Back

MEDIUM

libssh2 userauth.c userauth_password integer overflow

Published May 1, 2026

Description

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.

Affected products

Remediation

Red Hat statement

To exploit this flaw, an attacker needs to be able to supply an excessively large value to the arguments of the `userauth_password` function, typically to an application processing untrusted SSH authentication requests. The primary security impact of this issue is a crash to the application linked to the library due to memory corruption, potentially allowing arbitrary code execution. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to these reasons, this vulnerability has been rated with an important severity.

Red Hat mitigation

To mitigate this flaw, applications linked to the libssh2 library should be configured or updated to exclusively use public key authentication. Explicitly disabling password-based logins prevents the application from executing the vulnerable userauth_password function.

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published May 1, 2026
Updated Sep 1, 2026
Reserved May 1, 2026

CISA Vulnrichment

Updated May 4, 2026

NVD

Status Modified
Modified Sep 1, 2026

Red Hat

Severity Important
Public date May 1, 2026
Bugzilla 2464597

ENISA EUVD

Assigner VulDB
Published May 1, 2026
Updated Sep 1, 2026

GitHub

No data