What is CVE-2026-59843?
A flaw in libssh allows a remote authenticated peer to advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing subsequent channel writes to loop indefinitely and exhaust CPU resources, leading to denial of service. Affected libssh deployments should be patched promptly.
Azərbaycanca: CVE-2026-59843 libssh kitabxanasında aşkar edilmiş bir zəiflikdir. Uzaqdan autentifikasiyadan keçmiş şəxs SSH_MSG_CHANNEL_OPEN zamanı sıfır maksimum paket ölçüsü elan edərək kanal yazma əməliyyatlarını sonsuz dövrə sala, CPU resurslarını tükədə və denial of service (DoS) vəziyyətinə səbəb ola bilər. Təsirə məruz qalan libssh versiyalarını təcili yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
Which operation in the libssh library triggers the DoS condition in CVE-2026-59843?
The flaw is triggered by advertising a zero maximum packet size during SSH_MSG_CHANNEL_OPEN, which causes an infinite loop in channel write operations and exhausts CPU resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.