CVE-2026-59845 MEDIUM

CVE-2026-59845: Libssh: libssh: denial of service via unchecked proxycommand fork() failure

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Weakness CWE-390
Published July 21, 2026
Last update August 11, 2026

CVSS base score

5.3/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

Key dates

02Disclosure timeline

July 21, 2026 CVE published
August 11, 2026 Record updated