CVE-2026-66032

Description

A flaw was found in libssh2. A malicious SSH (Secure Shell) server can exploit a double-free vulnerability in the sftp_open() function. This flaw allows the server to corrupt the heap memory of an authenticated client when it opens an SFTP (SSH File Transfer Protocol) session. This heap corruption can lead to arbitrary code execution on the client system, giving the attacker control over the affected system.

Statement

Moderate: A double-free vulnerability in libssh2 allows a malicious SSH server to corrupt the heap of an authenticated client during an SFTP session. This flaw requires user interaction, as a client must connect to a specially crafted server and initiate an SFTP transfer, which can lead to arbitrary code execution on the client system.

Mitigation

Restrict your libssh2 clients to connect only to fully trusted, internal SFTP servers to eliminate exposure to malicious server responses. Additionally, configure dependent applications with Restart=on-failure in systemd so RHEL's glibc memory protections can safely crash and auto-recover the process during an attack.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.5N/A8.8
Attack VectorNetworkN/ANetwork
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionRequiredN/ARequired
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/AHigh
Integrity ImpactNoneN/AHigh
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Availability,Integrity

Technical Impact: DoS: Crash, Exit, or Restart

Frequently Asked Questions

Want to get errata notifications? Sign up here.