USN-8722-1: libssh2 vulnerabilities
It was discovered that libssh2 incorrectly handled certain SFTP server
responses. A remote attacker controlling an SSH server could use this issue
to cause libssh2 to crash or possibly execute arbitrary code.
(CVE-2026-66032)
It was discovered that libssh2 incorrectly handled AES-GCM cipher
negotiation. A remote attacker controlling an SSH server could possibly use
this issue to cause libssh2 to crash, resulting in a denial of service.
(CVE-2026-66033)
It was discovered that libssh2 incorrectly handled Encrypt-then-MAC cipher
negotiation. A remote attacker controlling an SSH server could use this
issue to cause libssh2 to crash or possibly execute arbitrary code.
(CVE-2026-66035)