ZeroHour

CVE-2026-15370

CVSS 3.1
7.3 high
EPSS
<1%p5
Published
()
Modified
Description

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

Vendors
libsshredhat
Products
libssh, hardened images, enterprise linux
Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.