CVE detail
CVE-2026-59843
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 4
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:55855access.redhat.com
No excerpt available.
Exploitaccess.redhat.comJul 21, 2026, 12:18 PM - https://access.redhat.com/errata/RHSA-2026:42922access.redhat.com
No excerpt available.
Exploitaccess.redhat.comJul 21, 2026, 12:18 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2498176bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJul 21, 2026, 12:18 PM - https://access.redhat.com/security/cve/CVE-2026-59843access.redhat.com
No excerpt available.
Exploitaccess.redhat.comJul 21, 2026, 12:18 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-59849CVSS 3.1 · Low
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are mi…
- CVE-2023-43786CVSS 5.5 · Medium
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a…
- CVE-2021-3737CVSS 7.5 · High
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client scr…
- CVE-2021-3679CVSS 5.5 · Medium
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only priv…
- CVE-2026-71227CVSS 5.1 · Medium
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior…
- CVE-2026-6844CVSS 5.5 · Medium
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Exec…