DSA-6410-1 libssh - security update
Several vulnerabilities were discovered in libssh, a tiny C SSH library, which may result in denial of service, information disclosure and potentially the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6410-1
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00321.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-09640.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-09650.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-09660.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
- Low exploitation riskCVE-2026-09670.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-09680.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-37310.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all scored CVEs.
- Low exploitation riskCVE-2026-153700.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-598430.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-598440.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-598450.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-0964 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0965 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0966 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0967 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0968 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3731 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15370 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59843 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59844 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59845 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59846 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59847 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59848 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59849 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59850 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] libssh: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] libssh: Vulnerability allows Denial of Servicecert-bund
- medium[UPDATE] [mittel] libssh: Mehrere Schwachstellen ermöglichen Manipulation von Dateien und DoScert-bund
- mediumCVE-2026-59850: A flaw was found in libssh. If data packets are processed after a channel is closed, channel d…nvd
- lowCVE-2026-59849: A flaw was found in libssh. Logic errors in automatic certificate-based public key authenticat…nvd
- mediumCVE-2026-59848: A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs…nvd
- mediumCVE-2026-59847: A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL …nvd
- lowCVE-2026-59846: A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling …nvd
- mediumCVE-2026-59845: A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stor…nvd
- mediumCVE-2026-59844: A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with…nvd
- mediumCVE-2026-59843: A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet si…nvd
- mediumCVE-2026-15370: A flaw was found in libssh. During SFTP server directory listing, the longname field is constr…nvd
More from Debian Security Advisories
- unknownDSA-6411-1 aom - security update2026-08-05
- unknownDSA-6412-1 botan3 - security update2026-08-05
- unknownDSA-6409-1 libgd2 - security update2026-08-01
- unknownDSA-6406-1 php8.4 - security update2026-07-31
- unknownDSA-6407-1 incus - security update2026-07-31