Back to CVE List

CVE-2026-15370

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.7 / 10
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Vulnerability Description

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-121
Source
NVD
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images

External References

Discussion (0)

Add Comment

No comments yet. Be the first!