CVE-2026-0964MediumCVSS 5.0

Libssh: improper sanitation of paths received from scp servers

Published
May 31, 2026
Last Modified
—

🔗 CVE IDs covered (1)

🎯 Affected products4

  • azl3 libssh 0.10.6-5 on Azure Linux 3.0
  • azl3 libssh 0.10.6-6 on Azure Linux 3.0
  • azl3 libssh 0.10.6-7 on Azure Linux 3.0
  • cbl2 libssh 0.10.6-5 on CBL Mariner 2.0

✅ Remediation

KBCBL-Mariner Releases (Security Update) — fixed build 0.10.6-6 KBCBL-Mariner Releases (Security Update) — fixed build 0.10.6-7

🔗 References (2)