libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Jun 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-824 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 29 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 28 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. | |
| Title | libssh2 - Free of Uninitialized Pointer in publickey List Cleanup | |
| First Time appeared |
Libssh2
Libssh2 libssh2 |
|
| Weaknesses | CWE-908 | |
| CPEs | cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libssh2
Libssh2 libssh2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-28T01:32:54.283Z
Updated: 2026-06-29T12:50:00.766Z
Reserved: 2026-06-28T00:55:25.426Z
Link: CVE-2026-58051
Updated: 2026-06-29T12:49:52.395Z
No data.