Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Disable GSSAPIKeyExchange or remove gss-curve25519-sha256- from GSSAPIKexAlgorithms if appropriate.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat enterprise Linux For Els
Redhat enterprise Linux For Eus Redhat enterprise Linux For Ibm Z Systems Redhat enterprise Linux For Ibm Z Systems Els Redhat enterprise Linux For Ibm Z Systems Eus Redhat enterprise Linux For Power Little Endian Redhat enterprise Linux For Power Little Endian Els Redhat enterprise Linux For Power Little Endian Eus |
|
| CPEs | cpe:2.3:a:libssh:libssh:0.12.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_els:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux_for_els:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_eus:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux_for_eus:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_els:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_els:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:10.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Redhat enterprise Linux For Els
Redhat enterprise Linux For Eus Redhat enterprise Linux For Ibm Z Systems Redhat enterprise Linux For Ibm Z Systems Els Redhat enterprise Linux For Ibm Z Systems Eus Redhat enterprise Linux For Power Little Endian Redhat enterprise Linux For Power Little Endian Els Redhat enterprise Linux For Power Little Endian Eus |
Wed, 19 Aug 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:10.2 | |
| References |
|
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libssh
Libssh libssh Redhat hardened Images |
|
| Vendors & Products |
Libssh
Libssh libssh Redhat hardened Images |
Wed, 22 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 22 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 21 Jul 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. | |
| Title | Libssh: libssh: information disclosure via short gssapi curve25519 public key | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-19T04:57:33.551Z
Reserved: 2026-07-07T15:40:24.560Z
Link: CVE-2026-59842
Updated: 2026-07-22T14:01:03.020Z
Status : Analyzed
Published: 2026-07-21T12:18:57.727
Modified: 2026-09-22T19:47:55.080
Link: CVE-2026-59842
OpenCVE Enrichment
Updated: 2026-07-30T18:00:15Z