Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-59842 — libssh: libssh: information disclosure via short GSSAPI Curve25519 public key CVE-2026-59843 — libssh: libssh: denial of service via zero advertised channel packet size CVE-2026-59844 — libssh: libssh: denial of service via oversized SFTP read length CVE-2026-59845 — libssh: libssh: denial of service via unchecked ProxyCommand fork() failure CVE-2026-59846 — libssh: libssh: information disclosure via ProxyCommand %r username expansion CVE-2026-59847 — libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification CVE-2026-59848 — libssh: libssh: denial of service via SFTP responses with unknown request IDs CVE-2026-59849 — libssh: libssh: denial of service via automatic certificate authentication loop CVE-2026-59850 — libssh: libssh: use-after-free via data callbacks on closed channels CVE-2026-59851 — libssh: libssh: authentication bypass via missing GSSAPI principal check
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:42922
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-59849
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-59848
- externalhttps://access.redhat.com/security/cve/CVE-2026-59846
- externalhttps://access.redhat.com/security/cve/CVE-2026-59845
- externalhttps://access.redhat.com/security/cve/CVE-2026-59844
- externalhttps://access.redhat.com/security/cve/CVE-2026-59843
- externalhttps://access.redhat.com/security/cve/CVE-2026-59842
- externalhttps://access.redhat.com/security/cve/CVE-2026-59851
- externalhttps://access.redhat.com/security/cve/CVE-2026-59850
- externalhttps://access.redhat.com/security/cve/CVE-2026-59847
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42922.json