Logo
vulnerabilityCVE-2026-3731
Name
CVE-2026-3731
Source
NVD ( link)Debian ( link)
Description
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libssh
Patched

Vulnerability Ratings#


6.9
CVSSv4
5.3
CVSSv31
7.5
CVSSv31
5
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.4
Not Affected
buildroot
master
0.12.0
Not Affected
openwrt
master
0.12.0-r1
Not Affected
openwrt
openwrt-25.12
0.11.3-r1
Exploitable
yocto
kirkstone
0.8.9
Patched
yocto
master
0.11.4
Not Affected

Resolved with patches#


libssh (yocto:kirkstone)

#
Title
Author
Resolve
1
sftp: Fix out-of-bound read from sftp extensions
Jakub Jelen <jjelen@redhat.com>
CVE-2026-3731

libssh (yocto:scarthgap)

#
Title
Author
Resolve
1
sftp: Fix out-of-bound read from sftp extensions
Jakub Jelen <jjelen@redhat.com>
CVE-2026-3731
2
Reproducer for out of bounds read of SFTP extensions
Jakub Jelen <jjelen@redhat.com>
CVE-2026-3731