Back to CVE List

CVE-2026-59842

LOW SEVERITY

CVSS Score & Metrics

Base Score
3.7 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Vulnerability Description

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-125
Source
NVD
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images

External References

Discussion (0)

Add Comment

No comments yet. Be the first!