CVE-2026-0968

Publication date 13 February 2026

Last updated 23 February 2026


Ubuntu priority

Description

[Denial of Service due to malformed SFTP message]

Status

Package Ubuntu Release Status
libssh 25.10 questing
Fixed 0.11.2-1ubuntu0.2
24.04 LTS noble
Fixed 0.10.6-2ubuntu0.3
22.04 LTS jammy
Fixed 0.9.6-2ubuntu0.22.04.6
20.04 LTS focal
Fixed 0.9.3-2ubuntu2.5+esm3
18.04 LTS bionic
Fixed 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6
16.04 LTS xenial
Fixed 0.6.3-4.3ubuntu0.6+esm4

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro 30-day free trial

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libssh

References

Related Ubuntu Security Notices (USN)

    • USN-8051-1
    • libssh vulnerabilities
    • 18 February 2026
    • USN-8051-2
    • libssh vulnerabilities
    • 23 February 2026

Other references