Logo
vulnerabilityCVE-2026-7598
Name
CVE-2026-7598
Source
NVD ( link)Debian ( link)
Description
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libssh2
Patched

Vulnerability Ratings#


6.9
CVSSv4
7.3
CVSSv31
7.5
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.11.1
Patched
buildroot
master
1.11.1
Patched
openwrt
master
1.11.1-r1
Exploitable
openwrt
openwrt-25.12
1.11.1-r1
Exploitable
yocto
kirkstone
1.10.0
Exploitable
yocto
scarthgap
1.11.1
Patched

Resolved with patches#


libssh2 (buildroot:2025.02.x)

#
Title
Author
Resolve
1
userauth.c: username_len bounds checking (#1858)
Will Cosgrove <will@panic.com>
CVE-2026-7598

libssh2 (buildroot:master)

#
Title
Author
Resolve
1
userauth.c: username_len bounds checking (#1858)
Will Cosgrove <will@panic.com>
CVE-2026-7598

libssh2 (yocto:master)

#
Title
Author
Resolve
1
userauth.c: username_len bounds checking (#1858)
Will Cosgrove <will@panic.com>
CVE-2026-7598

libssh2 (yocto:scarthgap)

#
Title
Author
Resolve
1
userauth.c: username_len bounds checking (#1858)
Will Cosgrove <will@panic.com>
CVE-2026-7598