CVE-2026-0967

Name
CVE-2026-0967
Description
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-0967
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2436981
secalert@redhat.com https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* libssh >= None <= 0.11.3
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* enterprise_linux == None == 10.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libssh edge-community 0.12.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libssh edge-community 0.11.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libssh edge-community 0.11.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libssh edge-community 0.11.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libssh edge-community 0.10.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libssh edge-community 0.9.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libssh edge-community 0.9.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libssh edge-community 0.9.4-r0 None possibly vulnerable
libssh edge-community 0.9.3-r0 None possibly vulnerable
libssh edge-community 0.7.6-r0 None possibly vulnerable
libssh 3.23-community 0.11.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libssh 3.23-community 0.11.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable