Logo
vulnerabilityCVE-2026-0965
Name
CVE-2026-0965
Source
NVD ( link)Debian ( link)
Description
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libssh
Exploitable

Vulnerability Ratings#


3.3
other
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.4
Not Affected
buildroot
master
0.12.0
Not Affected
openwrt
master
0.12.0-r1
Not Affected
openwrt
openwrt-25.12
0.11.3-r1
Exploitable
yocto
master
0.11.4
Not Affected
yocto
scarthgap
0.10.6
Patched

Resolved with patches#


libssh (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2026-0965 config: Do not attempt to read non-regular and
Jakub Jelen <jjelen@redhat.com>
CVE-2026-0965