PatchSiren cyber security CVE debrief
CVE-2026-0965 Redhat CVE debrief
CVE-2026-0965 is a low-severity local denial-of-service issue in libssh. During configuration parsing, affected versions may attempt to open arbitrary files. In misconfigured deployments or when a malicious configuration file is provided, this can cause the system to access sensitive targets such as block devices or large system files and disrupt normal operation.
- Vendor
- Redhat
- Product
- Unknown
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-26
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-03-26
- Advisory updated
- 2026-09-01
Who should care
Administrators and application teams that deploy libssh, especially where configuration files may be user-controlled or where the library is packaged in Red Hat Enterprise Linux environments. Security teams managing Red Hat errata and embedded libssh dependencies should also review exposure.
Technical summary
NVD lists libssh versions through 0.11.3 as vulnerable and maps the issue to CWE-73 (External Control of File Name or Path). The CVSS v3.0 vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L, indicating a local attack with low privileges and availability impact only. The reported behavior is arbitrary file opening during configuration parsing, which can lead to DoS when dangerous files are accessed.
Defensive priority
Low
Recommended defensive actions
- Apply vendor fixes and update affected libssh packages beyond the vulnerable range reported by NVD (through 0.11.3).
- Review any workflows that allow untrusted or attacker-influenced configuration files and stop them from reaching libssh parsing paths.
- Limit local access and follow least-privilege practices for services that use libssh.
- Check Red Hat advisories and errata for the applicable platform packages and confirm remediation is installed.
- Monitor for abnormal file-access errors or service instability around configuration parsing, especially on systems handling custom configs.
Evidence notes
The supplied official data shows CVE publication on 2026-03-26 and a later NVD modification on 2026-05-19. NVD marks libssh as vulnerable through 0.11.3 and includes Red Hat Enterprise Linux 9.0 and 10.0 CPE entries. The mapped weakness is CWE-73, and the CVSS vector indicates a local, low-privilege availability issue. Red Hat references include RHSA-2026:18160, RHSA-2026:18683, a Red Hat CVE page, and a Bugzilla record. No KEV listing or ransomware linkage was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-0965 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-0965
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-0965 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0965
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:18160
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:18683
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-0965
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.