial of service that reduces the availability of the host system. The weakness maps to CWE‑400: Uncontrolled Resource Consumption.

Affected Systems

The vulnerability is present in Red Hat Enterprise Linux 10, 8, and 9, as well as Red Hat Hardened Images that ship the libssh component (Hummingbird). Any system running the affected package versions is impacted.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of less than 1% points to a low probability of exploitation in the wild. The attack path requires an authenticated SSH session, meaning the attacker must have valid credentials or have already compromised the target. No workaround is available, and the issue is not listed in CISA KEV, so the recommended response is to apply the vendor update promptly.

Generated by OpenCVE AI on July 30, 2026 at 17:55 UTC.

Remediation

Vendor Workaround

No workaround available.


OpenCVE Recommended Actions

  • Install the Red Hat security update RHSA‑2026:42922 on all affected RHEL 8, 9, and 10 installations and Hardened Images to patch the libssh library.
  • Restart the SSH service or reboot the system to ensure the patched library is loaded into memory.
  • Monitor CPU usage and SSH audit logs for abnormal channel open attempts or sustained high CPU consumption, and investigate any anomalies immediately.

Generated by OpenCVE AI on July 30, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6410-1 libssh security update
History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Libssh
Libssh libssh
Redhat hardened Images
Vendors & Products Libssh
Libssh libssh
Redhat hardened Images

Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
References

Wed, 22 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Title Libssh: libssh: denial of service via zero advertised channel packet size
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Libssh Libssh
Redhat Enterprise Linux Hardened Images Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-22T19:07:08.289Z

Reserved: 2026-07-07T15:40:24.561Z

Link: CVE-2026-59843

cve-icon Vulnrichment

Updated: 2026-07-21T12:05:43.803Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T11:07:00Z

Links: CVE-2026-59843 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:00:15Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption