#libssh2 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #libssh2, aggregated by home.social.
-
Kritische #libssh2-Lücke: Proof-of-Concept-#Exploit veröffentlicht | Security https://www.heise.de/news/Kritische-libssh2-Luecke-Proof-of-Concept-Exploit-veroeffentlicht-11347855.html #Patchday
-
Kritische #libssh2-Lücke: Proof-of-Concept-#Exploit veröffentlicht | Security https://www.heise.de/news/Kritische-libssh2-Luecke-Proof-of-Concept-Exploit-veroeffentlicht-11347855.html #Patchday
-
@bagder ohoh #complexity please reduce as much as possible :( just btw #curl links #libssh2 https://lists.debian.org/debian-security-announce/2026/msg00276.html
-
@bagder ohoh #complexity please reduce as much as possible :( just btw #curl links #libssh2 https://lists.debian.org/debian-security-announce/2026/msg00276.html
-
🚨 Critical update: A proof-of-concept exploit has been released for a libssh2 vulnerability (CVE-2026-55200, CVSS 9.8). Attackers can abuse oversized SSH “packet_length” to corrupt heap memory. 📌 Patch status varies—check updates now: https://www.heise.de/en/news/Critical-libssh2-vulnerability-Proof-of-concept-exploit-released-11347906.html #CyberSecurity #Vulnerability #libssh2 #CVE
-
🚨 Critical update: A proof-of-concept exploit has been released for a libssh2 vulnerability (CVE-2026-55200, CVSS 9.8). Attackers can abuse oversized SSH “packet_length” to corrupt heap memory. 📌 Patch status varies—check updates now: https://www.heise.de/en/news/Critical-libssh2-vulnerability-Proof-of-concept-exploit-released-11347906.html #CyberSecurity #Vulnerability #libssh2 #CVE
-
🚨 Kritische libssh2-Lücke: Ein Proof-of-Concept-Exploit wurde veröffentlicht. Ursache: fehlende Begrenzung von „packet_length“ in ssh2_transport_read()—Angreifer können manipulierte SSH-Pakete senden und Speicher auf dem Heap durcheinanderbringen (CVE-2026-55200, CVSS 9.8). Update prüfen: https://www.heise.de/news/Kritische-libssh2-Luecke-Proof-of-Concept-Exploit-veroeffentlicht-11347855.html 🔐 #CyberSecurity #Vulnerability #CVE #SSH #libssh2
-
🚨 Kritische libssh2-Lücke: Ein Proof-of-Concept-Exploit wurde veröffentlicht. Ursache: fehlende Begrenzung von „packet_length“ in ssh2_transport_read()—Angreifer können manipulierte SSH-Pakete senden und Speicher auf dem Heap durcheinanderbringen (CVE-2026-55200, CVSS 9.8). Update prüfen: https://www.heise.de/news/Kritische-libssh2-Luecke-Proof-of-Concept-Exploit-veroeffentlicht-11347855.html 🔐 #CyberSecurity #Vulnerability #CVE #SSH #libssh2
-
Zwei Sicherheitslücken mit öffentlichen Exploits
https://linuxnews.de/zwei-sicherheitsluecken-mit-aktuellen-exploits/ #security #pedit COW #libssh2 #linux #linuxnews -
Zwei Sicherheitslücken mit öffentlichen Exploits
https://linuxnews.de/zwei-sicherheitsluecken-mit-aktuellen-exploits/ #security #pedit COW #libssh2 #linux #linuxnews -
Sicherheitslücken gefährden Verbindungen über #libssh2 | Security https://www.heise.de/news/Sicherheitsluecken-gefaehrden-Verbindungen-ueber-libssh2-11339571.html #Patchday #OpenSource
-
Sicherheitslücken gefährden Verbindungen über #libssh2 | Security https://www.heise.de/news/Sicherheitsluecken-gefaehrden-Verbindungen-ueber-libssh2-11339571.html #Patchday #OpenSource
-
CRITICAL: libssh2 contains 2 vulnerabilities allowing remote code execution without authentication or user action. No CVE, patch, or vendor advisory yet. Widely embedded — monitor for updates, limit exposure. https://radar.offseq.com/threat/massive-security-flaw-discovered-in-popular-ssh-li-1a973c1519977003 #OffSeq #libssh2 #vuln #remotecodeexecution
-
Warning to anyone using #curl (or other software) built against #libssh2 backend: "libssh2 through 1.11.1, fixed in commit https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8 contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution."
https://github.com/advisories/GHSA-R8MH-X5QV-7GG2 -
Warning to anyone using #curl (or other software) built against #libssh2 backend: "libssh2 through 1.11.1, fixed in commit https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8 contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution."
https://github.com/advisories/GHSA-R8MH-X5QV-7GG2 -
CVE Alert: CVE-2026-7598 - n/a - libssh2 - https://www.redpacketsecurity.com/cve-alert-cve-2026-7598-n-a-libssh2/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-7598 #n-a #libssh2
-
CVE Alert: CVE-2026-7598 - n/a - libssh2 - https://www.redpacketsecurity.com/cve-alert-cve-2026-7598-n-a-libssh2/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-7598 #n-a #libssh2
-
The "good" people at Emerson for some reason couldn't think for themselves when I responded to them on behalf of #curl and instead continue and send the same questions to the #libssh2 project with the same "demands".
"This is a gentle reminder regarding our earlier request for your input on the cybersecurity risk assessment of the software component “libssh2” version 1.11.0, as part of our compliance efforts with the EU Cyber Resilience Act (CRA)."
-
The "good" people at Emerson for some reason couldn't think for themselves when I responded to them on behalf of #curl and instead continue and send the same questions to the #libssh2 project with the same "demands".
"This is a gentle reminder regarding our earlier request for your input on the cybersecurity risk assessment of the software component “libssh2” version 1.11.0, as part of our compliance efforts with the EU Cyber Resilience Act (CRA)."
-
I ran a quick SFTP performance test with #curl built to use #libssh 0.11.1 vs one built that uses #libssh2 1.11.1 over a 400ms latency connection.
One of them managed to perform this at 1049K/sec, the other reached only 249K/sec.
And the winner is...
libssh2
Funny detail: I sped it up for this kind of use case **fifteen years ago** and blogged about it: https://daniel.haxx.se/blog/2010/12/08/making-sftp-transfers-fast/
-
I ran a quick SFTP performance test with #curl built to use #libssh 0.11.1 vs one built that uses #libssh2 1.11.1 over a 400ms latency connection.
One of them managed to perform this at 1049K/sec, the other reached only 249K/sec.
And the winner is...
libssh2
Funny detail: I sped it up for this kind of use case **fifteen years ago** and blogged about it: https://daniel.haxx.se/blog/2010/12/08/making-sftp-transfers-fast/
-
Say hello to #libssh2 1.11.1, just released => https://github.com/libssh2/libssh2/releases/tag/libssh2-1.11.1
-
Say hello to #libssh2 1.11.1, just released => https://github.com/libssh2/libssh2/releases/tag/libssh2-1.11.1
-
On this day, fifteen years ago, we shipped #libssh2 1.0
-
On this day, fifteen years ago, we shipped #libssh2 1.0
-
Glad to see that #libssh2 is on top of things adding #terrapinattack mitigation https://github.com/libssh2/libssh2/pull/1291
-
Glad to see that #libssh2 is on top of things adding #terrapinattack mitigation https://github.com/libssh2/libssh2/pull/1291
-
-