CVE-2026-0967 Details
Description
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
A denial-of-service vulnerability has been identified in libssh. A remote attacker can exploit this issue by manipulating client configuration or known_hosts files to introduce specific hostnames. When these hostnames are processed by the 'match_pattern()' function, they can cause inefficient backtracking in regular expression processing. This flaw can lead to timeouts and resource exhaustion, disrupting the client's operations.
Users are advised to avoid complex patterns in configuration files and known_hosts files.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1333 | Inefficient Regular Expression Complexity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libssh libssh | <= 0.11.3 |
CPE
Remediation
| |
| redhat enterprise linux | 9.0 10.0 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| Apr 2, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | CVE Modified | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |