Description
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
CVSS breakdown
CVSS 3.0
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Affected products
- libssh / libssh0.11.4
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / hardened_images
- RedHat / openshift_container_platform4.0 – 4.0
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:18160
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:18683
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-0964
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2436979
- MISChttps://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
Updated 17m ago · 8 sources