PatchSiren cyber security CVE debrief
CVE-2026-0968 Redhat CVE debrief
CVE-2026-0968, published on 2026-03-26 and last modified on 2026-05-19, affects libssh during SFTP file listing. A malicious server can send a malformed "longname" field in an SSH_FXP_NAME message, and the missing null check may cause an out-of-bounds read on the heap. The supplied record rates this as low severity with availability impact only, but it can still crash affected applications and cause a denial of service.
- Vendor
- Redhat
- Product
- Unknown
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-26
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-03-26
- Advisory updated
- 2026-09-01
Who should care
Security and platform teams that deploy applications using libssh for SFTP access, especially where clients connect to untrusted or third-party SFTP servers. Downstream package maintainers and Red Hat users should also review the referenced advisories and package updates.
Technical summary
The issue is a missing null check in libssh while processing SFTP directory listings. When a malicious server returns a malformed SSH_FXP_NAME response, the "longname" field can lead to reading beyond allocated heap memory. The supplied CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L, and the supplied weakness mapping is CWE-476.
Defensive priority
Moderate for exposed SFTP client workflows, despite the low CVSS score. The vulnerability requires a malicious server and user-driven file listing interaction, but affected clients may still crash. Prioritize if your environment connects to untrusted SFTP endpoints or ships libssh in widely used tooling.
Recommended defensive actions
- Inventory systems and applications using libssh, especially versions at or below 0.11.3.
- Apply vendor updates that include the libssh 0.11.4 security release or later.
- Review Red Hat advisories RHSA-2026:18160 and RHSA-2026:18683 for downstream package fixes.
- Validate whether SFTP file listing against untrusted servers is part of your operational workflow and add compensating controls where possible.
- Monitor for application crashes or abnormal behavior in SFTP-enabled clients until patched.
Evidence notes
Evidence comes from the supplied NVD record and Red Hat-linked references. The NVD data identifies libssh versions through 0.11.3 as vulnerable and assigns CVSS 3.1 AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L with CWE-476. The references include Red Hat advisories, a Red Hat CVE page, a Bugzilla entry, and libssh security release notes for 0.12.0 and 0.11.4.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-0968 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-0968
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-0968 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0968
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:18160
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:18683
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-0968
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
[email protected] - Release Notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.