Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-58051 — libssh2: libssh2: Denial of service or information disclosure via malformed SSH publickey response CVE-2026-66032 — libssh2: libssh2: Arbitrary code execution via double-free in SFTP session CVE-2026-66033 — libssh2: libssh2: Denial of Service via integer underflow in AES-GCM cipher negotiation CVE-2026-66034 — libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read
🎯 Affected products5
- Red Hat Hardened Images
- libssh2-main@aarch64 as a component of Red Hat Hardened Images
- libssh2-main@noarch as a component of Red Hat Hardened Images
- libssh2-main@src as a component of Red Hat Hardened Images
- libssh2-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, ensure your applications connect only to trusted and verified SSH servers. For added protection, maintain standard system memory defenses to automatically intercept and safely terminate any processes corrupted by an unexpected server error. Workaround: Restrict your libssh2 clients to connect only to fully trusted, internal SFTP servers to eliminate exposure to malicious server responses. Additionally, configure dependent applications with Restart=on-failure in systemd so RHEL's glibc memory protections can safely crash and auto-recover the process during an attack. Workaround: To mitigate the vulnerability, developers or administrators must configure the specific applications utilizing libssh2 to explicitly exclude AES-GCM from their preferred cipher lists. Workaround: To mitigate this, strictly avoid connecting to untrusted SSH servers and enforce this policy using outbound network firewalls to block unknown IP addresses. For defense-in-depth, utilize OS-level memory protections and service sandboxing to contain any accidental exposure.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:46927
- externalhttps://access.redhat.com/security/cve/CVE-2026-58051
- externalhttps://access.redhat.com/security/cve/CVE-2026-66032
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-66034
- externalhttps://access.redhat.com/security/cve/CVE-2026-66033
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_46927.json