CVE-2026-59845CWE-390

CVE-2026-59845

Medium · published July 21, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
1.1
In the wild
Unconfirmed
What it is

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00104 · 1.1th percentile
Weakness
CWE-390 · Detection of Error Condition Without Action
Published
2026-07-21T16:18Z
Affected products (5)
ProductVersionsFixed in
libssh/libsshall versions
redhat/hardened_imagesall versions
redhat/enterprise_linuxall versions
redhat/enterprise_linuxall versions
redhat/enterprise_linuxall versions
References (6)
EPSS history
Timeline
  • 21 JUL 11:26Z
    Libssh: libssh: denial of service via unchecked proxycommand fork() failure
    cvelistv5