Page MenuHomeVyOS Platform

CVE-2026-55200: memory corruption in libssh2
Closed, InvalidPublic

Description

https://app.opencve.io/cve/CVE-2026-55200 is a memory corruption in libssh2 that potentially allows a remote attacker who controls an SSH server to execute arbitrary code on clients who connect to it.

In VyOS, it's used by curl, which we use for commit archive over SSH and for tech support report uploads.

It's difficult to exploit and exploits have to be tailored to applications, but the main point is that Debian still lacks a fix and we have to produce a patched version ourselves if we want it fixes, for now at least.

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Security vulnerability

Event Timeline

dmbaturin triaged this task as High priority.

The version we use was proven not to actually have this issue.