CVE-2026-15370

Summary

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Enterprise Linux 100:0.12.0-3.el10_2 < *unaffected
Red HatRed Hat Hardened Images0.12.2-1.hum1 < *unaffected

Weaknesses

  • CWE-121: Stack-based Buffer Overflow

Workarounds

No workaround available.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References