RHSA-2026:42922Vendor advisory
https://access.redhat.com/errata/RHSA-2026:42922 CVE-2026-59845
MEDIUM
Libssh: libssh: denial of service via unchecked proxycommand fork() failure
Record summary
CVE-2026-59845 has a selected CVSS score of 5.3 (medium).
Description
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | 0.12.1-4.hum1 to < * | unaffected |
References
4access.redhat.comvdb entry
https://access.redhat.com/security/cve/CVE-2026-59845 RHBZ#2498178issue tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2498178 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-59845