home.social

#libssh2 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #libssh2, aggregated by home.social.

fetched live
  1. 🚨 Critical update: A proof-of-concept exploit has been released for a libssh2 vulnerability (CVE-2026-55200, CVSS 9.8). Attackers can abuse oversized SSH “packet_length” to corrupt heap memory. 📌 Patch status varies—check updates now: heise.de/en/news/Critical-libs #CyberSecurity #Vulnerability #libssh2 #CVE

  2. 🚨 Critical update: A proof-of-concept exploit has been released for a libssh2 vulnerability (CVE-2026-55200, CVSS 9.8). Attackers can abuse oversized SSH “packet_length” to corrupt heap memory. 📌 Patch status varies—check updates now: heise.de/en/news/Critical-libs #CyberSecurity #Vulnerability #libssh2 #CVE

  3. 🚨 Kritische libssh2-Lücke: Ein Proof-of-Concept-Exploit wurde veröffentlicht. Ursache: fehlende Begrenzung von „packet_length“ in ssh2_transport_read()—Angreifer können manipulierte SSH-Pakete senden und Speicher auf dem Heap durcheinanderbringen (CVE-2026-55200, CVSS 9.8). Update prüfen: heise.de/news/Kritische-libssh 🔐 #CyberSecurity #Vulnerability #CVE #SSH #libssh2

  4. 🚨 Kritische libssh2-Lücke: Ein Proof-of-Concept-Exploit wurde veröffentlicht. Ursache: fehlende Begrenzung von „packet_length“ in ssh2_transport_read()—Angreifer können manipulierte SSH-Pakete senden und Speicher auf dem Heap durcheinanderbringen (CVE-2026-55200, CVSS 9.8). Update prüfen: heise.de/news/Kritische-libssh 🔐 #CyberSecurity #Vulnerability #CVE #SSH #libssh2

  5. CRITICAL: libssh2 contains 2 vulnerabilities allowing remote code execution without authentication or user action. No CVE, patch, or vendor advisory yet. Widely embedded — monitor for updates, limit exposure. radar.offseq.com/threat/massiv #OffSeq #libssh2 #vuln #remotecodeexecution

  6. Warning to anyone using #curl (or other software) built against #libssh2 backend: "libssh2 through 1.11.1, fixed in commit github.com/libssh2/libssh2/com contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution."
    github.com/advisories/GHSA-R8M

    #CVE_2026_55200 #infosec #cybersecurity

  7. Warning to anyone using #curl (or other software) built against #libssh2 backend: "libssh2 through 1.11.1, fixed in commit github.com/libssh2/libssh2/com contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution."
    github.com/advisories/GHSA-R8M

    #CVE_2026_55200 #infosec #cybersecurity

  8. The "good" people at Emerson for some reason couldn't think for themselves when I responded to them on behalf of #curl and instead continue and send the same questions to the #libssh2 project with the same "demands".

    "This is a gentle reminder regarding our earlier request for your input on the cybersecurity risk assessment of the software component “libssh2” version 1.11.0, as part of our compliance efforts with the EU Cyber Resilience Act (CRA)."

  9. The "good" people at Emerson for some reason couldn't think for themselves when I responded to them on behalf of #curl and instead continue and send the same questions to the #libssh2 project with the same "demands".

    "This is a gentle reminder regarding our earlier request for your input on the cybersecurity risk assessment of the software component “libssh2” version 1.11.0, as part of our compliance efforts with the EU Cyber Resilience Act (CRA)."

  10. I ran a quick SFTP performance test with #curl built to use #libssh 0.11.1 vs one built that uses #libssh2 1.11.1 over a 400ms latency connection.

    One of them managed to perform this at 1049K/sec, the other reached only 249K/sec.

    And the winner is...

    libssh2

    Funny detail: I sped it up for this kind of use case **fifteen years ago** and blogged about it: daniel.haxx.se/blog/2010/12/08

  11. I ran a quick SFTP performance test with #curl built to use #libssh 0.11.1 vs one built that uses #libssh2 1.11.1 over a 400ms latency connection.

    One of them managed to perform this at 1049K/sec, the other reached only 249K/sec.

    And the winner is...

    libssh2

    Funny detail: I sped it up for this kind of use case **fifteen years ago** and blogged about it: daniel.haxx.se/blog/2010/12/08