Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:61752 - Security Advisory
Issued:
2026-08-31
Updated:
2026-08-31

RHSA-2026:61752 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libssh2 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libssh2 is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libssh2 packages provide a library that implements the SSH2 protocol.

Security Fix(es):

  • libssh2: integer overflow via large username or password arguments (CVE-2026-7598)
  • libssh2: libssh2: Heap buffer overflow via integer overflow in publickey attribute allocation (CVE-2026-58050)
  • libssh2: libssh2: Arbitrary code execution via double-free in SFTP session (CVE-2026-66032)
  • libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read (CVE-2026-66034)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2464597 - CVE-2026-7598 libssh2: integer overflow via large username or password arguments
  • BZ - 2493955 - CVE-2026-58050 libssh2: libssh2: Heap buffer overflow via integer overflow in publickey attribute allocation
  • BZ - 2506857 - CVE-2026-66032 libssh2: libssh2: Arbitrary code execution via double-free in SFTP session
  • BZ - 2506860 - CVE-2026-66034 libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read

CVEs

  • CVE-2026-7598
  • CVE-2026-58050
  • CVE-2026-66032
  • CVE-2026-66034

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
libssh2-1.8.0-4.el7_9.2.src.rpm SHA-256: e1e61bcc2c79b646875b5452b528b6b6351250af4e2a3c896a624dc594837216
x86_64
libssh2-1.8.0-4.el7_9.2.i686.rpm SHA-256: 59cd1e5cd26151417587f948c6be7c1420021687298a947b8b4894b4a8090cb4
libssh2-1.8.0-4.el7_9.2.x86_64.rpm SHA-256: 46c6afefcf79e0692161750267e2e8f2084b732f7b520ea5fec2efd0d2264909
libssh2-debuginfo-1.8.0-4.el7_9.2.i686.rpm SHA-256: 7b85fb0460c63ce7d8c6725716dab26695b7989a2d59f583c9ec534db3e20d25
libssh2-debuginfo-1.8.0-4.el7_9.2.i686.rpm SHA-256: 7b85fb0460c63ce7d8c6725716dab26695b7989a2d59f583c9ec534db3e20d25
libssh2-debuginfo-1.8.0-4.el7_9.2.x86_64.rpm SHA-256: b94db91c82081a03be47d2dda51e8e50a89013c1cc9ef1cc65d70e56d6bed890
libssh2-debuginfo-1.8.0-4.el7_9.2.x86_64.rpm SHA-256: b94db91c82081a03be47d2dda51e8e50a89013c1cc9ef1cc65d70e56d6bed890
libssh2-devel-1.8.0-4.el7_9.2.i686.rpm SHA-256: d1217167130217c2247a1b225a6d9ad9233aae03337af2414ee37eb9cd98e53a
libssh2-devel-1.8.0-4.el7_9.2.x86_64.rpm SHA-256: ef5f40e093cd50e2ec54cc56ed19ca625c70eb74ada9a661a2ec6f70ef66da87
libssh2-docs-1.8.0-4.el7_9.2.noarch.rpm SHA-256: ef792e49d34b08227b521fc8ff762281fb88a6f54cb48d5335c53c8ccf44142e

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
libssh2-1.8.0-4.el7_9.2.src.rpm SHA-256: e1e61bcc2c79b646875b5452b528b6b6351250af4e2a3c896a624dc594837216
s390x
libssh2-1.8.0-4.el7_9.2.s390.rpm SHA-256: e3c3e96ca7a76af8e99df34db660ad32fe9063e4644a1b7def3345ef5e718f0b
libssh2-1.8.0-4.el7_9.2.s390x.rpm SHA-256: 4588370a32afd0fbc887c7fa9d71e56d0fb63d55c904b56ac4775f475445b412
libssh2-debuginfo-1.8.0-4.el7_9.2.s390.rpm SHA-256: c1659e4441af49372b9469c70911ee56b389eedd3b4b7cc99c075f382ed0a193
libssh2-debuginfo-1.8.0-4.el7_9.2.s390.rpm SHA-256: c1659e4441af49372b9469c70911ee56b389eedd3b4b7cc99c075f382ed0a193
libssh2-debuginfo-1.8.0-4.el7_9.2.s390x.rpm SHA-256: 97a1e631caa0c9cebf1e344d9620ab955e00bfb3ec39cda0b1063fd4488f4dbb
libssh2-debuginfo-1.8.0-4.el7_9.2.s390x.rpm SHA-256: 97a1e631caa0c9cebf1e344d9620ab955e00bfb3ec39cda0b1063fd4488f4dbb
libssh2-devel-1.8.0-4.el7_9.2.s390.rpm SHA-256: 015ceaab0ea934dbdef196fc7c85f14f937b74163f1846da167d8ca924e278fe
libssh2-devel-1.8.0-4.el7_9.2.s390x.rpm SHA-256: 74c8755fdf9f4b05365b6a34de4a6d6af5b620c0efe675fb14cac131d6638670
libssh2-docs-1.8.0-4.el7_9.2.noarch.rpm SHA-256: ef792e49d34b08227b521fc8ff762281fb88a6f54cb48d5335c53c8ccf44142e

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
libssh2-1.8.0-4.el7_9.2.src.rpm SHA-256: e1e61bcc2c79b646875b5452b528b6b6351250af4e2a3c896a624dc594837216
ppc64
libssh2-1.8.0-4.el7_9.2.ppc.rpm SHA-256: c6580a063a81d2dd30d48eb0923b2a8aba762ee281c2105a9f619cfabc8573c7
libssh2-1.8.0-4.el7_9.2.ppc64.rpm SHA-256: b57b0191c4d0a37056de119a129432e1f4d636c753271d7ca6e289e15acb9d08
libssh2-debuginfo-1.8.0-4.el7_9.2.ppc.rpm SHA-256: 824eb603734d4c798e558bc963b2e6a27a2ca40a9833020d1b77ee8997b9628c
libssh2-debuginfo-1.8.0-4.el7_9.2.ppc.rpm SHA-256: 824eb603734d4c798e558bc963b2e6a27a2ca40a9833020d1b77ee8997b9628c
libssh2-debuginfo-1.8.0-4.el7_9.2.ppc64.rpm SHA-256: 078d03027e93c38c0aab8fb2b3c2f7abf8b6f198ea7cc7545753f0ac55b27278
libssh2-debuginfo-1.8.0-4.el7_9.2.ppc64.rpm SHA-256: 078d03027e93c38c0aab8fb2b3c2f7abf8b6f198ea7cc7545753f0ac55b27278
libssh2-devel-1.8.0-4.el7_9.2.ppc.rpm SHA-256: 5408a2bb650b80e8a07c64e69c847b5f02f28dd4b6a307ed12f65dbca80e7533
libssh2-devel-1.8.0-4.el7_9.2.ppc64.rpm SHA-256: 3140d7fe06fad926f49eaa08feebabfd124fae033719cda1dd9980226b30eba0
libssh2-docs-1.8.0-4.el7_9.2.noarch.rpm SHA-256: ef792e49d34b08227b521fc8ff762281fb88a6f54cb48d5335c53c8ccf44142e

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
libssh2-1.8.0-4.el7_9.2.src.rpm SHA-256: e1e61bcc2c79b646875b5452b528b6b6351250af4e2a3c896a624dc594837216
ppc64le
libssh2-1.8.0-4.el7_9.2.ppc64le.rpm SHA-256: 4a6bd0d6b938636e115d20444dd2fb4f3bf1fda3e00c0b00d03750d78627bea9
libssh2-debuginfo-1.8.0-4.el7_9.2.ppc64le.rpm SHA-256: 028f37fed340ee9a32d7d93805b760996b589c05ace1c723bbe5c955c1186015
libssh2-debuginfo-1.8.0-4.el7_9.2.ppc64le.rpm SHA-256: 028f37fed340ee9a32d7d93805b760996b589c05ace1c723bbe5c955c1186015
libssh2-devel-1.8.0-4.el7_9.2.ppc64le.rpm SHA-256: 6fa292b92d43191f29d8a9d1411a34b38135fab4adcb0e63f26f7157ba24491d
libssh2-docs-1.8.0-4.el7_9.2.noarch.rpm SHA-256: ef792e49d34b08227b521fc8ff762281fb88a6f54cb48d5335c53c8ccf44142e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility