libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
Published Jul 24, 2026
7.7
HIGHCVSS 4.0
EPSS 0.55%
Description
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.
Affected products
-
- Version 0StatusaffectedConstraints<=1.11.1
- Version
-
- Version StatusunaffectedConstraints-
- Version
No data.
Red Hat Hardened Images
libssh2-main-1.11.1-10.3.hum1
Fixed · RHSA-2026:46955
Red Hat Enterprise Linux 6
libssh2
Out of support scope
Red Hat Enterprise Linux 7
libssh2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | libssh2-main-1.11.1-10.3.hum1 | Fixed | RHSA-2026:46955 |
| Red Hat Enterprise Linux 6 | libssh2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libssh2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact flaw in libssh2 allows a malicious SSH server to trigger a pre-authentication heap buffer overflow on a connecting client. During Encrypt-then-MAC (ETM) cipher negotiation, a specially crafted packet can corrupt heap memory, potentially leading to arbitrary code execution. Exploitation requires a client to connect to a compromised server, limiting the attack surface.
Red Hat mitigation
To reduce exposure, restrict SSH client connections to only trusted and verified SSH servers. Avoid initiating SSH connections to unknown or unverified hosts, as successful exploitation requires the client to connect to a malicious server.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jul 24, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.55% (0.00551) | 44.03th | v5 (v2026.06.15) |
| Jul 25, 2026 | 0.32% (0.00320) | 24.38th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-66035 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2506851 Issue Tracking
- https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4 patch
- https://github.com/libssh2/libssh2/pull/2198 issue-trackingpatchIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-66035
- https://www.cve.org/CVERecord?id=CVE-2026-66035
- https://www.vulncheck.com/advisories/libssh2-heap-buffer-overflow-via-etm-cipher-negotiation third-party-advisoryPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-66035 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2506851 | Issue Tracking | |
| https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4 | patch | |
| https://github.com/libssh2/libssh2/pull/2198 | issue-trackingpatchIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-66035 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-66035 | ||
| https://www.vulncheck.com/advisories/libssh2-heap-buffer-overflow-via-etm-cipher-negotiation | third-party-advisoryPatchThird Party Advisory |
Change history (0)
No recorded changes yet.