CVE-2026-66034 @ Helios
Status
accepted_risk
Priority
1.12
Match score
4.0
Risk
InfoLeak
MemCorrupt
CVSS
7.5 HIGH
Reason
cpe: libssh2; pkgs: libssh2-1; version: in-range: libssh2-1-1.9.0-2+deb11u1; debian:bullseye libssh2 open; risk:info_disclosure
Created
2026-08-03T02:34:45Z
Updated
2026-08-22T10:16:55Z
Closed
2026-08-03T02:48:16Z
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| libssh2-1-1.9.0-2+deb11u1 | |
| libssh2-1 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: libssh2 · libssh2-1
| System | Matches | Ticket for CVE-2026-66034 | |
|---|---|---|---|
| Helios | libssh2-1 1.9.0-2+deb11u1 | accepted_risk open | |
| Archive | libssh2-1 1.8.0-2.1+deb10u1 | none | |
| Bullseye | libssh2-1 1.9.0-2+deb11u1 | none | |
| Janus | libssh2-1 1.8.0-2.1+deb10u1 | none | |
| Library | libssh2-1 1.7.0-1+deb9u2 | none | |
| Matrix | libssh2-1 1.10.0-3+b1 | none | |
| Saiph | libssh2-1 1.8.0-2.1+deb10u1 | none | |
| Silk | libssh2-1 1.10.0-3+b1 | none |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-66032 | 8.8 | Helios, morris, mufasa | accepted_risk | libssh2 | — | ||
| CVE-2026-66033 | 7.5 | Helios, morris, mufasa | accepted_risk | libssh2 | — | ||
| CVE-2026-66035 | 7.5 | morris, mufasa | not_applicable | libssh2 | → CVE-2026-66033 |
Related CVE (same fix)
This CVE is subordinated to primary CVE-2026-66033 — same product as CVE-2026-66033
Host OS / kernel
OS
Debian GNU/Linux 11 (bullseye)
(11)
· debian
Arch
aarch64
kernel_release
uname -r → 6.1.21-v8+kernel_version
uname -v → #1642 SMP PREEMPT Mon Apr 3 17:24:16 BST 2023For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | not_applicable | 7.5 | 2026-08-22T10:16:55Z | Open |
| mufasa | not_applicable | 7.5 | 2026-08-22T10:16:55Z | Open |
Description
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.
Update status
Add note only
References
- https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9
- https://github.com/libssh2/libssh2/pull/2202
- https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem
NVD: CVE-2026-66034