cve-2026-0966

HIGH CVSS 8.2 nvd
Description

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.

Timeline
Published
2026-03-26
Last Modified
2026-09-01
CVSS Details
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
Affected Products
  • libssh libssh
  • redhat hardened_images
  • redhat openshift_container_platform
  • redhat enterprise_linux
Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 8.2 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H 3.9 4.2 nvd@nist.gov
3.0 6.5 MEDIUM CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H 2.2 4.2 secalert@redhat.com
CPE configurations
OR
CPE Version range Vulnerable
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* < 0.11.4 yes
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* — yes
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* — yes
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* — yes
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* — yes
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* — yes
NVD metadata
NVD status
Modified
Source identifier
secalert@redhat.com
References
Linked Vulnerabilities

{
  "cvss": 8.2,
  "datePublished": "2026-03-26T21:17:00.783",
  "dateUpdated": "2026-09-01T12:17:33.740",
  "description": "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.",
  "id": "CVE-2026-0966",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/o:redhat:enterprise_linux:10.2"
            ],
            "defaultStatus": "affected",
            "packageName": "libssh",
            "product": "Red Hat Enterprise Linux 10",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "0:0.12.0-2.el10",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:enterprise_linux:9::appstream",
              "cpe:/o:redhat:enterprise_linux:9::baseos"
            ],
            "defaultStatus": "affected",
            "packageName": "libssh",
            "product": "Red Hat Enterprise Linux 9",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "0:0.10.4-18.el9",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:enterprise_linux:9::appstream",
              "cpe:/o:redhat:enterprise_linux:9::baseos"
            ],
            "defaultStatus": "affected",
            "packageName": "libssh",
            "product": "Red Hat Enterprise Linux 9",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "0:0.10.4-18.el9",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:hummingbird:1"
            ],
            "defaultStatus": "affected",
            "packageName": "libssh-main",
            "product": "Red Hat Hardened Images",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "0.12.0-1.1.hum1",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/o:redhat:enterprise_linux:6"
            ],
            "defaultStatus": "unaffected",
            "packageName": "libssh2",
            "product": "Red Hat Enterprise Linux 6",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/o:redhat:enterprise_linux:7"
            ],
            "defaultStatus": "unaffected",
            "packageName": "libssh2",
            "product": "Red Hat Enterprise Linux 7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/o:redhat:enterprise_linux:8"
            ],
            "defaultStatus": "affected",
            "packageName": "libssh",
            "product": "Red Hat Enterprise Linux 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:hummingbird:1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "libssh2",
            "product": "Red Hat Hardened Images",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift:4"
            ],
            "defaultStatus": "affected",
            "packageName": "openshift/ose-rhel-coreos-8",
            "product": "Red Hat OpenShift Container Platform 4",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift:4"
            ],
            "defaultStatus": "affected",
            "packageName": "openshift/ose-rhel-coreos-9",
            "product": "Red Hat OpenShift Container Platform 4",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "68C64024-6979-46E1-A57F-5C0228DC8DAD",
                "versionEndExcluding": "0.11.4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "87DEB507-5B64-47D7-9A50-3B87FD1E571F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "932D137F-528B-4526-9A89-CD59FA1AB0FE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F6FB57C-2BC7-487C-96DD-132683AEB35D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process."
      },
      {
        "lang": "es",
        "value": "La función API 'ssh_get_hexa()' es vulnerable cuando se proporciona una entrada de longitud 0 a esta función. Esta función se utiliza internamente en 'ssh_get_fingerprint_hash()' y 'ssh_print_hexa()' (obsoleta), la cual es vulnerable a la misma entrada (la longitud es proporcionada por la aplicación que realiza la llamada).\n\nLa función también se utiliza internamente en el código gssapi para registrar los OID recibidos por el servidor durante la autenticación GSSAPI. Esto podría activarse de forma remota cuando el servidor permite la autenticación GSSAPI y la verbosidad del registro se establece al menos en SSH_LOG_PACKET (3). Esto podría causar un auto-DoS del proceso demonio por conexión."
      }
    ],
    "id": "CVE-2026-0966",
    "lastModified": "2026-09-01T12:17:33.740",
    "metrics": {
      "cvssMetricV30": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.0"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 4.2,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-0966",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-27T19:52:22.819171Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-03-26T21:17:00.783",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:18160"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:18683"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:7067"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-0966"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-124"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  },
  "severity": "HIGH",
  "source": "nvd",
  "title": "A flaw was found in libssh"
}
Enrichment data
View JSON API Download JSON