Database/Kernel, userspace & hypervisor
libssh: incorrect AES-GCM finalization removes integrity protection on SSH sessions
Impact
Builds of libssh using the OpenSSL backend do not correctly check AES-GCM finalization, so the authentication tag that is supposed to make tampering detectable effectively stops protecting the session. An in-path attacker can modify plaintext on the wire and the endpoints will not notice. That is a meaningful loss on a GPU fleet because libssh - not OpenSSH - is what libvirt, remote management tooling, automation agents and various vendor CLIs use to reach hypervisors, BMC-adjacent hosts and node management interfaces, often over a management VLAN that is trusted precisely because SSH was assumed to be integrity-protected. Confidentiality is not directly broken here; integrity is, which is what matters when the traffic being modified is a management command.
Who can reach it
An attacker positioned in the network path between a libssh client or server and its peer - no credentials needed, but a machine-in-the-middle position on the management or control network is required.
What to do
Update libssh from the vendor errata (Red Hat ships fixes in RHSA-2026:42922 and RHSA-2026:55855) and restart every service linked against it - libvirtd and any management or automation daemon that speaks SSH through libssh - since long-lived processes keep the vulnerable code loaded. Container images built on affected bases need rebuilding, not just a host package update.
References
Related entries
- Xen (vRTC): Out-of-bounds read in vRTC emulation - hypervisor memory disclosure to a guestCVE-2026-62430 · Xen (vRTC)High
- OpenSSL: crafted CMS message causes an 8-byte out-of-bounds heap write during CMS_decrypt()CVE-2026-63072 · OpenSSL CMS decryption (AES-WRAP-PAD key unwrap output buffer)High
- OpenSSL QUIC: a peer withholding acknowledgements makes ACK-only metadata accumulate for the connection's lifeCVE-2026-63075 · OpenSSL QUIC packet history (ACK-only packet metadata retention)High
- OpenSSL CMP: unchecked protectionAlg parameter type is dereferenced as a PBMParameter and crashes the processCVE-2026-63076 · OpenSSL CMP password-based MAC verification (protectionAlg parameter type check)High
- Linux kernel SMC-D client (CHID matching against unpopulated ism_dev slot): Slot 0 of the client's ISM device array isCVE-2026-64048 · Linux kernel SMC-D client (CHID matching against unpopulated ism_dev slot)High
- Linux kernel pcrypt: padata fallback leaves the parallel completion callback on the child requestCVE-2026-64312 · Linux kernel crypto pcrypt (padata -EBUSY fallback path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.