Aller au contenu

Fiche vulnérabilité

CVE-2026-15370 : faille élevée libssh libssh (CVSS 7.3)

Description

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

En bref

Sévérité
Élevée (CVSS 7.3)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
21 juil. 2026
Dernière mise à jour
22 sept. 2026

Produits concernés

  • libssh libssh
  • redhat hardened images
  • redhat enterprise linux
  • redhat enterprise linux for els
  • redhat enterprise linux for eus
  • redhat enterprise linux for ibm z systems
  • redhat enterprise linux for ibm z systems els
  • redhat enterprise linux for ibm z systems eus
  • redhat enterprise linux for power little endian
  • redhat enterprise linux for power little endian els
  • redhat enterprise linux for power little endian eus

Références

Rechercher une autre vulnérabilité dans la base CVE