Compound WireCOMPOUND31 August 2026
USN-8699-1: libssh vulnerabilities
Ubuntu published USN-8699-1 for libssh, and both bugs sit in code that runs before you would think of it as an attack surface. One is a stack buffer overflow in the SFTP server while building directory listing entries for long filenames, a crash or arbitrary code execution from the act of listing a directory, and it only affects Ubuntu 26.04 LTS. The other is an SSH channel open message advertising a maximum packet size of zero, which an authenticated remote attacker can send. If you embed libssh rather than run OpenSSH, patch the thing you forgot you linked against.