Logo
vulnerabilityCVE-2026-0964
Name
CVE-2026-0964
Source
NVD ( link)Debian ( link)
Description
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libssh
Exploitable

Vulnerability Ratings#


6.3
CVSSv31
5
other
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.4
Not Affected
buildroot
master
0.12.0
Not Affected
openwrt
master
0.12.0-r1
Not Affected
yocto
kirkstone
0.8.9
Patched
yocto
master
0.11.4
Not Affected
yocto
scarthgap
0.10.6
Patched

Resolved with patches#


libssh (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2026-0964 scp: Reject invalid paths received through scp
Jakub Jelen <jjelen@redhat.com>
CVE-2026-0964

libssh (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2026-0964 scp: Reject invalid paths received through scp
Jakub Jelen <jjelen@redhat.com>
CVE-2026-0964