Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:62218 - Security Advisory
Issued:
2026-09-01
Updated:
2026-09-01

RHSA-2026:62218 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: libssh security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libssh is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.

Security Fix(es):

  • libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843)
  • libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844)
  • libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845)
  • libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846)
  • libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847)
  • libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848)
  • libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x

Fixes

  • BZ - 2498176 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size
  • BZ - 2498177 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length
  • BZ - 2498178 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure
  • BZ - 2498179 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion
  • BZ - 2498180 - CVE-2026-59847 libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification
  • BZ - 2498181 - CVE-2026-59848 libssh: libssh: denial of service via SFTP responses with unknown request IDs
  • BZ - 2498183 - CVE-2026-59850 libssh: libssh: use-after-free via data callbacks on closed channels

CVEs

  • CVE-2026-59843
  • CVE-2026-59844
  • CVE-2026-59845
  • CVE-2026-59846
  • CVE-2026-59847
  • CVE-2026-59848
  • CVE-2026-59850

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b
x86_64
libssh-0.9.6-17.el8_10.i686.rpm SHA-256: 1e8870229bc1c60428e3e760e516b123ca8545d67f864ca11c7ae6313ed2031b
libssh-0.9.6-17.el8_10.x86_64.rpm SHA-256: 6b63ff7d5535f6b2e0c59c721346bccc27aa8c69e91c1f91aa5164841d25fe6c
libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e
libssh-debuginfo-0.9.6-17.el8_10.i686.rpm SHA-256: 6c35bfc67ac4da8a774438533093f4f7cca9715bc0dd89a2f48604179786b7f1
libssh-debuginfo-0.9.6-17.el8_10.i686.rpm SHA-256: 6c35bfc67ac4da8a774438533093f4f7cca9715bc0dd89a2f48604179786b7f1
libssh-debuginfo-0.9.6-17.el8_10.x86_64.rpm SHA-256: 126cad613e54b435f9c9af9b0c01657acc25eca20e4e2ef0e41bf402aeff0819
libssh-debuginfo-0.9.6-17.el8_10.x86_64.rpm SHA-256: 126cad613e54b435f9c9af9b0c01657acc25eca20e4e2ef0e41bf402aeff0819
libssh-debugsource-0.9.6-17.el8_10.i686.rpm SHA-256: 33c749839225fbafb2e873894731da3c1ddcd58e0857f7f8ad1425cf9243916d
libssh-debugsource-0.9.6-17.el8_10.i686.rpm SHA-256: 33c749839225fbafb2e873894731da3c1ddcd58e0857f7f8ad1425cf9243916d
libssh-debugsource-0.9.6-17.el8_10.x86_64.rpm SHA-256: 90ee6393194e7798e74317676e162ff7e0e5678b8c4bd866487c266cf7141439
libssh-debugsource-0.9.6-17.el8_10.x86_64.rpm SHA-256: 90ee6393194e7798e74317676e162ff7e0e5678b8c4bd866487c266cf7141439
libssh-devel-0.9.6-17.el8_10.i686.rpm SHA-256: ebb1c09208865f3dad62c6e2b5166a1a1bc52b6b2004fb8063145dcc03d69729
libssh-devel-0.9.6-17.el8_10.x86_64.rpm SHA-256: 289409df706a04ce80cc55e4ad40a3c9494063a8a871392a0b8f359689cc5bd1

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b
s390x
libssh-0.9.6-17.el8_10.s390x.rpm SHA-256: 24ada9a39b08317ebd00b79919556ac0251a7729afc5a56583654ebace8e0d84
libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e
libssh-debuginfo-0.9.6-17.el8_10.s390x.rpm SHA-256: 2741a093e57718e9a9676da553bfebe15789233099cc72070e0b7d419c81ef9b
libssh-debuginfo-0.9.6-17.el8_10.s390x.rpm SHA-256: 2741a093e57718e9a9676da553bfebe15789233099cc72070e0b7d419c81ef9b
libssh-debugsource-0.9.6-17.el8_10.s390x.rpm SHA-256: 8d8b6f4d244eeb3fc844e4f6706002c07d0c840764f9a3f5729a735a81fd44df
libssh-debugsource-0.9.6-17.el8_10.s390x.rpm SHA-256: 8d8b6f4d244eeb3fc844e4f6706002c07d0c840764f9a3f5729a735a81fd44df
libssh-devel-0.9.6-17.el8_10.s390x.rpm SHA-256: 2cdd3b6f62cf43aa1ee09b882bf08a040bf0cefcd6b721ac550bcfbfde846d33

Red Hat Enterprise Linux for Power, little endian 8

SRPM
libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b
ppc64le
libssh-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 7d6796427509bb5f850df20f26cb8670abf9836afef1201bd431c73d95e2747e
libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e
libssh-debuginfo-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 5e7ee6231a11ac7fe00ffb303018eca5855aededcf78c4a2df7bcfa54b602114
libssh-debuginfo-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 5e7ee6231a11ac7fe00ffb303018eca5855aededcf78c4a2df7bcfa54b602114
libssh-debugsource-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 20a046b29dc5f0cfc8dd91105f4fe5088c8208533e4258caa6e7c35590d2e0de
libssh-debugsource-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 20a046b29dc5f0cfc8dd91105f4fe5088c8208533e4258caa6e7c35590d2e0de
libssh-devel-0.9.6-17.el8_10.ppc64le.rpm SHA-256: f367d42f1cb411e72f3f86e8bdd23bfac9088f6a9ea280cc34b9cd67b157da18

Red Hat Enterprise Linux for ARM 64 8

SRPM
libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b
aarch64
libssh-0.9.6-17.el8_10.aarch64.rpm SHA-256: ffba69fdbd592b3576ecf5a69723b49e07dba5364e1c78161ff6374c35dde6da
libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e
libssh-debuginfo-0.9.6-17.el8_10.aarch64.rpm SHA-256: fa2d168d45ceaf1145b92cb90cdbfe5cac408521e0b5aa1437143958f0392483
libssh-debuginfo-0.9.6-17.el8_10.aarch64.rpm SHA-256: fa2d168d45ceaf1145b92cb90cdbfe5cac408521e0b5aa1437143958f0392483
libssh-debugsource-0.9.6-17.el8_10.aarch64.rpm SHA-256: 7968a9d01f01cc8c06a57aba5657423bd018f0909795ab0bdef799fb9859f8eb
libssh-debugsource-0.9.6-17.el8_10.aarch64.rpm SHA-256: 7968a9d01f01cc8c06a57aba5657423bd018f0909795ab0bdef799fb9859f8eb
libssh-devel-0.9.6-17.el8_10.aarch64.rpm SHA-256: 69063d6ea75f1066fee58f7b2f66450205da6234da346adeb048edcdc2746137

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10

SRPM
libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b
x86_64
libssh-0.9.6-17.el8_10.i686.rpm SHA-256: 1e8870229bc1c60428e3e760e516b123ca8545d67f864ca11c7ae6313ed2031b
libssh-0.9.6-17.el8_10.x86_64.rpm SHA-256: 6b63ff7d5535f6b2e0c59c721346bccc27aa8c69e91c1f91aa5164841d25fe6c
libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e
libssh-debuginfo-0.9.6-17.el8_10.i686.rpm SHA-256: 6c35bfc67ac4da8a774438533093f4f7cca9715bc0dd89a2f48604179786b7f1
libssh-debuginfo-0.9.6-17.el8_10.i686.rpm SHA-256: 6c35bfc67ac4da8a774438533093f4f7cca9715bc0dd89a2f48604179786b7f1
libssh-debuginfo-0.9.6-17.el8_10.x86_64.rpm SHA-256: 126cad613e54b435f9c9af9b0c01657acc25eca20e4e2ef0e41bf402aeff0819
libssh-debuginfo-0.9.6-17.el8_10.x86_64.rpm SHA-256: 126cad613e54b435f9c9af9b0c01657acc25eca20e4e2ef0e41bf402aeff0819
libssh-debugsource-0.9.6-17.el8_10.i686.rpm SHA-256: 33c749839225fbafb2e873894731da3c1ddcd58e0857f7f8ad1425cf9243916d
libssh-debugsource-0.9.6-17.el8_10.i686.rpm SHA-256: 33c749839225fbafb2e873894731da3c1ddcd58e0857f7f8ad1425cf9243916d
libssh-debugsource-0.9.6-17.el8_10.x86_64.rpm SHA-256: 90ee6393194e7798e74317676e162ff7e0e5678b8c4bd866487c266cf7141439
libssh-debugsource-0.9.6-17.el8_10.x86_64.rpm SHA-256: 90ee6393194e7798e74317676e162ff7e0e5678b8c4bd866487c266cf7141439
libssh-devel-0.9.6-17.el8_10.i686.rpm SHA-256: ebb1c09208865f3dad62c6e2b5166a1a1bc52b6b2004fb8063145dcc03d69729
libssh-devel-0.9.6-17.el8_10.x86_64.rpm SHA-256: 289409df706a04ce80cc55e4ad40a3c9494063a8a871392a0b8f359689cc5bd1

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10

SRPM
libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b
aarch64
libssh-0.9.6-17.el8_10.aarch64.rpm SHA-256: ffba69fdbd592b3576ecf5a69723b49e07dba5364e1c78161ff6374c35dde6da
libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e
libssh-debuginfo-0.9.6-17.el8_10.aarch64.rpm SHA-256: fa2d168d45ceaf1145b92cb90cdbfe5cac408521e0b5aa1437143958f0392483
libssh-debuginfo-0.9.6-17.el8_10.aarch64.rpm SHA-256: fa2d168d45ceaf1145b92cb90cdbfe5cac408521e0b5aa1437143958f0392483
libssh-debugsource-0.9.6-17.el8_10.aarch64.rpm SHA-256: 7968a9d01f01cc8c06a57aba5657423bd018f0909795ab0bdef799fb9859f8eb
libssh-debugsource-0.9.6-17.el8_10.aarch64.rpm SHA-256: 7968a9d01f01cc8c06a57aba5657423bd018f0909795ab0bdef799fb9859f8eb
libssh-devel-0.9.6-17.el8_10.aarch64.rpm SHA-256: 69063d6ea75f1066fee58f7b2f66450205da6234da346adeb048edcdc2746137

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10

SRPM
libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b
ppc64le
libssh-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 7d6796427509bb5f850df20f26cb8670abf9836afef1201bd431c73d95e2747e
libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e
libssh-debuginfo-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 5e7ee6231a11ac7fe00ffb303018eca5855aededcf78c4a2df7bcfa54b602114
libssh-debuginfo-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 5e7ee6231a11ac7fe00ffb303018eca5855aededcf78c4a2df7bcfa54b602114
libssh-debugsource-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 20a046b29dc5f0cfc8dd91105f4fe5088c8208533e4258caa6e7c35590d2e0de
libssh-debugsource-0.9.6-17.el8_10.ppc64le.rpm SHA-256: 20a046b29dc5f0cfc8dd91105f4fe5088c8208533e4258caa6e7c35590d2e0de
libssh-devel-0.9.6-17.el8_10.ppc64le.rpm SHA-256: f367d42f1cb411e72f3f86e8bdd23bfac9088f6a9ea280cc34b9cd67b157da18

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10

SRPM
libssh-0.9.6-17.el8_10.src.rpm SHA-256: cda247c567406436485e81b58b5eb90e86a21f9d69b2741d9d2e546e8f24d03b
s390x
libssh-0.9.6-17.el8_10.s390x.rpm SHA-256: 24ada9a39b08317ebd00b79919556ac0251a7729afc5a56583654ebace8e0d84
libssh-config-0.9.6-17.el8_10.noarch.rpm SHA-256: d7a95db22137990f5026b5f601e3f48dab314e850b3587a1e46b412cb7f6b60e
libssh-debuginfo-0.9.6-17.el8_10.s390x.rpm SHA-256: 2741a093e57718e9a9676da553bfebe15789233099cc72070e0b7d419c81ef9b
libssh-debuginfo-0.9.6-17.el8_10.s390x.rpm SHA-256: 2741a093e57718e9a9676da553bfebe15789233099cc72070e0b7d419c81ef9b
libssh-debugsource-0.9.6-17.el8_10.s390x.rpm SHA-256: 8d8b6f4d244eeb3fc844e4f6706002c07d0c840764f9a3f5729a735a81fd44df
libssh-debugsource-0.9.6-17.el8_10.s390x.rpm SHA-256: 8d8b6f4d244eeb3fc844e4f6706002c07d0c840764f9a3f5729a735a81fd44df
libssh-devel-0.9.6-17.el8_10.s390x.rpm SHA-256: 2cdd3b6f62cf43aa1ee09b882bf08a040bf0cefcd6b721ac550bcfbfde846d33

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility