Record summary

CVE-2026-59845 has a selected CVSS score of 5.3 (medium).

Description

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2026 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10libssh

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8libssh

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 9

Browse Red Hat / Red Hat Enterprise Linux 9libssh

Default status: affected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imageslibssh-main

Default status: affected

CVE List0.12.1-4.hum1 to < *unaffected

References

4