Logo
vulnerabilityCVE-2026-0967
Name
CVE-2026-0967
Source
NVD ( link)Debian ( link)
Description
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libssh
Exploitable

Vulnerability Ratings#


5.5
CVSSv31
2.2
other
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.4
Not Affected
buildroot
master
0.12.0
Not Affected
openwrt
master
0.12.0-r1
Not Affected
yocto
kirkstone
0.8.9
Exploitable
yocto
master
0.11.4
Not Affected
yocto
scarthgap
0.10.6
Patched

Resolved with patches#


libssh (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2026-0967 match: Avoid recursive matching (ReDoS)
Jakub Jelen <jjelen@redhat.com>
CVE-2026-0967