What is CVE-2026-59842?
A vulnerability in libssh allows an out-of-bounds heap read during server-side GSSAPI key exchange when copying a client-supplied Curve25519 public key without proper length validation. This flaw could enable a remote unauthenticated attacker to disclose limited heap memory, affecting servers using libssh. Immediate patching of libssh is strongly recommended.
Azərbaycanca: libssh kitabxanasında server tərəfli GSSAPI açar mübadiləsində, müştəri tərəfindən göndərilən qısa Curve25519 açıq açarı uzunluq yoxlanılmadan kopyalanır, bu isə heap-də sərhəddən kənar oxuma zəifliyinə səbəb olur. Bu qüsur uzaqdan autentifikasiya olunmamış hücumçuya məhdud yaddaş məlumatlarını əldə etməyə imkan verə bilər, libssh istifadə edən serverlər təsirlənir. Dərhal libssh yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
In which component of libssh was CVE-2026-59842 discovered?
The vulnerability occurs during the server-side GSSAPI key exchange in libssh when copying a client-supplied Curve25519 public key.
What outcome can an attacker achieve by exploiting CVE-2026-59842?
A remote unauthenticated attacker can disclose limited heap memory through this out-of-bounds read vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.