CVE Tracker

CVE-2026-66034 @ morris

Status
not_applicable
Priority
7.5
Match score
4.0
Risk
InfoLeak MemCorrupt
CVSS
7.5 HIGH
Reason
cpe: libssh2; pkgs: libssh2, libssh2-devel; version: in-range: libssh2-1.8.0-4.el7_9.1.tuxcare.els3, libssh2-devel-1.8.0-4.el7_9.1.tuxcare.els3; risk:info_disclosure
Created
2026-08-02T19:35:07Z
Updated
2026-08-22T10:16:55Z
Closed
2026-08-02T20:43:35Z

Package interrogation (copy)

Run on the host — click to copy a command. RPM

PackageCommands
libssh2-1.8.0-4.el7_9.1.tuxcare.els3
libssh2-devel-1.8.0-4.el7_9.1.tuxcare.els3

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: libssh2 · libssh2-devel

SystemMatchesTicket for CVE-2026-66034
Helios libssh2-1 1.9.0-2+deb11u1 accepted_risk open
morris alt-libssh2 1.8.0; alt-libssh211 1.11.1; libssh2 1.8.0; libssh2-devel 1.8.0 not_applicable open
mufasa alt-libssh2 1.8.0; alt-libssh211 1.11.1; libssh2 1.8.0 not_applicable open
Archive libssh2-1 1.8.0-2.1+deb10u1 none
Bullseye libssh2-1 1.9.0-2+deb11u1 none
Janus libssh2-1 1.8.0-2.1+deb10u1 none
Library libssh2-1 1.7.0-1+deb9u2 none
Matrix libssh2-1 1.10.0-3+b1 none
Saiph libssh2-1 1.8.0-2.1+deb10u1 none
Silk alt-libssh2 1.11.1-1.6; libssh2-1 1.10.0-3+b1 none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-66032 8.8 Helios, morris, mufasa accepted_risk libssh2
CVE-2026-66033 7.5 Helios, morris, mufasa accepted_risk libssh2
CVE-2026-66035 7.5 morris, mufasa not_applicable libssh2 → CVE-2026-66033

Related CVE (same fix)

This CVE is subordinated to primary CVE-2026-66033 — same product as CVE-2026-66033

Host OS / kernel

OS
CloudLinux release 7.9 (Boris Yegorov) (7.9) · cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64
kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
mufasa not_applicable 7.5 2026-08-22T10:16:55Z Open
Helios accepted_risk 1.12 2026-08-22T10:16:55Z Open

Description

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.

Determination

Related to primary CVE-2026-66033: same product as CVE-2026-66033

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-02T20:43:35Z — not_applicable
Related to primary CVE-2026-66033: same product as CVE-2026-66033

References

NVD: CVE-2026-66034