Release date:
2026-08-18 12:38:09 UTC
Description:
- CVE-2025-4878: initialize pointers and properly check the return value
of ssh_pki_import_privkey_file() in privatekey_from_file(), so a missing
key file no longer leaves an uninitialized key in use
- CVE-2026-59846: validate usernames and reject shell metacharacters before
they are expanded into a shell-evaluated ProxyCommand
Updated packages:
-
libssh-0.10.4-8.el9_2.tuxcare.els15.i686.rpm
sha:bf4b5cd044523b78f799c8002aa59424b6b6e7386419b6c97c5913bab50f1ea6
-
libssh-0.10.4-8.el9_2.tuxcare.els15.x86_64.rpm
sha:88faee6620a17c30549eb2d9d499e2f5fc8eea0da62a30727c5767928d6c50ff
-
libssh-config-0.10.4-8.el9_2.tuxcare.els15.noarch.rpm
sha:4d400d8d9c4f865ba803e683c8a73f1a5168c6f70bdaba8300111e692f38b8d8
-
libssh-devel-0.10.4-8.el9_2.tuxcare.els15.i686.rpm
sha:ef82dc84802b7f72653dddfc7c9864ca0ef8871966385fda7e3ec8ed3c566637
-
libssh-devel-0.10.4-8.el9_2.tuxcare.els15.x86_64.rpm
sha:50ef1f4fefe935ffd0dee00c484c4ebbc6c5cebe2b49323a51dd8906e4e7ad31
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.