libssh2是libssh2团队开源的一款实现SSH2协议的客户端C库。 libssh2 1.11.1及之前版本存在资源管理错误漏洞,该漏洞源于sftp_open()函数中存在双重释放,可能导致恶意SSH服务器破坏任何打开SFTP会话的已验证客户端的堆。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: glibc tcache double-free abort in libssh2 sftp_open(): 'free(): double free detected in tcache 2' (client exit=134)
| CVE-2026-66033 | 7.5 HIGH | libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation |
| CVE-2026-66034 | 7.5 HIGH | libssh2 Heap Out-of-Bounds Read via publickey subsystem |
| CVE-2026-66035 | 7.5 HIGH | libssh2 Heap Buffer Overflow via ETM Cipher Negotiation |
No comments yet