CVE-2026-59847 PUBLISHED

Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification

Assigner: redhat
Reserved: 07.07.2026 Published: 21.07.2026 Updated: 21.07.2026

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 5.9

Product Status

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 8
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected
Vendor Red Hat
Product Red Hat Hardened Images
Versions Default: affected

Workarounds

Disable the aes128-gcm@openssh.com and aes256-gcm@openssh.com ciphers.

Credits

  • Red Hat would like to thank Ben Smyth for reporting this issue.

References