Lucene search

K
osvGoogleOSV:RLSA-2022:2031
HistoryMay 10, 2022 - 8:14 a.m.

Low: libssh security, bug fix, and enhancement update

2022-05-1008:14:06
Google
osv.dev
6

6.8 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.7%

libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.

The following packages have been upgraded to a later upstream version: libssh (0.9.6). (BZ#1896651)

Security Fix(es):

  • libssh: possible heap-based buffer overflow when rekeying (CVE-2021-3634)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.