CVE Tracker

CVE-2026-0966 @ Saiph

Status
new
Priority
0.73
Match score
4.0
Risk
DoS Remote
CVSS
8.2 HIGH
Reason
cpe: libssh; pkgs: libssh-gcrypt-4; version: in-range: libssh-gcrypt-4-0.8.7-1+deb10u2; risk:dos
Created
2026-08-22T10:15:32Z
Updated
2026-08-22T10:15:32Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
libssh-gcrypt-4-0.8.7-1+deb10u2
libssh-gcrypt-4
libssh

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: libssh-gcrypt · libssh · libssh-gcrypt-4

SystemMatchesTicket for CVE-2026-0966
Saiph libssh-gcrypt-4 0.8.7-1+deb10u2; libssh2-1 1.8.0-2.1+deb10u1 new open
Archive libssh2-1 1.8.0-2.1+deb10u1 none
Bullseye libssh2-1 1.9.0-2+deb11u1 none
Helios libssh2-1 1.9.0-2+deb11u1 none
Janus libssh2-1 1.8.0-2.1+deb10u1 none
Library libssh2-1 1.7.0-1+deb9u2 none
Matrix libssh2-1 1.10.0-3+b1 none
Silk alt-libssh2 1.11.1-1.6; libssh2-1 1.10.0-3+b1 none
morris alt-libssh2 1.8.0; alt-libssh211 1.11.1; libssh2 1.8.0; libssh2-devel 1.8.0 none
mufasa alt-libssh2 1.8.0; alt-libssh211 1.11.1; libssh2 1.8.0 none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-66032 8.8 Helios, morris, mufasa accepted_risk libssh
CVE-2026-59851 8.8 Saiph not_applicable libssh-gcrypt
CVE-2026-66033 7.5 Helios, morris, mufasa accepted_risk libssh
CVE-2026-66034 7.5 Helios, morris, mufasa accepted_risk, not_applicable libssh → CVE-2026-66033
CVE-2026-66035 7.5 morris, mufasa not_applicable libssh → CVE-2026-66033
CVE-2025-5318 5.4 Saiph accepted_risk libssh-gcrypt

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
Debian GNU/Linux 10 (buster) (10) · debian
Arch
x86_64
kernel_release
uname -r → 4.19.0-27-amd64
kernel_version
uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Description

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.

Update status

Add note only

References

NVD: CVE-2026-0966