CVE-2026-0966Disclosure(libssh / enterprise_linux)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-124

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • hardened_images
  • libssh
  • openshift_container_platform

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
enterprise_linuxhardened_imageslibsshopenshift_container_platform

5 versions affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-26: 1Technical Details · 2026-03-26: 103-26
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-0966 The API function `ssh_get_hexa()` is vulnerable, when 0-lenght input is provided to this function. This function is used internally in `ssh_get_fingerprint_hash()` and … https://www.cve.org/CVERecord?id=CVE-2026-0966

    Post summary

    CVE-2026-0966 highlights a vulnerability in the ssh_get_hexa API function triggered by 0‑length input, potentially affecting ssh_get_fingerprint_hash and related operations.

    0001092
    56.9K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Applibsshlibssh---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---
Appredhatopenshift_container_platform4.0--

Explore more