[RLSA-2022:2031] libssh security, bug fix, and enhancement update
An update is available for libssh. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.
The following packages have been upgraded to a later upstream version: libssh (0.9.6). (BZ#1896651)
Security Fix(es):
- libssh: possible heap-based buffer overflow when rekeying (CVE-2021-3634)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.
Package | Affected Version |
---|---|
pkg:rpm/rockylinux/libssh?arch=x86_64&distro=rockylinux-8 | < 0.9.6-3.el8 |
pkg:rpm/rockylinux/libssh?arch=aarch64&distro=rockylinux-8 | < 0.9.6-3.el8 |
pkg:rpm/rockylinux/libssh-devel?arch=x86_64&distro=rockylinux-8 | < 0.9.6-3.el8 |
pkg:rpm/rockylinux/libssh-devel?arch=aarch64&distro=rockylinux-8 | < 0.9.6-3.el8 |
pkg:rpm/rockylinux/libssh-config?arch=noarch&distro=rockylinux-8 | < 0.9.6-3.el8 |
- ID
- RLSA-2022:2031
- Severity
- low
- URL
- https://errata.rockylinux.org/RLSA-2022:2031
- Published
-
2022-05-10T08:14:06
(2 years ago) - Modified
-
2023-02-02T12:53:32
(19 months ago) - Rights
- Copyright 2023 Rocky Enterprise Software Foundation
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2021-3634 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3634 | |
Bugzilla | 1896651 | https://bugzilla.redhat.com/show_bug.cgi?id=1896651 | |
Bugzilla | 1978810 | https://bugzilla.redhat.com/show_bug.cgi?id=1978810 | |
Bugzilla | 2020159 | https://bugzilla.redhat.com/show_bug.cgi?id=2020159 | |
Self | RLSA-2022:2031 | https://errata.rockylinux.org/RLSA-2022:2031 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/rockylinux/libssh?arch=x86_64&distro=rockylinux-8 | rockylinux | libssh | < 0.9.6-3.el8 | rockylinux-8 | x86_64 | |
Affected | pkg:rpm/rockylinux/libssh?arch=aarch64&distro=rockylinux-8 | rockylinux | libssh | < 0.9.6-3.el8 | rockylinux-8 | aarch64 | |
Affected | pkg:rpm/rockylinux/libssh-devel?arch=x86_64&distro=rockylinux-8 | rockylinux | libssh-devel | < 0.9.6-3.el8 | rockylinux-8 | x86_64 | |
Affected | pkg:rpm/rockylinux/libssh-devel?arch=aarch64&distro=rockylinux-8 | rockylinux | libssh-devel | < 0.9.6-3.el8 | rockylinux-8 | aarch64 | |
Affected | pkg:rpm/rockylinux/libssh-config?arch=noarch&distro=rockylinux-8 | rockylinux | libssh-config | < 0.9.6-3.el8 | rockylinux-8 | noarch |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |