Ad

CVE-2026-0965

LOW CVSS 3.0: 3.3 EPSS 0.02%
Updated Mar 30, 2026
Red Hat
Parameter Value
CVSS 3.3 (LOW)
Affected Versions before 0.11.3
Type CWE-73 (External Control of File Name or Path)
Vendor Red Hat
Public PoC No

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.0

Vulnerable Products 3

Configuration From (including) Up to (excluding)
Libssh Libssh
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
<= 0.11.3
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*