CVE-2026-15370 MEDIUM

CVE-2026-15370: Libssh: libssh: stack buffer overflow in sftp server longname construction

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Weakness CWE-121
Published July 21, 2026
Last update July 21, 2026

CVSS base score

6.7/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

Key dates

02Disclosure timeline

July 21, 2026 CVE published